AI Model Mythos Breaks PQC Candidate HAWK, Forcing Withdrawal

Original: Mythos uncovers crypto weaknesses that went unknown for years

Why This Matters

AI-assisted cryptanalysis breaking a NIST PQC candidate signals a new threat vector for post-quantum standardization efforts.

Anthropic's AI security model Mythos helped find a fatal flaw in HAWK, a quantum-resistant digital signature scheme under NIST's third-round PQC evaluation. After ~60 hours of work and ~$100,000 in compute costs, the attack halved HAWK's effective key strength, prompting its developer to withdraw it on Tuesday.

HAWK, a post-quantum cryptography (PQC) digital signature scheme based on the Lattice Isomorphism Problem, had survived two full rounds of NIST evaluation before Anthropic's Mythos AI security model exposed a critical weakness. Using approximately 60 hours of work and around $100,000 in compute, an Anthropic researcher with no cryptography background guided Mythos to improve upon the best-known existing attack against HAWK, effectively halving its key strength. Following Anthropic's announcement on Monday, HAWK's developer announced withdrawal of the algorithm on Tuesday. Mythos also separately identified weaknesses in a challenge instance of AES, the widely used symmetric cipher. Several important caveats apply: the attacks targeted deliberately weakened 'challenge instances' provided for adversarial testing, not production implementations; the improvements are incremental and do not break any currently deployed systems; the underlying mathematical primitives remain secure for now; and the attack methods would likely be infeasible outside controlled testing environments. Mythos itself remains available only to a select group of trusted researchers. Despite the incremental nature of the findings, the results are notable as they demonstrate AI-assisted cryptanalysis uncovering flaws that years of conventional peer review had missed.

Source

arstechnica.com — Read original →