AI Discovers Critical Cryptographic Flaws in Google’s Tink Library
Key Takeaways Anthropic’s Claude Mythos Preview AI has identified fundamental mathematical weaknesses in two significant cryptographic algorithms: HAWK and a reduced-round version of AES. The...
Key Takeaways
- Anthropic’s Claude Mythos Preview AI has identified fundamental mathematical weaknesses in two significant cryptographic algorithms: HAWK and a reduced-round version of AES.
- The AI autonomously discovered improved key-recovery attacks against HAWK, a post-quantum digital signature candidate, effectively halving its claimed security strength.
- It also developed a novel “Möbius Bridge” technique to accelerate cryptanalysis of 7-round AES-128 by hundreds of times.
- These findings do not impact currently deployed production systems but demonstrate AI’s advanced capability to uncover algorithmic flaws, shifting the paradigm for cryptographic security analysis.
AI Uncovers Deep Cryptographic Flaws in Core Algorithms
Researchers at Anthropic, leveraging their Claude Mythos Preview artificial intelligence, have made a groundbreaking discovery: mathematical vulnerabilities within prominent cryptographic algorithms that had eluded human experts for years. This marks a significant evolution in AI’s role in cybersecurity, moving beyond identifying mere implementation bugs to uncovering fundamental flaws in the algorithms themselves.
Table Of Content
The AI successfully developed enhanced attack vectors against HAWK, a leading post-quantum digital signature scheme, and a truncated version of AES, the world’s most widely adopted symmetric cipher. While these specific breakthroughs do not immediately threaten current production systems, they underscore a pivotal shift in how artificial intelligence can rigorously stress-test the bedrock of digital security.
Cryptographic algorithms are the invisible guardians of our digital lives, safeguarding everything from secure online banking transactions to encrypted web communications. Digital signatures authenticate websites and data, while symmetric ciphers ensure data privacy between parties sharing a secret key. Flaws in these foundational systems could potentially expose billions of users to severe risks.
Mythos Preview’s Cryptographic Breakthroughs
The first major achievement by Mythos Preview targets HAWK, a third-round contender in the National Institute of Standards and Technology’s (NIST) ongoing post-quantum cryptography competition. This initiative aims to develop new cryptographic standards resilient to attacks from future quantum computers, which could potentially shatter existing schemes like RSA and ECDSA.
Despite two years of intense scrutiny by human cryptographic experts, HAWK’s vulnerabilities remained undetected. Operating semi-autonomously for approximately 60 hours, at an estimated API cost of $100,000, Mythos significantly refined the most effective known key-recovery attack against HAWK, effectively reducing the scheme’s key strength by half.
This attack exploits a previously unrecognized symmetry—a non-trivial automorphism—within HAWK’s underlying lattice structure. While theoretical work had previously suggested that such symmetries could facilitate faster attacks, their actual existence within HAWK’s design had never been demonstrated. The consequence of this finding is that HAWK’s proposed key sizes are weaker than initially claimed; for instance, the estimated computational cost to break HAWK-256 plummeted from 2^64 to 2^38 operations. While doubling key sizes could restore the intended security, it would diminish much of HAWK’s attractiveness as a compact post-quantum solution.
It is important to note that this attack remains exponential in complexity and is not practically feasible against larger key sizes. Furthermore, it does not impact other NIST candidates or lattice-based cryptography in general. Anthropic responsibly shared its findings with the HAWK development team and coordinated the disclosure through NIST.
The second significant outcome involves an improved cryptanalysis of 7-round AES-128. The full AES-128 cipher, which utilizes 10 rounds, remains robustly secure; however, researchers often study reduced-round versions to explore and refine attack methodologies.
Building upon existing meet-in-the-middle attack techniques, Mythos innovated a unique fingerprinting method it termed a “Möbius Bridge.” This novel approach eliminates a critical guessing step that previously necessitated checking 256 distinct values, resulting in an attack that is between 200 to 800 times faster than the previous best, depending on measurement metrics.
This discovery was largely autonomous, requiring only minor human prompts over several days. Following the AI’s initial findings, researchers dedicated hundreds of hours to meticulously validate the claims.
Anthropic has also reported encouraging preliminary results against reduced-round versions of LEA and Serpent, alongside more modest gains on Salsa20, Poseidon, and SHA-1. To foster further research and provide a standardized evaluation tool, Anthropic has collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa to develop CryptanalysisBench, a new benchmark specifically designed for assessing the cryptanalytic capabilities of large language models.
These revelations do not necessitate immediate changes to currently deployed software. HAWK is still a candidate scheme, and the AES attack does not compromise the full 10-round cipher. However, these findings emphatically demonstrate that advanced AI can significantly accelerate the adversarial review process—a cornerstone of cryptography that aims to identify weaknesses before schemes are deployed to protect real-world users.
As AI models continue to advance in capability, human experts may increasingly pivot their focus towards verifying AI-generated research. Anthropic has initiated broader audits and plans to host academic workshops exploring the evolving role of language models in security research. When employed responsibly, such tools hold immense potential to strengthen the cryptographic algorithms that form the very foundation of internet security for everyone.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.