Anthropic disclosed on 28 July 2026 that its unreleased Claude Mythos Preview model found a previously unknown structural weakness in HAWK, a lattice based post-quantum signature scheme under NIST evaluation, cutting the cost of key recovery on the HAWK-256 challenge parameter from about 2^64 to about 2^38 operations, work the model completed in roughly 60 hours after the scheme had survived two years of expert human review.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source A second result improved the best known attack on seven round AES-128 by 200 to 800 times, though it still requires about 2^105 chosen plaintexts and, by Anthropic's own estimate, hundreds of millions of dollars to implement, so no deployed system is at risk.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 6 CSO Online 2026-07-29 HAWK was evaluated for two years before the discovery; the finding is specific to HAWK and does not affect other NIST post-quantum signature candidates or lattice cryptography generally; the AES attack targets 7 of 10 rounds and is completely impractical; neither result compromises production deployments. Open source The stake is the US post-quantum standardization process itself: the HAWK team withdrew the scheme the next day.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source We assess with high confidence that the significance is not either break but the demonstration that roughly 100,000 dollars of model time can now do review work that two years of expert attention did not, which changes who participates in cryptographic vetting and how fast candidates get stress tested.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source

What the model actually found

HAWK rests on the lattice isomorphism problem and had been moved by NIST into a third evaluation round in May 2026.3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source Claude's attack exploits a previously undiscovered symmetry in the lattice structure, recovering functionally equivalent signing material rather than the original seed, and the proof of concept ran in about 3 hours 42 minutes on a 96 core server against the challenge parameter.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source The larger parameters that NIST actually evaluates remain out of practical reach, but the gate count estimates moved everywhere: HAWK-512 from roughly 2^150 to 2^108, HAWK-1024 from roughly 2^288 to 2^182.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source That is a structural halving of the security margin, not an edge case, and the HAWK team concluded that restoring the claimed levels meant roughly doubling key sizes, which would erase the compactness that made the scheme competitive. It was withdrawn from the NIST process on 29 July.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source 3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source

Matthew Green, a cryptographer at Johns Hopkins University, made the point that matters for calibration: the attack roughly halves the bits of security, does not transfer to Falcon, the related scheme already being standardized, and, in his words, "none of the ingredients are exotic."4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source The model did not invent new mathematics. It combined known lattice tools more thoroughly than the humans who had two years to do the same, which is in some ways the more uncomfortable finding, because thoroughness at scale is exactly what model time buys.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source

The AES result is deliberately the smaller story. The attack targets 7 of AES-128's 10 rounds, a research variant, and improves on a 2013 meet in the middle record using a fingerprinting construction Anthropic calls the Mobius Bridge.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source 3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source Green puts the requirements at about 2^89 operations and 2^105 chosen plaintexts and calls it not remotely practical; CSO Online's summary is blunter, completely impractical.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source 6 CSO Online 2026-07-29 HAWK was evaluated for two years before the discovery; the finding is specific to HAWK and does not affect other NIST post-quantum signature candidates or lattice cryptography generally; the AES attack targets 7 of 10 rounds and is completely impractical; neither result compromises production deployments. Open source Nobody's TLS session is in danger. What the AES work demonstrates is process: the model burned through roughly 200 failed attack variants and about 1 billion output tokens before landing the improvement.3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source

The economics underneath the result

Each discovery cost about 100,000 dollars in API usage.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source Set that against what it replaced. Cryptanalysis of standardization candidates has historically been donated labor from a small global pool of academic specialists, and HAWK had absorbed two years of that pool's attention without anyone finding this symmetry.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 6 CSO Online 2026-07-29 HAWK was evaluated for two years before the discovery; the finding is specific to HAWK and does not affect other NIST post-quantum signature candidates or lattice cryptography generally; the AES attack targets 7 of 10 rounds and is completely impractical; neither result compromises production deployments. Open source A six figure compute bill that outperforms that review on a specific target is a new price point for adversarial scrutiny, and it is available to anyone who can pay it once frontier models with this capability are released.

The bottleneck moved rather than disappeared. Two researchers spent nearly a month validating the AES mathematics, and Anthropic describes human verification time as far exceeding model discovery time.5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source 1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source Green's formulation is that "verifiability is now the bottleneck."4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source That inversion, cheap conjecture and expensive checking, is the same shape AI has imposed on software and on parts of mathematics, and cryptography is unusually well suited to survive it because attacks come with runnable proofs: the HAWK code either recovers a key or it does not.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source

Who gains and who loses

NIST and the standardization process gain, on net. A weakness surfaced during review, before deployment, is the process working, and the disclosure was coordinated: NIST, US government and industry partners were briefed before publication, and the HAWK authors were told in June.3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source 1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source Green argues the timing is close to ideal, since the migration from RSA and elliptic curves to novel hard problems is precisely when a large new public cryptanalysis capability is most useful.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source Anthropic gains a demonstration for Mythos that is verifiable by third parties rather than benchmark scored, which is rare in frontier model marketing. Academic collaborators at ETH Zurich, Tel Aviv University and the University of Haifa share authorship of that shift.5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source

The HAWK team loses the obvious way, a decade of design work withdrawn.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source The subtler losers are the remaining candidates and the timeline: every scheme still in the process now faces the question of whether it has been Mythos tested, and a negative result cannot be demonstrated. Defenders broadly should note the dual use edge: the same capability that hardens standards pre deployment will probe deployed protocol implementations, where the target is not clean mathematics but configuration and code. We assess with moderate confidence that NIST will formally incorporate AI assisted cryptanalysis into candidate evaluation within two years, because the cost asymmetry against volunteer review is now on the record.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source

The counter-case

The deflationary reading has real evidence behind it. Both attacks are exponential; neither touches a production system, and the AES improvement is a modest step on a 13 year old record against a reduced round variant.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source 6 CSO Online 2026-07-29 HAWK was evaluated for two years before the discovery; the finding is specific to HAWK and does not affect other NIST post-quantum signature candidates or lattice cryptography generally; the AES attack targets 7 of 10 rounds and is completely impractical; neither result compromises production deployments. Open source Candidates have been broken during past NIST processes by unaided humans, so a review stage casualty is not novel in kind.5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source All of the capability claims here rest on Anthropic's own paper and disclosures, with Green working from the published mathematics rather than independent access to the model, so the efficiency narrative, 60 hours, 100,000 dollars, is per the company's own account and not independently reproduced.1 Anthropic 2026-07-28 HAWK-256 weakened from effective 2^64 to 2^38 keysize in about 60 hours after two years of expert review; seven round AES-128 attack improved 200 to 800 times, needing 2^105 chosen plaintexts and hundreds of millions of dollars to implement; about 100,000 dollars API cost each; coordinated disclosure with NIST, US government and industry; HAWK authors told in June. Open source 4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source For the thesis to fail, Mythos class models would need to produce no further review grade results on other candidates over the next year, which would recast HAWK as a one off: a scheme with an unusually findable flaw that happened to be found by a machine first.

What to watch

  • A second scheme moves. If any other NIST post-quantum candidate is withdrawn or reparameterized citing AI assisted cryptanalysis by mid 2027, the HAWK result is a category, not an incident.2 The Hacker News 2026-07-28 Attack exploits a previously undiscovered lattice symmetry; proof of concept ran in about 3 hours 42 minutes on a 96 core server; gate count estimates fell from 2^150 to 2^108 for HAWK-512 and 2^288 to 2^182 for HAWK-1024; Mobius Bridge fingerprint; HAWK withdrawn from the NIST process 29 July 2026; both attacks remain exponential. Open source
  • NIST changes its process. Watch for NIST guidance or workshop material through 2027 that formally treats large model cryptanalysis as part of candidate evaluation; silence past that point weakens the institutional adoption thesis.3 Decrypt 2026-07-28 NIST moved HAWK into a third round in May 2026; the cost drop is roughly 67 million times less work; the AES refinement consumed about 1 billion output tokens across roughly 200 failed variants against a 2013 record; results disclosed to NIST, the US government and industry partners before publication. Open source
  • Independent reproduction. An external team confirming the HAWK attack from the published construction, within roughly six months, converts a company claim into settled literature.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source
  • Falcon holds. Green states the technique does not transfer to Falcon; any sign through 2027 that related symmetry arguments reach schemes already being standardized would escalate this from process story to deployment story.4 Matthew Green, Cryptography Engineering 2026-07-29 Johns Hopkins cryptographer: attack roughly halves bits of security, does not transfer to Falcon, none of the ingredients are exotic; AES result needs about 2^89 operations and 2^105 chosen plaintexts and is not remotely practical; verifiability is now the bottleneck; a large public cryptanalysis capability arrives at a useful moment for the post-quantum transition. Open source
  • The verification gap closes or widens. If proof assistant tooling starts absorbing the month long human validation step within the next year, the last human bottleneck in machine cryptanalysis thins, and the pace of results is set by compute budgets alone.5 The Quantum Insider 2026-07-29 Each discovery cost about 100,000 dollars in API usage; two researchers spent nearly a month validating the AES mathematics; partners included ETH Zurich, Tel Aviv University and the University of Haifa; weaknesses found during review reflect the standardization process working; candidates have been broken in past NIST rounds. Open source

The signature scheme is gone and the block cipher is fine. What the week actually priced is adversarial mathematical attention, at about 100,000 dollars a target, and every cryptographic design that expects to live for decades now has to assume that price keeps falling.