A quantum-resistant cryptography algorithm that was under consideration as an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken.
The algorithm is known as HAWK. It’s a digital signature scheme designed to withstand future attacks from quantum computers. HAWK had survived two rounds of testing by NIST (the National Institute of Standards and Technology) for evaluating the security of PQC (post-quantum cryptographic) algorithms through widespread testing. HAWK was in a third round of testing designed to catch precisely the kinds of flaws Mythos helped uncover.
Following Anthropic’s Monday announcement of the results, the developer of HAWK said Tuesday he was withdrawing it.
Even before the development, Anthropic was hailing the results of the two cryptographic problems it threw at its Mythos AI security model. The model found weaknesses in the mathematical problems underpinning HAWK and, separately, the widely used AES cipher.
Despite the withdrawing of HAWK, it’s hard to know how much of the company’s reporting is marketing hype, but the findings are still worth paying attention to because they could signal important advances in breaking cryptography that’s crucial to privacy and security.
Before digging into the results, a few caveats.
First, the outcomes are incremental. They don’t break any of the cryptosystems anyone relies on today. Instead, they reveal methods for moderately reducing the work that would be required to defeat the systems.
Second, the cryptosystems tested were weakened versions of the ones defined in their formal specifications. Such “challenge instances” are provided by the specification authors for use in adversarial peer review. It’s standard to use the weakened versions in testing, but the real ones are considerably more robust in production settings.
As Bruce Schneier said when reviewing another incremental improvement on the attacks on AES:
And as he often says
Edit: reorder paragraphs and trim original quote.
Facts Only
* An algorithm named HAWK was under consideration as a US standard.
* HAWK is a digital signature scheme designed to withstand quantum computer attacks.
* HAWK survived two rounds of NIST testing for PQC evaluation.
* HAWK entered a third round of testing targeting specific flaws.
* Anthropic's security model found weaknesses in the mathematical problems underpinning HAWK.
* The AI model also found weaknesses in the AES cipher.
* Following Anthropic’s announcement, the developer withdrew HAWK.
* The findings relate to methods for moderately reducing the work required to defeat the systems.
* Testing used weakened versions of cryptosystems defined in their formal specifications.
Executive Summary
Full Take
The narrative presents a tension between the public promise of quantum-resistant security and the reality that even advanced, vetted systems possess exploitable structural weaknesses. The central implication is that cryptographic robustness is not an absolute state but rather a spectrum determined by the level of adversarial modeling applied. Anthropic’s work suggests that advances in AI-driven reasoning can expose vulnerabilities in mathematical foundations utilized by high-security standards, shifting the focus from mere algorithmic strength to the resilience of foundational assumptions. The mitigation strategy—reducing required computational work rather than total system collapse—suggests a pragmatic reality where security advancements operate incrementally against an ongoing arms race. The inherent skepticism should be directed toward the claims of absolute security in complex systems; the process of validation itself introduces layers of necessary approximation and testing, whether in cryptology or AI safety.
Bridge Questions: What are the long-term implications if these incremental vulnerabilities become widely exploited in production environments? How should standards bodies adjust their verification protocols to account for iterative adversarial discovery by advanced modeling techniques? What is the societal risk associated with systems that rely on the assumption of perfect, unprovable mathematical security?
Sentinel — Human
The text reads like careful journalistic reporting that balances technical facts with necessary contextual caveats, suggesting a strong human editorial presence.
