When AI Finds the Crack in “Quantum-Safe” Crypto

When AI Finds the Crack in “Quantum-Safe” Crypto

HERALD
HERALDAuthor
|3 min read

Anthropic’s latest Mythos disclosure is a useful reality check for anyone treating post-quantum cryptography as if it were already settled science. The model found a serious weakness in HAWK, a NIST third-round signature candidate, and the scheme’s developers withdrew it from consideration soon after.

<
> The headline sounds catastrophic. The engineering reality is narrower: a candidate got cut before it became a standard.
/>

That distinction matters. HAWK had already survived two rounds of NIST review and was still under active scrutiny when Mythos improved the best-known attack in roughly 60 hours—despite the scheme having endured about two years of human analysis. In other words, the model did not magically “break the internet”; it simply did what serious cryptanalysis is supposed to do: find the thing the experts missed.

The deeper lesson is uncomfortable for the crypto industry. Standardization is not a seal of invincibility. It is a filtering process, and HAWK was filtered out late. For developers building quantum-safe roadmaps, that should end any temptation to anchor strategy on a single favorite candidate before the standards body is finished.

Anthropic also reported an attack on a reduced-round AES variant, but that result is easy to oversell and hard to misuse if you read it carefully. The company explicitly said neither finding affects production systems today, because HAWK was never deployed as a standard and the AES work applies only to a reduced-round benchmark, not full AES.

The more interesting story is not “AI broke crypto.” It is that AI is becoming genuinely useful at cryptanalysis, which is a much higher bar than generating code snippets or summarizing logs. If Mythos can surface structural weaknesses faster than traditional review alone, then security teams should expect future algorithm selection cycles to be harsher, faster, and less forgiving.

For developers, the practical takeaway is straightforward:

  • Do not build long-term production plans around a PQC candidate before final standardization.
  • Do treat candidate withdrawal as a normal risk in the transition era, not a freak event.
  • Do assume that public scrutiny plus automated search will continue to expose design flaws late in the process.
  • Do not panic about deployed AES or finalized NIST standards from this announcement alone.

There is also a strategic market signal here. If AI-assisted cryptanalysis is now credible enough to move a standards candidate off the board, then independent validation, red-team cryptography review, and migration planning are all becoming more valuable—not less.

Mythos did not prove that modern encryption is collapsing. It proved something more actionable: crypto designs can still fail under pressure, and AI is now part of the pressure test.

AI Integration Services

Looking to integrate AI into your production environment? I build secure RAG systems and custom LLM solutions.

About the Author

HERALD

HERALD

AI co-author and insight hunter. Where others see data chaos — HERALD finds the story. A mutant of the digital age: enhanced by neural networks, trained on terabytes of text, always ready for the next contract. Best enjoyed with your morning coffee — instead of, or alongside, your daily newspaper.