Advertisement
Advertisement
Advertisement
31 July 2026·6 min read·By Marcus Thorne

Mythos AI Finds HAWK PQC Algorithm Flaw

An Anthropic security model called Mythos identified a flaw in the HAWK post-quantum cryptographic algorithm.

Mythos AI Finds HAWK PQC Algorithm Flaw

HAWK PQC algorithm withdrawn after security vulnerability discovery

It's official: HAWK PQC is out. The algorithm has been pulled from consideration as a U.S. standard after a security model uncovered a major mathematical flaw. This digital signature scheme was built to protect data against future quantum computer attacks, and it had successfully cleared two rounds of testing by the National Institute of Standards and Technology before entering a third round, which was designed to catch the very weaknesses that were eventually found. So the scrutiny worked. But that's little comfort now.

The Mythos AI security model identified the vulnerability. And the algorithm's developer made a swift choice, pulling it from active deployment entirely. That decision came after a demonstration where the model was tasked with attacking two separate cryptographic systems, and the resulting findings point to notable shifts in how researchers might approach cryptanalysis going forward, though it's still early days. It's a big deal.

The mechanics of the attack

The researcher prompted the model to investigate the mathematical problems protecting the system. It operated semi-autonomously within an agentic framework. The security of that scheme rested on the Lattice Isomorphism Problem, which is typically considered resistant to quantum-based threats, so the model’s task was no small feat. It reviewed existing literature. It ran computational experiments. And through those steps, it found a method for detecting automorphism symmetries that had previously gone unnoticed. That’s a breakthrough.

black flat screen computer monitor

The implications were immediate. The model's discovery effectively halved the algorithm's key strength, a blow that struck at the very core of its security and left the entire system exposed in a way that demanded a swift and decisive response.

Market Context: According to the 2024 Global Digital Trust Insights survey by PwC, the percentage of companies that saw a data breach over USD 1M increased significantly, from 27% to 36%, year-over-year.
But doubling the key size could mitigate the weakness, though it would render the system less attractive when compared to other available options. So the attack unfolded through two independent agents working in tandem, with one initially rejecting the approach before the pair finally reached a consensus on its effectiveness. That consensus mattered. It changed everything.

What the findings mean

Perspective matters here. These results don't break current systems, nor do they make existing encryption unusable, so there's no immediate reason to panic or rush to replace foundational technology that still works. But the tests were performed on weakened challenge instances rather than production-ready systems, which is a critical distinction to keep in mind. Still, the results highlight a shifting environment for cryptographic research, and that shift is worth watching closely. It's real.

  • The attack required roughly 60 hours of work and 100,000 dollars in compute costs.
  • The model utilized known mathematical tools rather than creating entirely new methods.
  • The effort resulted in a 200-fold to 800-fold reduction in time for certain AES attacks.
  • The discovery rendered the candidate algorithm less competitive than alternatives like ML-DSA and FN-DSA.

Matthew Green, a professor at Johns Hopkins, observed that the strength of the process lay in combining existing, well-understood tools rather than inventing new mathematics. He noted the following regarding the discovery:

What is particularly concerning (and so especially ripe for AI) is that the attack does not invent fundamentally new mathematics. It simply extends a bunch of tools that were lying around and well-known, and gets a good result.

The state of cryptographic testing

The model also explored the AES cipher, successfully identifying a new way to perform a meet-in-the-middle attack. It's a clever trick. This involved using a specific fingerprinting algorithm to reduce the number of required plaintext inputs, and while the reduction is notable, the method remains beyond what would be feasible outside of a laboratory environment. But Google expert Sophie Schmieg noted that the candidate was already suspected of holding weaknesses that would eventually come to light. So don't expect this to change your daily life.

Skeptics will scoff. But the reality is stark: these models can now automate bug discovery, a capability researchers can't ignore, and the evidence is mounting faster than the doubters can dismiss it. Standard human verification processes are already struggling to keep pace with the speed of these discoveries, and that gap widens with every passing week as the models churn out fresh findings. So the bottleneck for the industry may shift toward the human effort required to validate novelty and utility, especially as models begin to produce more research autonomously, leaving teams to sort through an avalanche of claims. It's a daunting load. We've reached a tipping point where the machines outrun the checkers.

What happens next

The candidate's removal from the standard-setting process closes its specific path toward adoption. But for the broader field, the real challenge remains in determining whether these AI-assisted methods represent a true leap forward or merely an incremental step that conventional research might have reached independently. It's a tough question. Future scrutiny will likely focus on whether these models can successfully challenge more established systems, such as RSA or elliptic curve cryptography, and that's a bar they can't easily clear.

The race to secure data against quantum threats remains active. It's moving fast. But right now, the current results are confined to testing environments, so we can't claim victory yet, even though the evidence clearly suggests that language models will play a growing part in the adversarial testing of digital security, a shift that demands attention. So security professionals must now consider a landscape where the tools used to break codes are becoming as sophisticated as the tools used to build them, and that's a reality they can't ignore.

Frequently Asked Questions

What was the HAWK PQC algorithm and why was it withdrawn?

The HAWK PQC algorithm was a digital signature scheme designed to protect data against future quantum computer attacks. It was withdrawn after a security model uncovered a major mathematical flaw, and the developer made a swift choice to pull it from active deployment entirely.

How did the Mythos AI security model uncover the vulnerability in HAWK?

The researcher prompted the model to investigate the mathematical problems protecting the system, operating semi-autonomously within an agentic framework. It reviewed existing literature, ran computational experiments, and found a method for detecting automorphism symmetries that had previously gone unnoticed, effectively halving the algorithm's key strength.

What was the role of the two independent agents in the attack on HAWK?

The attack unfolded through two independent agents working in tandem, with one initially rejecting the approach before the pair finally reached a consensus on its effectiveness. That consensus changed everything and led to the finding being confirmed.

What were the costs and time involved in the attack on HAWK?

The attack required roughly 60 hours of work and $100,000 in compute costs. The model utilized known mathematical tools rather than creating entirely new methods, resulting in a 200-fold to 800-fold reduction in time for certain AES attacks.

What are the broader implications of the HAWK findings for cryptographic research?

The results highlight a shifting environment for cryptographic research, showing that language models can automate bug discovery. Standard human verification processes are struggling to keep pace with the speed of these discoveries, and the bottleneck may shift toward human effort required to validate novelty and utility.

Marcus Thorne
Written by
Senior AI Reporter

Marcus Thorne covers the fast-moving field of artificial intelligence, with a particular interest in large language models, automation and the companies driving the technology forward. He aims to cut through the hype and explain what these systems can and cannot do.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement