Mythos AI Finds HAWK PQC Algorithm Flaw
An Anthropic security model called Mythos identified a flaw in the HAWK post-quantum cryptographic algorithm.
HAWK PQC algorithm withdrawn after security vulnerability discovery
It's official: HAWK PQC is out. The algorithm has been pulled from consideration as a U.S. standard after a security model uncovered a major mathematical flaw. This digital signature scheme was built to protect data against future quantum computer attacks, and it had successfully cleared two rounds of testing by the National Institute of Standards and Technology before entering a third round, which was designed to catch the very weaknesses that were eventually found. So the scrutiny worked. But that's little comfort now.
The Mythos AI security model identified the vulnerability. And the algorithm's developer made a swift choice, pulling it from active deployment entirely. That decision came after a demonstration where the model was tasked with attacking two separate cryptographic systems, and the resulting findings point to notable shifts in how researchers might approach cryptanalysis going forward, though it's still early days. It's a big deal.
The mechanics of the attack
The researcher prompted the model to investigate the mathematical problems protecting the system. It operated semi-autonomously within an agentic framework. The security of that scheme rested on the Lattice Isomorphism Problem, which is typically considered resistant to quantum-based threats, so the model’s task was no small feat. It reviewed existing literature. It ran computational experiments. And through those steps, it found a method for detecting automorphism symmetries that had previously gone unnoticed. That’s a breakthrough.

The implications were immediate. The model's discovery effectively halved the algorithm's key strength, a blow that struck at the very core of its security and left the entire system exposed in a way that demanded a swift and decisive response.
What the findings mean
Perspective matters here. These results don't break current systems, nor do they make existing encryption unusable, so there's no immediate reason to panic or rush to replace foundational technology that still works. But the tests were performed on weakened challenge instances rather than production-ready systems, which is a critical distinction to keep in mind. Still, the results highlight a shifting environment for cryptographic research, and that shift is worth watching closely. It's real.
- The attack required roughly 60 hours of work and 100,000 dollars in compute costs.
- The model utilized known mathematical tools rather than creating entirely new methods.
- The effort resulted in a 200-fold to 800-fold reduction in time for certain AES attacks.
- The discovery rendered the candidate algorithm less competitive than alternatives like ML-DSA and FN-DSA.
Matthew Green, a professor at Johns Hopkins, observed that the strength of the process lay in combining existing, well-understood tools rather than inventing new mathematics. He noted the following regarding the discovery:
What is particularly concerning (and so especially ripe for AI) is that the attack does not invent fundamentally new mathematics. It simply extends a bunch of tools that were lying around and well-known, and gets a good result.
The state of cryptographic testing
The model also explored the AES cipher, successfully identifying a new way to perform a meet-in-the-middle attack. It's a clever trick. This involved using a specific fingerprinting algorithm to reduce the number of required plaintext inputs, and while the reduction is notable, the method remains beyond what would be feasible outside of a laboratory environment. But Google expert Sophie Schmieg noted that the candidate was already suspected of holding weaknesses that would eventually come to light. So don't expect this to change your daily life.
Skeptics will scoff. But the reality is stark: these models can now automate bug discovery, a capability researchers can't ignore, and the evidence is mounting faster than the doubters can dismiss it. Standard human verification processes are already struggling to keep pace with the speed of these discoveries, and that gap widens with every passing week as the models churn out fresh findings. So the bottleneck for the industry may shift toward the human effort required to validate novelty and utility, especially as models begin to produce more research autonomously, leaving teams to sort through an avalanche of claims. It's a daunting load. We've reached a tipping point where the machines outrun the checkers.
What happens next
The candidate's removal from the standard-setting process closes its specific path toward adoption. But for the broader field, the real challenge remains in determining whether these AI-assisted methods represent a true leap forward or merely an incremental step that conventional research might have reached independently. It's a tough question. Future scrutiny will likely focus on whether these models can successfully challenge more established systems, such as RSA or elliptic curve cryptography, and that's a bar they can't easily clear.
The race to secure data against quantum threats remains active. It's moving fast. But right now, the current results are confined to testing environments, so we can't claim victory yet, even though the evidence clearly suggests that language models will play a growing part in the adversarial testing of digital security, a shift that demands attention. So security professionals must now consider a landscape where the tools used to break codes are becoming as sophisticated as the tools used to build them, and that's a reality they can't ignore.
Frequently Asked Questions
What was the HAWK PQC algorithm and why was it withdrawn?
The HAWK PQC algorithm was a digital signature scheme designed to protect data against future quantum computer attacks. It was withdrawn after a security model uncovered a major mathematical flaw, and the developer made a swift choice to pull it from active deployment entirely.
How did the Mythos AI security model uncover the vulnerability in HAWK?
The researcher prompted the model to investigate the mathematical problems protecting the system, operating semi-autonomously within an agentic framework. It reviewed existing literature, ran computational experiments, and found a method for detecting automorphism symmetries that had previously gone unnoticed, effectively halving the algorithm's key strength.
What was the role of the two independent agents in the attack on HAWK?
The attack unfolded through two independent agents working in tandem, with one initially rejecting the approach before the pair finally reached a consensus on its effectiveness. That consensus changed everything and led to the finding being confirmed.
What were the costs and time involved in the attack on HAWK?
The attack required roughly 60 hours of work and $100,000 in compute costs. The model utilized known mathematical tools rather than creating entirely new methods, resulting in a 200-fold to 800-fold reduction in time for certain AES attacks.
What are the broader implications of the HAWK findings for cryptographic research?
The results highlight a shifting environment for cryptographic research, showing that language models can automate bug discovery. Standard human verification processes are struggling to keep pace with the speed of these discoveries, and the bottleneck may shift toward human effort required to validate novelty and utility.
💬 Comments (0)
No comments yet. Be the first!













