Anthropic Research has published findings detailing how Claude Mythos Preview was used to discover improved ways to attack cryptographic algorithms. This work includes weakening a post-quantum digital signature scheme and identifying a new attack vector for a round-reduced version of the Advanced Encryption Standard (AES).
Key Points
- Claude Mythos Preview was used to discover improved attacks on cryptographic algorithms.
- One attack significantly weakens HAWK, a digital signature scheme that is a third-round candidate in the NIST call for post-quantum cryptographic systems.
- Claude Mythos Preview improved the best-known attack on HAWK in 60 hours, effectively halving its key strength, despite HAWK having undergone two years of human review.
- A second attack identified a new method against round-reduced AES, improving the speed of previous best attacks by 200-800x.
- Neither of these findings currently impacts production systems; HAWK is not deployed, and the AES attack targets a reduced version, not the full cipher.
- The development of these results cost approximately $100,000 in API costs for each finding.
- Anthropic partnered with academics to create CryptanalysisBench, a benchmark for evaluating LLM capabilities in cryptanalysis.
Context
According to Anthropic, Claude Mythos Preview previously demonstrated an ability to find and exploit vulnerabilities in various software, including cryptographic libraries, due to implementation errors. The current research extends this by showing the model's capacity to find mathematical flaws within the algorithms themselves. Cryptographic algorithms are fundamental to digital security, protecting data in applications like online banking and email.
Why It Matters
This research indicates that advanced AI models could play a role in identifying vulnerabilities in cryptographic algorithms, both before and after their deployment. This capability could influence how cryptographic systems are stress-tested and ultimately secured, requiring builders and researchers to consider AI-driven cryptanalysis in their development and evaluation processes.
What To Do
- Note that Claude Mythos Preview was able to achieve these results mostly autonomously, with one HAWK attack developed over a week with a researcher, and the AES attack discovered fully autonomously with a scaffold.
- Watch for further details on other cryptographic findings that Anthropic plans to release.
- Consider the implications of AI models in cryptanalysis when evaluating the robustness of cryptographic systems.
- Explore CryptanalysisBench as a resource for evaluating LLM capabilities in cryptanalysis.
Keep Exploring
/atlas/claude-family
