The HAWK Collapse and the AI Cryptanalysis Race

AI-generated image · US National Wire
The failure of a promising post-quantum candidate via Anthropic's Mythos model suggests that the roadmap for future security is being rewritten by agentic AI.
The recent withdrawal of HAWK from the running for official U.S. security standards is more than a technical footnote; it is a signal that the race to secure our digital future against quantum computing is shifting.
As reported by Ars Technica, HAWK—a digital signature scheme designed to withstand quantum attacks—was effectively neutralized after Anthropic's Mythos AI security model uncovered a fatal flaw. The algorithm had previously survived two rounds of testing by the National Institute of Standards and Technology (NIST) and was currently in a third round of evaluation. Following the results released by Anthropic, the developer said he was withdrawing the algorithm on Tuesday.
Opinion: This is not merely a failure of one algorithm, but a demonstration that our current defensive roadmap is being outpaced by the offensive capabilities of AI. The danger is not that AI is inventing new mathematics, but that it is mastering the synthesis of existing knowledge at a scale humans cannot match.
According to Ars Technica, the attack on HAWK was particularly efficient. An Anthropic researcher with no background in cryptography used the Mythos model to improve an existing attack, cutting the algorithm's key strength in half. This was achieved with approximately $100,000 in compute costs and 60 hours of work. The security of HAWK relied on the Lattice Isomorphism Problem, and the AI discovered a previously unknown method for finding automorphism symmetries to break it.
Matthew Green, a cryptography expert and professor at Johns Hopkins, noted that the discovery is concerning because it did not require fundamentally new mathematics. Instead, the AI extended a set of well-known, existing tools to achieve the result. Anthropic detailed that the Mythos model operated in an agentic harness, utilizing two separate agents that worked independently before collaborating to verify the attack's effectiveness through a literature review and computational experiments.
While the impact is significant, some context is necessary. Ars Technica notes that these attacks were performed on "challenge instances"—weakened versions of the systems provided for peer review—and the underlying mathematical primitives remain safe for now. Moreover, the techniques would likely be impractical to execute outside controlled testing conditions.
Still, the competitive landscape of post-quantum cryptography (PQC) has shifted. Sophie Schmieg, a PQC expert at Google, stated that while HAWK was already suspected of having weaknesses, the method found by Mythos makes it less competitive than other PQC digital signature schemes, specifically FN-DSA and ML-DSA. In Schmieg's words, "basically with this paper, HAWK is dead."

