ANALYSIS: Anthropic says it advanced post-quantum cryptanalysis, and no one has checked
Anthropic published research, covered by The Hacker News on July 29, 2026 , claiming its Claude Mythos Preview model derived an end-to-end key-recovery attack against HAWK-256 , a third-round candidate in the NIST…
- Anthropic published research, covered by The Hacker News on July 29, 2026 , claiming its Claude Mythos Preview model derived an end-to-end key-recovery attack against HAWK-256 , a third-round candidate in the NIST…
- Anthropic published research, covered by The Hacker News on July 29, 2026 , claiming its Claude Mythos Preview model derived an end-to-end key-recovery attack against HAWK-256 , a third-round candidate in the NIST post-quantum cryptography standardization process.
- The published implementation gives an expected runtime of about 3 hours and 42 minutes on a 96-core server.
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Anthropic published research, covered by The Hacker News on July 29, 2026, claiming its Claude Mythos Preview model derived an end-to-end key-recovery attack against HAWK-256, a third-round candidate in the NIST post-quantum cryptography standardization process. The published implementation gives an expected runtime of about 3 hours and 42 minutes on a 96-core server. A key-recovery attack against a NIST candidate is not a detail buried in a research paper. It is the kind of claim that should draw scrutiny before it draws applause.
According to Anthropic, the claimed work factor for recovering a HAWK-256 key drops from 2^64 to 2^38 — an enormous reduction, if confirmed, in the computational effort required to break the scheme. The company also claims a 200 to 800 times speedup of an existing "meet-in-the-middle" attack against a reduced, 7-round version of AES-128, out of the standard's normal 10 rounds.
This analysis examines what Anthropic has actually published, what independent artifacts allow outside researchers to verify, and what remains, as of publication, a company statement rather than a peer-reviewed, third-party-confirmed result.
What Anthropic claims about HAWK-256
A drop from an impractical to a theoretically feasible work factor
The claimed drop from a work factor of 2^64 to 2^38 for HAWK-256 represents, in cryptographic terms, a massive reduction: a work factor of 2^38 falls within a range some computing setups could realistically attempt, whereas 2^64 remains firmly in impractical territory for most attackers. This gap is the central technical claim driving the entire announcement.
Anthropic states this attack was derived by its Claude Mythos Preview model, framing the result as evidence of AI systems' growing capacity to independently discover novel cryptanalytic techniques, rather than merely applying known methods faster.
Why HAWK-512 and HAWK-1024 remain out of reach
For the larger variants, HAWK-512 and HAWK-1024, Anthropic's claimed logic-gate estimates drop respectively from 2^150 to 2^108 and from 2^288 to 2^182 — reductions that, however significant in relative terms, still leave both variants firmly in the range of practically unbreakable with current computing resources. A reduction from astronomical to merely enormous is real progress on paper. It changes nothing for anyone actually trying to break the cipher today.
Anthropic itself acknowledges this distinction: the HAWK-256 result is presented as more consequential precisely because its reduced work factor edges toward a range where practical exploitation becomes conceivable, unlike the larger variants.
The second claim: an accelerated attack on reduced AES-128
A speedup on a weakened version of the algorithm, not the real standard
The second result Anthropic claims is a 200 to 800 times speedup of an existing meet-in-the-middle attack, but applied against AES-128 reduced to 7 rounds, not the full standard, which uses 10 rounds in real-world deployment. This distinction matters enormously: AES-128 as actually deployed in production systems worldwide is not the version this attack targets.
The claimed improvement works by removing an exhaustive search step over 256 possibilities that the previous version of the attack required, a genuine algorithmic refinement if confirmed, but one that applies to an already artificially weakened test version of the cipher.
Why Anthropic itself says this changes nothing in production
Anthropic explicitly states that neither of its two published results affects currently deployed production systems: the HAWK attack remains exponential in nature rather than a polynomial-time break, and the AES attack requires a number of chosen plaintexts that remains practically impossible to obtain in a real attack scenario. The company that announced the discovery is also the one setting the limits of its consequences. That symmetry alone justifies an outside look.
This self-imposed caveat is worth noting: Anthropic is not claiming to have broken cryptography used in the real world today, only to have found a measurable theoretical weakening of specific reduced or standardization-candidate variants.
What can actually be independently verified
A published implementation, a partial reproducibility
Anthropic published an implementation of the HAWK-256 attack, complete with the claimed 3 hour 42 minute runtime on a specified 96-core server configuration — a level of technical detail that does allow, in principle, independent researchers to attempt reproduction of the result. This transparency distinguishes the claim from a purely rhetorical announcement with no verifiable substance.
However, publishing an implementation is not the same as having that implementation independently run and confirmed by a third party outside Anthropic. As of July 29, 2026, no publicly documented independent reproduction of either result had been reported.
What NIST has said, and not said
As of July 29, 2026, NIST still lists HAWK as a third-round candidate in its post-quantum standardization process, with no official reaction to Anthropic's claims documented in the sources available for this analysis. The body responsible for deciding HAWK's fate has said nothing yet. Its silence is not a confirmation, any more than it is a denial.
This absence of an official NIST response means the claimed attack has not, as of this writing, been factored into any formal reassessment of HAWK's status in the standardization process — a process that moves on its own institutional timeline, independent of a single company's press cycle.
The broader context: CryptanalysisBench
A benchmark published one week earlier
Anthropic's announcement follows the July 20, 2026 publication of CryptanalysisBench, a 191-task benchmark developed by researchers from ETH Zurich, Anthropic, the University of Haifa, TU Berlin and Tel Aviv University. This multi-institutional collaboration lends the benchmark itself a degree of academic credibility distinct from a single company's internal claims.
On that benchmark, five different AI models reportedly broke between 65% and 86% of first-level cryptographic schemes, according to the results published alongside the benchmark's release — a result that, unlike the HAWK and AES claims, benefits from multi-institutional academic co-authorship.
More analysis
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
Why the benchmark's credibility does not automatically transfer to the later claims
The fact that CryptanalysisBench involved credible academic partners does not mean every subsequent claim Anthropic publishes using models tested on that benchmark inherits the same level of independent verification. A credible benchmark built with universities is not the same thing as a credible result announced by one company, alone, one week later.
The HAWK-256 and AES-128 results were published by Anthropic through its own research blog, without the co-authorship of the external academic institutions involved in CryptanalysisBench, a distinction that matters for assessing the actual level of independent scrutiny each claim has received.
What "AI discovers a cryptographic weakness" actually means here
Discovery assisted by a model, not a fully autonomous breakthrough narrative
Anthropic's framing emphasizes that its Claude Mythos Preview model derived these results, a claim that fits a broader industry narrative about AI systems approaching or exceeding human capability in specialized technical domains. This framing deserves scrutiny distinct from the technical claims themselves: the degree of human guidance, prompt engineering, and iterative correction involved in reaching these results is not fully detailed in the public materials available.
Distinguishing between an AI model producing a result under close human direction and an AI model autonomously discovering a novel technique with minimal guidance is a meaningful technical distinction that the available sources do not fully resolve.
Why this distinction matters for how the claim should be read
If the attacks required extensive human cryptographic expertise to guide, verify, and refine the model's output, the achievement, while still potentially significant, represents a different category of result than a claim of autonomous discovery. Whether Claude found this alone or with a research team correcting every wrong turn changes what the result actually proves about AI capability.
Anthropic's published materials describe the model's role prominently, but the available sources for this analysis do not include a full methodological breakdown of the human-AI division of labor in reaching the published results.
The status of Anthropic's own safety framing
A company stating its own result poses no immediate risk
Anthropic's own characterization that neither result affects current production systems is, itself, a claim made by the same organization that produced and is publicizing the underlying research. This is not, on its own, a reason for suspicion — companies with cryptography expertise routinely make accurate technical assessments of their own findings — but it is a detail worth naming plainly rather than treating as a neutral third-party judgment.
An independent cryptographic audit, separate from Anthropic's own safety assessment, would be needed to fully confirm that the practical implications described match the technical reality of the published attacks.
Why self-assessed safety claims deserve the same scrutiny as capability claims
The same standard of verification that applies to Anthropic's capability claim — that its model found these weaknesses — should also apply to its safety claim — that the weaknesses found do not matter in practice. A company grading its own homework as both a breakthrough and harmless is making two claims, not one, and both deserve to be checked.
Neither claim is inherently implausible, but neither has, as of this analysis, received the kind of independent academic scrutiny that would settle the question definitively.
What independent cryptographers would need to confirm this
The minimum conditions for full verification
Full independent verification of Anthropic's claims would require outside cryptography researchers to run the published implementation themselves, confirm the claimed runtime and work-factor reductions on independent hardware, and publish their own findings through a peer-reviewed or otherwise scrutinized channel. None of these three steps is documented as having occurred in the sources available for this analysis, as of July 29, 2026.
The NIST standardization process itself, given its institutional pace, is unlikely to issue a formal reassessment of HAWK's candidacy status within days of a single company's announcement, regardless of that announcement's technical merit.
A dossier that remains open, not resolved
This analysis does not conclude that Anthropic's claims are false, exaggerated, or fabricated: the published implementation and detailed technical parameters suggest a genuine research effort with real substance behind it. Publishing your work is not the same as having it checked. Anthropic has done the first. Nobody outside the company has yet done the second.
What this analysis does conclude is that the claims remain, as of publication, unconfirmed by an independent third party, a status that differs meaningfully from either "false" or "definitively proven."
Why this matters beyond one company's research blog
The stakes of AI-assisted cryptanalysis for global infrastructure
Post-quantum cryptography standards like HAWK are being developed precisely to protect digital infrastructure against future quantum-computing threats; any credible demonstration that AI models can accelerate attacks against standardization candidates carries real stakes for the security of systems still years away from deployment. This context explains why Anthropic's claims, even unconfirmed, deserve serious attention rather than dismissal.
At the same time, the stakes involved are precisely why premature certainty, in either direction — treating the claim as a confirmed crisis or dismissing it outright — would be a disservice to the seriousness of the underlying question.
What this means for the NIST standardization timeline
If independent researchers eventually confirm Anthropic's HAWK-256 result, it could influence how NIST and the broader cryptographic community weigh HAWK's candidacy relative to competing post-quantum schemes still under consideration. A standard's fate should rest on confirmed mathematics, not on the publication date of a single company's blog post.
Until such confirmation arrives, treating the claim as a settled input into that standardization decision would be premature, regardless of how detailed Anthropic's published materials appear.
How this fits Anthropic's broader public narrative on AI capability
A pattern of publishing capability milestones
This announcement follows a broader pattern in which Anthropic and its competitors regularly publish research highlighting their models' growing capabilities in specialized technical domains, from coding to, now, cryptanalysis. This pattern serves both genuine scientific interest and a clear commercial incentive: demonstrating frontier capability strengthens a company's competitive position in the AI market.
Recognizing this commercial context does not invalidate the underlying research, but it is a relevant factor in understanding why capability announcements of this kind tend to receive rapid, wide media pickup before independent verification catches up.
Why the pace of announcement outstrips the pace of verification
The gap between when a capability claim is published and when independent verification can realistically confirm or refute it is structurally longer than the news cycle covering the initial announcement, a dynamic already observed across multiple recent AI capability claims. The claim travels at the speed of a press release. The proof travels at the speed of peer review. They rarely arrive together.
This structural gap is not unique to Anthropic or to cryptography; it characterizes how capability claims across the entire AI industry are currently disseminated and, much more slowly, verified.
What responsible coverage of this claim requires
Naming the claim precisely, without inflating or deflating it
Responsible coverage of Anthropic's announcement requires stating precisely what was claimed — a reduced work factor for HAWK-256, a speedup against reduced-round AES-128 — without inflating this into "AI breaks encryption," a framing that misrepresents both the scope and the current verification status of the results. This precision is not pedantry; it is the difference between informing the public and needlessly alarming it about the security of systems the claim does not actually threaten.
Equally, dismissing the claim entirely because it originates from a company with commercial interests in demonstrating AI capability would be its own form of imprecision, given the genuine technical detail Anthropic did publish.
What this analysis recommends to readers
Readers should treat Anthropic's HAWK-256 and AES-128 results as credible but unconfirmed research claims, worth following as the story develops, but not yet a basis for concluding that any currently deployed cryptographic system is at risk. A claim worth watching is not the same as a claim worth believing. This one, for now, sits in the first category only.
This analysis will need to be revisited if independent cryptographers publish their own confirmation, refutation, or qualification of Anthropic's published implementation and claimed results.
What history of AI capability claims suggests about the likely outcome
A mixed track record across the industry
Discover
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
Previous AI capability claims across the industry, in domains ranging from mathematical proof discovery to software vulnerability detection, have shown a mixed pattern upon independent verification: some held up largely as described, others required significant qualification once outside researchers examined them closely. This mixed history provides no strong prior in either direction for how Anthropic's cryptanalysis claims will ultimately fare under scrutiny.
What this history does suggest is that patience, rather than immediate acceptance or immediate dismissal, has historically proven the more accurate posture for this category of claim.
Why this specific claim may attract faster scrutiny than most
Because cryptography is a field with an unusually active, technically rigorous community of independent researchers accustomed to publicly checking extraordinary claims, Anthropic's HAWK-256 and AES-128 results may receive faster independent attention than capability claims in less tightly scrutinized technical domains. If any AI capability claim gets checked quickly, cryptography's community is exactly the one built to do it.
This relatively fast-moving scrutiny culture in cryptography research is a reason for cautious optimism that this dossier will not remain unresolved for long, even if it remains unresolved as of this publication.
What remains genuinely uncertain
The open questions this analysis cannot resolve
This analysis cannot determine, based on currently available sources, the precise degree of human guidance involved in reaching Anthropic's published results, whether independent researchers have privately begun attempting reproduction, or how NIST will eventually factor this claim, if confirmed, into its standardization deliberations. These three open questions define the genuine limits of what can be said with confidence today.
Any claim to have definitively settled these questions, in either direction, would exceed what the currently available public record supports.
What would change this analysis's conclusions
Independent confirmation of the claimed work-factor reductions, an official NIST statement addressing the HAWK candidacy in light of Anthropic's claims, or a detailed methodological disclosure clarifying the human-AI division of labor involved would each meaningfully update the conclusions of this analysis. This dossier is not closed. It is dated, and it is waiting for exactly the kind of proof that only time and outside scrutiny can supply.
Until any of these developments occurs, the most accurate description of Anthropic's claim remains: detailed, published, and not yet independently confirmed.
What this episode adds to the broader AI-safety conversation
A concrete data point in an often abstract debate
Much of the public conversation about advanced AI capability and safety operates at a fairly abstract, speculative level; Anthropic's cryptanalysis claim, whatever its ultimate verification status, offers a concrete, technically specific data point that researchers can actually attempt to reproduce or refute. This concreteness is itself valuable, regardless of how the verification ultimately resolves.
Debates about AI capability too often rest on hypothetical scenarios rather than testable claims; this dossier, precisely because it invites independent verification, represents a more productive form of that broader conversation.
Why the industry needs more of this kind of testable claim, not fewer
Regardless of how Anthropic's specific results hold up, the practice of publishing detailed, reproducible implementations alongside capability claims should be encouraged across the AI industry, precisely because it is what makes independent verification possible in the first place. A claim you can actually test is worth more than ten claims you are simply asked to believe.
This standard of reproducibility, even when it leaves a claim's ultimate validity temporarily unresolved, is preferable to capability announcements that offer no path to independent verification at all.
On the same topic
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
OPINION: Merz Under Fire as the CDU Learns the…
On July 29, 2026 , Le Monde describes an " unprecedented…
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
Anthropic's claim that its Claude Mythos Preview model found a significant weakening of HAWK-256, a NIST post-quantum standardization candidate, along with an accelerated attack against a reduced version of AES-128, rests on published, detailed technical materials that permit, at least in principle, independent verification. As of July 29, 2026, no publicly documented independent confirmation of either result exists, and NIST has issued no formal reaction.
Anthropic's own assessment that neither result threatens current production systems is plausible on its technical merits but remains, itself, a claim from the same party announcing the underlying discovery. The distinction between a detailed, reproducible research claim and an independently confirmed scientific result is the central fact this analysis insists on preserving. A published paper is an invitation to verify, not a substitute for the verification itself. Cryptography, of all fields, should be the last to forget that.
This dossier will need to be revisited as independent researchers, and eventually NIST itself, respond to Anthropic's published implementation. Until then, the most accurate description remains that of a serious, well-documented, but unconfirmed claim — neither dismissed nor accepted, simply still open.
Signed Maxime Marquette, columnist
Columnist's Transparency box
Editorial positioning
This text adopts a posture of technical verification, without taking a position on the broader debate over AI capability trajectories. The objective is to separate what Anthropic has published from what independent third parties have confirmed, not to diminish or amplify the significance of the underlying research.
Methodology and sources
This analysis relies on coverage from The Hacker News, Anthropic's own research publication, and independent technology-press coverage of the CryptanalysisBench benchmark and the HAWK-256 and AES-128 claims, as documented as of July 29, 2026. No unlisted source was used to build this analysis.
Nature of the analysis
This text constitutes a factual verification exercise applied to a capability claim, not a cryptographic peer review. The conclusions presented reflect the state of publicly available evidence at the date of publication and may be revised if independent confirmation, refutation, or an official NIST statement emerges.
Sources
Primary sources
Secondary sources
Get the tech columns
AI, platforms, digital power: the next analyses straight to your inbox.
Cite this article
Maxime Marquette (2026). ANALYSIS: Anthropic says it advanced post-quantum cryptanalysis, and no one has checked. MadMax. https://mad-max.co/en/article/analysis-anthropic-says-it-advanced-post-quantum-cryptanalysis-and-no-one-has-ch
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.