Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet
What happened
Anthropic’s Claude Mythos Preview AI model exposed vulnerabilities in cryptographic algorithms that underpin internet security. The model identified a more effective attack on HAWK, a post-quantum signature scheme vetted by human experts for over two years. Mythos found this flaw in 60 hours using about $100,000 worth of API calls. These weaknesses do not affect cryptographic systems currently in use but reveal how AI can rapidly uncover subtle flaws in theoretically secure protocols.
The risk
This development raises the risk profile for cryptography relying on human-led audits and traditional validation timelines. AI’s ability to detect cryptographic weaknesses quickly at scale pressures security teams to rethink evaluation processes and timelines. While current deployed systems remain safe, future cryptographic designs may face faster obsolescence or require more robust AI-assisted vetting to maintain trust and security.
Why it matters
Cryptographic algorithms secure everything from online banking to government data. Mythos’ discovery signals a shift in the threat model, where AI can accelerate the discovery of vulnerabilities that would take humans years to find. Operators and cryptographers must treat AI as both a tool and a potential adversary in cyber defense, raising the cost and complexity of safely deploying new cryptographic standards. The security community should prepare for more AI-powered security audits as a baseline expectation.
Who should pay attention
Security architects, cryptographers, protocol developers, and infrastructure operators all need to factor in AI-driven vulnerability discovery. Founders and investors in cybersecurity startups should watch for AI tools that augment both offense and defense. Regulators and standards bodies must also consider AI’s impact on cryptographic validation and certification processes to avoid underestimating risk in future protocols.
What to watch next
Observe how Anthropic and other AI developers evolve these models for security testing and whether defenders adopt them broadly. Watch for updates from cryptography standards groups on how they plan to incorporate AI-assisted analysis in vetting new algorithms. Also, monitor any shifts in budget allocations or staffing in security teams to integrate AI-powered auditing tools and countermeasures.
AI Quick Briefs Editorial Desk