Anthropic: Mythos Uncovers Cryptographic Flaws in 60 Hours

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Anthropic: Mythos Unveils Cryptographic Flaws in 60 Hours
Anthropic announces that its model Mythos has discovered vulnerabilities in cryptographic algorithms that secure the Internet.
The AI model Claude Mythos Preview identified mathematical weaknesses in cryptographic algorithms, including a reduced version of AES, the most widely used symmetric encryption standard in the world. Anthropic clarifies that these discoveries have no immediate impact on currently used systems.
Working largely autonomously within a multi-agent system, the model developed two attacks at an API cost of approximately $100,000 each. According to Anthropic, human researchers primarily managed the project, provided simple instructions, and verified the results afterward.
Discoveries of Mythos
The model developed an enhanced attack on the post-quantum signature scheme HAWK and a new attack on a reduced version of the Advanced Encryption Standard (AES). Encryption protects nearly everything people do online, and AES is the most widely used symmetric encryption standard for digital data.
Anthropic asserts that none of these discoveries affect systems in use today. HAWK is merely a candidate in an ongoing standardization process led by the National Institute of Standards and Technology (NIST), and the attack on AES applies to a modified version that uses 7 of the 10 rounds of the complete scheme. Nevertheless, these results demonstrate how AI models could challenge fundamental assumptions about Internet security.
Details on the HAWK Attack
HAWK is one of the remaining schemes in the third round of the NIST competition for additional post-quantum signatures. These schemes are designed to remain secure even against future quantum computers. Human experts have examined HAWK for over two years, but Mythos Preview found an enhanced attack in just 60 hours, according to Anthropic.
The attack exploits a previously undetected symmetry in the mathematical grid on which HAWK's security relies. Mythos worked semi-autonomously in a multi-agent system to discover it. One agent initially attempted to dismiss the idea as unrealistic, but a second agent found a way to fully exploit it.
The human researcher had a background in theoretical computer science but was not an expert in network-based cryptography, according to Anthropic. Their role was primarily limited to project management. API costs amounted to approximately $100,000.
Discovery of the AES Attack
The model also found the attack on a reduced version of AES-128 almost entirely autonomously, according to Anthropic. A researcher built a framework that allowed Claude to formulate hypotheses and test them through experiments. Mythos then developed a new fingerprinting method that Anthropic calls "Möbius Bridge."
This method eliminates one of the assumptions an attacker must make and improves upon the best-known attacks by a factor of 200 to 800.
Human incentive played a minor role. The model initially refused to tackle the problem as it deemed further improvements impossible, writing that "If you want a different outcome, the target must change... AES-128 r5/r6 is just really hard." Mythos began to explore more creative approaches only after the researcher encouraged it to seek "really new ideas."
Sharing Results and Access Restrictions
Anthropic shared the results in advance with the U.S. government and industry partners. It also coordinated the disclosure of the HAWK weakness with the authors of the scheme. Mythos Preview remains unavailable to the public.
In collaboration with researchers from ETH Zurich, Tel Aviv University, and Haifa University, Anthropic also developed a benchmark called CryptanalysisBench that allows others to systematically assess the cryptanalytic capabilities of language models.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.