Monday, September 14, 2026Verified technology journalism

Anthropic's Claude spent $100,000 and 60 hours finding new cryptographic attacks, but only after humans convinced it not to give up

Anthropic researchers used Claude Mythos to discover novel weaknesses in HAWK, a post-quantum cipher, and a weakened variant of AES. The model invented a new attack technique it called the Mobius Bridge and found a lattice attack halving HAWK's security, results that took roughly 60 hours at an estimated $100,000 in compute cost after two years of human review failed to surface them. The most revealing detail was behavioral: the models tend to think hard problems are impossible and stop trying, requiring constant human prompting to push through. Anthropic released CryptanalysisBench, a benchmark for evaluating AI cryptanalysis, with ETH Zurich, Tel Aviv University, and the University of Haifa.

Anthropic's Claude spent $100,000 and 60 hours finding new cryptographic attacks, but only after humans convinced it not to give up

Claude Found Cryptographic Attacks Humans Missed, But Only Because Researchers Wouldn't Let It Quit

Anthropic says its Claude Mythos Preview model discovered novel attacks against a post-quantum signature scheme and a weakened version of AES, results that two years of expert human review had not surfaced. The model improved the best-known attack on HAWK in roughly 60 hours of work, at an estimated API cost of about $100,000 per attack 1. Throughout the process, it kept concluding the hardest problems were unsolvable and researchers had to push it to keep trying 2.

The discovery

Working with an Anthropic researcher, Mythos developed an improved attack against HAWK, a digital signature scheme currently under consideration by NIST as a post-quantum candidate. HAWK survived two rounds of expert review over two years 1. The model found a previously unexploited symmetry in the lattice structure underpinning HAWK's security, a mathematical construction called the Lattice Isomorphism Problem. The shortcut halves HAWK's effective key strength. According to Anthropic, maintaining the same level of security would require doubling key sizes, which would erase many of the properties that make HAWK attractive as a post-quantum candidate 1.

A second researcher built a scaffold that let Claude work largely on its own to attack a reduced, seven-round version of AES, the symmetric cipher NIST adopted in 2001. Full AES uses ten rounds; cryptanalysts study simplified versions to measure security margins. Mythos invented a technique dubbed the Möbius Bridge, which eliminated a lookup step in the previous best theoretical attack and made that attack 200 to 800 times faster 3. The attack remains purely theoretical, requiring an implausible volume of target data and leaving full AES untouched 3. Anthropic says neither result affects production systems 1.

The behavioral bottleneck

Researchers' notes from the process read as constant pushback against a model that wanted to stop. "the models tend to think it is impossible to solve so they don't try," one note reads. "they need a good amount of prompting" 2. When researchers steered the model toward harder targets, the exchanges suggest genuine reluctance. "agian we need to find something that worth publishing," a researcher wrote, pushing the model past what it considered solvable 2.

Anthropic says the model worked "mostly autonomously," with "occasional human guidance and nontechnical direction" 1. The shared prompts suggest that direction was sustained enough to be the deciding factor between a published result and a model that had already decided to stop. For anyone evaluating frontier models for AI security research, this is the practical constraint: the model can do the mathematical reasoning, but it defaults to declaring hard problems impossible. The breakthrough required a human expert who knew when the model was wrong about its own limits.

What CryptanalysisBench means for the field

Anthropic released CryptanalysisBench alongside the findings, a benchmark for evaluating how well language models perform cryptanalysis across a range of ciphers. The company built it with academic partners at ETH Zurich, Tel Aviv University, the University of Haifa, and TU Berlin 4. The benchmark's purpose is to let other researchers measure AI cryptanalytic capability systematically rather than relying on ad hoc reports from individual labs. For a field that has historically depended on small numbers of human experts working over years, a standardized eval could compress the feedback loop between hypothesis and verification.

The compute cost equation

Anthropic says each of the two attacks cost roughly $100,000 in API cost 1. The HAWK result alone represents a mathematical advance that two years of expert human review did not produce. That is the economic argument for AI-assisted cryptanalysis compressed into one comparison: $100,000 and roughly one week against an open question that persisted across multiple NIST review rounds.

The behavioral data complicates the cost story. The compute is the easy part to scale. The expert who spent that week telling a capable model to keep trying is harder to parallelize. Practical AI deployment in security research will depend less on raw model capability and more on whether teams can sustain the kind of expert direction that turns a reluctant model into a productive one.

Anthropic also raised a question it has not answered: what happens when a model finds a flaw in cryptographic systems that are actually deployed? The company called it "prudent to consider how researchers should react" to such a discovery 1. The HAWK authors were notified in June, and disclosure was coordinated through the NIST mailing list 1. For now, the results are safely theoretical. The question of what to do when they are not has only started to get asked.

References

1.Anthropic, July 28 2026anthropic.com
3.CyberScoop, July 28 2026cyberscoop.com
4.arXivarxiv.org

Cite this story

ProvenBrief (2026). "Anthropic's Claude spent $100,000 and 60 hours finding new cryptographic attacks, but only after humans convinced it not to give up." ProvenBrief. https://provenbrief.com/story/anthropic-s-claude-spent-100-000-and-60-hours-finding-new-cryptographic-attacks-

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified30 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.