Top cryptographer warns AI's cryptanalysis skills are arriving at the worst possible moment for the post-quantum transition
Matthew Green, one of the world's leading cryptographers, says AI's emerging capability to break cryptographic systems is arriving during the most fragile moment in the history of the field: the global transition from established RSA and elliptic curve algorithms to untested post-quantum standards. Green, commenting on Anthropic's recent cryptography research, argues that if AI gets good enough at cryptanalysis, it could either validate the mathematical problems the world is betting its security on or expose catastrophic weaknesses before the migration is complete. The assessment highlights a collision between rapidly advancing AI capabilities and the most consequential cryptographic transition ever attempted.

When the Codebreaker Arrives Mid-Migration
Matthew Green, a cryptographer and professor at Johns Hopkins University 1, sees a collision coming. AI systems are beginning to demonstrate real cryptanalysis capability at the exact moment the world is replacing the cryptographic foundations of the internet.
Green was reacting to Anthropic's publication of two cryptanalysis results, both produced by Claude Mythos, an unreleased advanced model 1. His assessment: "If there was ever a perfect time for a massive new public cryptanalysis capability to come on line, we're in it"
2.
A Migration in Progress
The timing Green points to is specific. NIST finalized three post-quantum cryptography standards in August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), all based on lattice and hash problems designed to resist quantum computers 3. Under the transition plan in NIST IR 8547, quantum-vulnerable algorithms like RSA and elliptic curve cryptography are set for deprecation by 2035
3. NIST's own guidance notes that deploying modern public-key infrastructure historically took nearly two decades
3.
The migration is underway but far from complete. NIST is still standardizing additional algorithms, including Falcon (a digital signature scheme) and HQC (a key-encapsulation mechanism), and running a second round of evaluation for further signature candidates 3. Algorithms still under evaluation are the ones most exposed to a new cryptanalytic capability arriving mid-process.
What Anthropic's Results Actually Did
Neither result breaks anything in production. The first is a key-recovery attack against HAWK, a proposed post-quantum signature scheme based on the module Lattice Isomorphism Problem. HAWK is not standardized or deployed. It is related to Falcon but uses a different hard problem, and the attack does not transfer 1. The attack halves HAWK's security bits but remains exponential-time, meaning it could theoretically be mitigated by doubling key sizes, though that would undercut HAWK's reason for existing, which is efficiency
1.
The second result is an improved attack on a reduced-round version of AES. Full AES runs 10 to 14 rounds depending on key size. The attack targets a 7-round variant and requires roughly 2^89 cipher operations plus 2^105 chosen-plaintext encryptions, figures so large they exist only as theoretical analysis 1.
The Method, Not the Breakthrough
What caught Green's attention is how the HAWK result was achieved. The attack does not invent fundamentally new mathematics. It takes existing, well-known cryptanalytic tools and applies them more exhaustively than human research teams had 1. Green relayed that when he asked Claude to assess its own work, the model said the ingredients were not exotic and that the result came from doing "a much more thorough job applying all of our known tools"
1.
That is the capability that scales without new breakthroughs. It needs to be relentless and precise at applying the tools that already exist. As that capability improves, each new result lands on standards and candidates that have not yet been deployed at scale.
Green sees a best case: AI cryptanalysis validates the problems the world is betting on and hardens the field before mass deployment 2.
What This Changes for Migration Planning
For security teams, Green's framing adds a variable to migration planning that did not exist when NIST began this process in 2016 3. The 2035 deprecation deadline was built around quantum computing projections. It was not built around the pace of AI.
The signal to watch is specific: whether the next AI-produced cryptanalysis result targets an algorithm NIST has already finalized as a standard. The HAWK attack hit a proposed scheme still in evaluation. An attack on ML-KEM or ML-DSA would land on algorithms organizations are being told to deploy right now 3. That is the line between a field-strengthening exercise and a migration emergency.
References
Cite this story
ProvenBrief (2026). "Top cryptographer warns AI's cryptanalysis skills are arriving at the worst possible moment for the post-quantum transition." ProvenBrief. https://provenbrief.com/story/top-cryptographer-warns-ai-s-cryptanalysis-skills-are-arriving-at-the-worst-poss
Free to quote and link with attribution. Republishing in full or AI-training use requires a license.
Get the next brief in your inbox
One weekly email. Every claim verified against primary sources before we hit send.
This story
WordsProduced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.