Anthropic’s Mythos AI Breaks Quantum-Resistant HAWK Algorithm
Anthropic's Mythos security model found a fatal flaw in HAWK, a post-quantum cryptography candidate under NIST evaluation. Its developer withdrew it Tuesday.
Anthropic's security-focused AI model Mythos has found a fatal weakness in HAWK, a post-quantum cryptography (PQC) algorithm that was under active consideration for US standardisation by NIST. HAWK is a digital signature scheme built to resist attacks from future quantum computers. It had cleared two full rounds of NIST testing without issue. After Anthropic published the findings on Monday, HAWK's developer announced Tuesday that he was withdrawing the algorithm from the process entirely.
What happened
| Detail | Fact |
|---|---|
| Algorithm affected | HAWK |
| Algorithm type | Digital signature scheme, post-quantum |
| AI model responsible | Mythos (Anthropic) |
| NIST rounds completed | 2 full rounds passed; flaw found in round 3 |
| Announcement date | Monday (Anthropic) |
| Withdrawal date | Tuesday (developer) |
HAWK is a digital signature scheme, meaning it is used to verify the authenticity of messages or data, designed to hold up against attacks from quantum computers. Quantum computers, once powerful enough, are expected to break most of the encryption standards businesses and governments rely on today. NIST, the US standards body, has been running a multi-year competition to identify and certify replacement algorithms, called PQC (post-quantum cryptographic) algorithms, before that threat becomes real.
HAWK cleared two rounds of that competition, meaning it survived widespread scrutiny from cryptographers worldwide. It was in round three, specifically designed to catch subtle and deeply buried flaws, when Anthropic’s Mythos model identified the weakness that rendered HAWK broken. Anthropic published the results on Monday. By Tuesday, HAWK’s developer had pulled it from contention.
Why it matters
The NIST PQC process is one of the most carefully watched cryptography projects in recent memory. The algorithms that come out of it will likely protect financial transactions, government communications, and web infrastructure for decades. A candidate surviving two full rounds before being broken is not unusual, but having an AI model be the instrument that finds the flaw is new territory.
For businesses, this is a reminder that PQC migration is not a simple swap. Algorithms can be pulled at any stage, and the standards are still being refined. If you are already planning a migration to post-quantum encryption, you need to track which algorithms are currently active in the NIST process, not just which ones were approved years ago.
The Mythos finding also signals a shift in how cryptographic auditing might work going forward. AI-assisted analysis can cover ground that human researchers, working under time and resource constraints, might miss. The question is whether that cuts both ways: adversaries could use the same class of tools to probe algorithms that have already been standardised.
Our take
This is a genuinely significant result. Not because an algorithm failed, which happens, but because an AI model found a flaw that years of expert human review did not catch. That is worth taking seriously, not as a reason to distrust all PQC algorithms, but as a signal that AI-assisted security research is moving from a novelty to a real part of the cryptography toolkit.
For most businesses, the practical action is not panic but awareness. The NIST PQC shortlist has other approved algorithms, and the process has not collapsed. But if you have vendors or infrastructure teams telling you to adopt a specific PQC scheme, it is worth asking which one and checking its current NIST status before committing.
We cover how AI tooling is reshaping technical work across the board, from AI code generation to security research. This case shows the stakes can be high when AI gets things right, not just when it gets things wrong. If you are thinking about how AI could support your own technical or security workflows, our AI integration service covers practical implementation for business environments.
What to do about it
- Check which PQC algorithms your vendors or infrastructure teams are planning to adopt and confirm they are still active in the NIST process.
- Avoid locking in any single PQC algorithm until NIST finalises its latest round of standards.
- Watch the NIST PQC project page directly for updates on remaining candidates.
- If you are early in a cryptography migration, build in flexibility to swap algorithms without a full system rebuild.
The safest position right now is to stay informed and keep your options open.
Frequently asked questions
What is the HAWK cryptography algorithm?
HAWK is a digital signature scheme designed to resist attacks from quantum computers. It was a candidate in NIST's post-quantum cryptography standardisation process, where it passed two rounds of evaluation before a flaw was found.
How did Anthropic's Mythos break HAWK?
Anthropic's Mythos security AI model identified a weakness in HAWK during NIST's third evaluation round. The flaw rendered the algorithm broken. Anthropic published the results on Monday, and the developer withdrew HAWK on Tuesday.
Is HAWK still being considered as a NIST PQC standard?
No. The developer of HAWK withdrew it from the NIST post-quantum cryptography process on Tuesday, the day after Anthropic published Mythos's findings.
What is NIST's post-quantum cryptography process?
NIST runs a multi-round competition to evaluate and certify cryptographic algorithms that can withstand attacks from quantum computers. The goal is to replace current encryption standards before quantum computers become powerful enough to break them.