Anthropic's Mythos cracked a 7-round AES variant for $100K in API costs
Curated by the Inblix editorial team
Anthropic’s Claude Mythos Preview model just spent three days and about $100,000 in compute to find a real mathematical weakness in a reduced-round version of AES, the encryption standard that secures most of the internet. It’s not an immediate threat—the attack targets a 7-round variant, not the full 10-round cipher in production use—but the sheer autonomy of the discovery is what’s raising eyebrows. The same multi-agent system also found an improved attack on HAWK, a post-quantum signature scheme that had survived over two years of expert human review, in just 60 hours.
The human role here was largely project management. Anthropic says the researcher overseeing the AES work wasn’t a cryptography expert and provided only a handful of prompts. One telling moment: Mythos initially balked at the task, flatly stating further improvements were likely impossible. It took a nudge to look for “genuinely novel ideas” before the model developed what Anthropic calls a “Möbius Bridge” fingerprinting method, improving on the best previous attacks by a factor of 200 to 800.
The findings, which Anthropic shared with the U.S. government and the HAWK authors before going public, don’t break anything you use today. But they puncture a quiet assumption. The security of these algorithms has always rested on the idea that finding such weaknesses requires rare human ingenuity and years of specialized training. Mythos suggests that a sufficiently motivated AI with a big enough budget can start stress-testing those foundations in ways we haven’t systematically accounted for.
This is still a preview model, and Anthropic is keeping it locked down. They’ve also released a benchmark, CryptanalysisBench, with several universities so others can measure what language models can actually do in this space. The real question isn’t whether this specific AES attack matters—it’s what happens when $100,000 in API costs becomes $10,000, then $1,000, and the patience of these systems is aimed at protocols with higher stakes.
💡 Key Takeaways
- Anthropic's Mythos model found a cryptographic weakness in a reduced 7-round AES variant with minimal human guidance, improving attack efficiency by a factor of up to 800.
- The same system exploited a previously undetected symmetry in the HAWK post-quantum signature scheme in 60 hours, after human experts had reviewed it for over two years.
- The human researchers acted primarily as project managers, with the AI initially refusing the AES challenge before producing results after being prompted to seek novel ideas.
- Anthropic has restricted public access to Mythos Preview and is working with academic partners on a benchmark to systematically evaluate AI cryptanalysis capabilities.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.