AI Discovers Weaknesses in "Future Cryptographic Standards"—The Contents of Two Cryptographic Decryption Studies Published by Anthropic
On July 28th, Anthropic's Frontier Red Team (a specialized team that evaluates the potential risks of the company's AI models) published research titled "Discovering cryptographic weaknesses with Claude." The research describes the discovery of new attack methods against two cryptographic algorithms using the company's cutting-edge model, Claude Mythos Preview. As a journalist with a research background, I would like to carefully examine the contents of this research and its implications.
The Two Algorithms Targeted
The research dealt with two cryptographic techniques with different properties.
The first is "HAWK," a type of post-quantum cryptography designed to maintain security even in the age of quantum computers, and is used for digital signatures (a technology that proves the sender of data). HAWK is one of the candidates in the review process for selecting future cryptographic standards being conducted by the U.S. National Institute of Standards and Technology (NIST). This time, Claude discovered an attack on this scheme with significantly higher precision than existing attack methods.
The second is an attack on "AES," the most widely used symmetric-key cryptography (a method that uses the same key for both encryption and decryption). However, the target was not the standard, complete AES, but a "round-reduced AES" with a reduced number of internal processing rounds, and a new attack method against this version was demonstrated.
Anthropic clearly states that neither discovery "will affect systems currently in actual use." This is because HAWK is a candidate under review and has not yet been officially adopted as a standard, and the round-reduced AES is a simplified version for research purposes, different from the complete AES used in actual operation.
Results "Almost Autonomously" Derived
What is technically interesting about this research is the process of deriving the results. The attack on HAWK was developed by one Anthropic researcher in collaboration with Claude over a week, but the attack on AES was discovered almost entirely autonomously by Claude within a "scaffolding" (a working environment set up for Claude to explore and execute autonomously) prepared by another researcher.
Anthropic explains that the computational cost to derive each result was approximately $100,000 in API usage fees. What's important here is that Claude didn't easily produce these results from the start. Looking at the actual prompt exchanges released by Anthropic, it's clear that the researcher repeatedly faced situations where "the model assumed it couldn't be solved and wouldn't even try," and that persistent guidance was required, such as "don't be satisfied with easy results, but look for a real discovery worth publishing." This demonstrates that AI doesn't automatically solve everything; these kinds of results are only achieved with the right scaffolding and patient prompt design.
The "Dual Nature" of This Research
Anthropic positions this research in a defensive context: "strengthening cryptography by finding vulnerabilities before attackers do." Indeed, this is the very essence of cryptographic research—a process of stress-testing new cryptographic schemes from every angle and building reliability before they become standard.
At the same time, Anthropic acknowledges the "double-edged sword" aspect of these results. When the company previously released Claude Mythos Preview, it demonstrated that the model could autonomously discover and exploit vulnerabilities in virtually any software. This latest achievement in the cryptographic field is an extension of that. As the capabilities of AI models improve, the idea that the same capabilities can be used for both defense and offense has now extended to the extremely fundamental technological field of cryptography.
What Researchers Should Consider
Anthropic also released a new benchmark, CryptanalysisBench, to evaluate the cryptographic decryption capabilities of AI models. This initiative aims to systematically measure and compare the capabilities of AI models across various cryptographic techniques.
The development of this type of benchmark is highly significant. If the capabilities of AI models in the cryptographic field can be continuously and quantitatively tracked, rather than relying solely on individual, flashy announcements, the entire cryptographic community will be able to discuss with greater evidence "what cryptographic standard should be adopted next" and "which model capabilities should we be wary of."
This announcement is particularly noteworthy because it's not an AI company showcasing the capabilities of its own models, but rather a transparent presentation of results to the existing academic community of cryptographic research. We look forward to seeing how other AI companies and independent cryptography researchers will use CryptanalysisBench for further testing and verification.