An AI found a weakness in a post-quantum candidate. The standards you use are fine.
A signature scheme called HAWK, one of the candidates NIST is still evaluating, was weakened by an attack an AI model discovered. The algorithms already finalized and being deployed, ML-KEM and ML-DSA, are not affected.
Over the next few days you may see a headline along the lines of "an AI just broke post-quantum cryptography." It did not. Here is what actually happened, and why the encryption you are moving to is unaffected.
What happened
On 28 July 2026, Anthropic published research in which one of its AI models, Claude Mythos, found a previously unknown weakness in HAWK, a post-quantum digital signature scheme. The flaw is a hidden symmetry in the mathematics HAWK is built on. Exploiting it roughly halves the effective size of HAWK's keys: for the smallest version, HAWK-256, the effort to recover a key dropped from around 2^64 to about 2^38.
Why it is not the disaster the headline suggests
HAWK is not a finalized standard, and nobody is relying on it. It is one of the extra candidates NIST is still evaluating in a separate process meant to add more signature options alongside the ones already chosen. Putting candidates under exactly this kind of scrutiny, before they are standardized, is the whole point of that process. A weakness found now is a candidate that can be strengthened or dropped before anyone builds on it.
The part that matters for you
The algorithms that are finalized and actually being deployed are untouched:
- ML-KEM (FIPS 203), the key exchange that protects connections against harvest-now-decrypt-later.
- ML-DSA (FIPS 204), the default post-quantum signature.
Anthropic's own write-up is explicit that the result is specific to HAWK, does not affect other candidates or lattice-based cryptography in general, and that no production software has to change. If you have already turned on post-quantum key exchange, nothing here changes that. If you have not, this is not a reason to wait.
The wider point
There is a larger signal here: AI is becoming a practical tool for finding weaknesses in cryptography, and that cuts both ways. It means candidates will be tested harder and faster than before, which is good, and it means the same capability exists on the other side. Either way the response is the one it has always been. Keep your cryptography agile, stay on the finalized standards, and do not build on anything that has not been through the wringer. It is exactly why NIST deliberately keeps more than one option in each category.
Sources
- anthropic.comhttps://www.anthropic.com/research/discovering-cryptographic-weaknesses
- groups.google.comhttps://groups.google.com/a/list.nist.gov/g/pqc-forum/c/2r2u6SbHun4
We cite original sources only. No news outlets or aggregators.
Comments
Leave a comment
Get the next one
We email when there is something new. No noise.