Bottom line
Anthropic's July 2026 cryptography release is a meaningful frontier-AI warning signal: a model-assisted workflow produced real cryptanalysis results and a benchmark for testing future models. The important boundary is equally clear. Anthropic says the HAWK result concerns an undeployed post-quantum signature candidate, and the AES result concerns a reduced 7-round variant, not full production AES. The story is not "internet encryption is broken." It is "AI may soon become a serious force in finding cryptographic weaknesses, so evaluation and disclosure need to keep up."
What Anthropic published
On July 28, 2026, Anthropic published Discovering cryptographic weaknesses with Claude, a Frontier Red Team post about Claude Mythos Preview assisting cryptanalysis. The post links two technical papers and a benchmark paper:
- HAWK: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1, by Zygimantas Straznickas and Stephen A. Weis of Anthropic.
- Reduced-round AES: Cryptanalysis of 7-Round AES via the Algebraic Structure of its S-box, by Milad Nasr and Nicholas Carlini of Anthropic.
- Benchmark: CryptanalysisBench: Can LLMs do Cryptanalysis?, an arXiv paper by Lukas Fluri, Avital Shafran, Nicholas Carlini, Matthew Jagielski, Milad Nasr, Orr Dunkelman, Eyal Ronen and Florian Tramèr.
Anthropic says it followed responsible-disclosure procedures, consulted academics, and shared advance copies with government and industry partners. For HAWK, Anthropic says it coordinated disclosure with the HAWK authors and the public NIST mailing list.
The HAWK result
HAWK is a post-quantum digital-signature candidate in NIST's additional-signatures process. Anthropic's linked paper describes a key-recovery reduction that substantially lowers estimated attack cost for HAWK parameter sets. The public-interest point is not that HAWK was protecting today's web traffic. Anthropic says HAWK is a candidate scheme and is not deployed.
That is exactly why standardization competitions exist: candidate algorithms are published so researchers can attack them before the world depends on them. The new element is that a frontier AI model helped find and develop the attack.
The reduced-round AES result
AES is one of the core ciphers behind modern digital security. That makes the headline sensitive. But the Anthropic paper is not claiming to break full AES-128. It focuses on a 7-round version of AES-128 under a research threat model. Full AES-128 uses 10 rounds.
Reduced-round cryptanalysis is still useful. Researchers study weakened versions to understand how close attacks are to the real cipher and how design structure behaves under pressure. The correct read is: model-assisted cryptanalysis made progress on a serious research target, not that production AES has failed.
Why CryptanalysisBench matters
CryptanalysisBench turns the broader question into a repeatable evaluation: can large language models find attacks against cryptographic schemes? The arXiv abstract describes 191 tasks across six families of cryptographic primitives, mostly drawn from NIST standardization competitions. It reports that several frontier models can solve many known-break tasks and some harder variants.
That kind of benchmark is important because cryptography is a high-stakes domain where answers can often be checked mathematically. If model capability rises here, defenders need early warning — not after a widely deployed primitive is already under pressure.
What this does not prove
- It does not prove that Claude, or any other model, can freely break production internet encryption.
- It does not show a break of full AES-128, AES-192 or AES-256.
- It does not mean HAWK protects current banking, email or browser sessions; Anthropic identifies it as a candidate scheme.
- It does not remove the need for human cryptographers. Anthropic's own description emphasizes validation, disclosure, academic consultation and careful review.
The practical read
This is a capability warning with a useful safety frame. AI could help defenders stress-test standards before deployment, find implementation mistakes faster, and expand the number of researchers who can audit complex systems. The same capability could also help attackers search for weaknesses in systems that have not been reviewed enough.
Managing expectations means holding both truths at once: this is not a reason to panic about today's encrypted web, and it is not a toy demo. It is a sign that AI security evaluation has to include mathematical and cryptographic domains, not only chat behavior, coding benchmarks or jailbreak prompts.
Source trail
- Anthropic — Discovering cryptographic weaknesses with Claude
- Anthropic PDF — HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
- Anthropic PDF — Cryptanalysis of 7-Round AES via the Algebraic Structure of its S-box
- arXiv — CryptanalysisBench: Can LLMs do Cryptanalysis?
- Managing Expectations source note for this article
Managing Expectations framing
The useful question is not whether the headline sounds scary. It is which target was attacked, whether it is deployed, what assumptions were used, how the result was validated, and what monitoring defenders need before AI-assisted cryptanalysis becomes ordinary.
Open the AI Papers Library