Post-AI Cryptography?

11 views
Skip to first unread message

Ruy Jose Guerra Barretto de Queiroz

unread,
Jul 30, 2026, 1:28:33 PM (13 days ago) Jul 30
to Lista acadêmica brasileira dos profissionais e estudantes da área de LOGICA
O Claude Mythos Preview quebrou uma das novas candidatas a padronização pelo NIST de esquema de assinatura digital resistente a ataques de computadores quânticos: a proposta denominada de HAWK. Os proponentes da HAWK reconheceram a vulnerabilidade e retiraram a candidatura.



"Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems. This post describes both findings in more detail and discusses the implications for cryptography in an age of powerful AI models."



"One can even imagine a crisis in cryptography: in the worst-case scenario, all human-designed cryptosystems are broken by AI. Whether or not that happens, a new era—Post-AI Cryptography—has arrived."

Cong Ling


---------- Mensagem encaminhada ---------
De: Steve Weis <Desconhecido>
Data: terça-feira, 28 de julho de 2026 às 14:06:14 UTC-3
Assunto: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
Para: 


Hello pqc-forum. We would like to announce an improved key recovery attack against HAWK-n that reduces to SVP in dimension n/2 + 1. The paper will appear at https://anthropic.com/document/hawk_key_recovery.pdf and is linked to from an accompanying blog post that will shortly be live: https://www.anthropic.com/research/discovering-cryptographic-weaknesses

In the gate-count model of AGPS'20, the improved attack lowers the key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from 2^288 to 2^182. We demonstrate this with a practical implementation that recovers a HAWK-256 secret key end-to-end in a few hours on a single server. The implementation can be found at: https://github.com/anthropics/cryptography-research-demo

This result does not impact Falcon, ML-DSA, or other latticed-based schemes.

We would like to thank the HAWK team for their help verifying this result and for their feedback. We would also like to acknowledge that this was found by Claude, with minimal technical guidance from people. For more information on the process, please refer to the above blog post.

Thank you very much.


---------- Forwarded message ---------
De: 'Cong Ling' via pqc-forum 
Date: qui., 30 de jul. de 2026 às 06:25
Subject: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
To: pqc-forum 
Cc: 


Dear Colleagues,

This is a historic moment in cryptology: AI has beaten humans at cryptanalysis. We would like to share a few thoughts with the PQC community based on our own experience.

There are other dimension-reduction attacks on HAWK in literature. At Eurocrypt 2026, we proposed a dimension-halving algorithm for quaternion Ideal-SVP, which potentially implies that HAWK-n key recovery can be reduced to (cyclotomic) Ideal-SVP in dimension n:

https://eprint.iacr.org/2025/1448

Later, we proposed another guessing attack based on advanced number theory, under a few heuristic assumptions:

https://eprint.iacr.org/2026/1318

However, one of these heuristics was soon found to be invalid by colleagues with the assistance of AI.

Apparently, we were outpaced by AI in both cases. A couple of lessons we have learned are: (a) humans can make mistakes; and (b) humans are slower than AI. Beyond cryptanalysis itself, the use of AI to check mathematical proofs is becoming an increasingly serious issue.

One can even imagine a crisis in cryptography: in the worst-case scenario, all human-designed cryptosystems are broken by AI. Whether or not that happens, a new era—Post-AI Cryptography—has arrived.

Cong Ling

Reply all
Reply to author
Forward
0 new messages