In the gate-count model of AGPS'20, the improved attack lowers the key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from 2^288 to 2^182. We demonstrate this with a practical implementation that recovers a HAWK-256 secret key end-to-end in a few hours on a single server. The implementation can be found at:
https://github.com/anthropics/cryptography-research-demo
This result does not impact Falcon, ML-DSA, or other latticed-based schemes.
We would like to thank the HAWK team for their help verifying this result and for their feedback. We would also like to acknowledge that this was found by Claude, with minimal technical guidance from people. For more information on the process, please refer to the above blog post.
Thank you very much.