Sophie Schmieg, an expert in PQC at Google, said HAWK was already suspected to have weaknesses that would eventually be found. Still, the method for halving the key strength found through Mythos makes the candidate algorithm less competitive than existing PQC digital signature schemes such as ML-DSA and FN-DSA.
“Basically with this paper, HAWK is dead,” she wrote.
Less drama, but still kind of neat
The attack against AES produced less dramatic results. It’s based on an improvement found through Mythos for performing a “meet-in-the-middle” attack, which is used to derive a key under a chosen plaintext threat model, the best-known existing attack against AES. The technique inputs large numbers of known plaintext into the crypto system and analyzes the encrypted output for clues that, with enough inputs, eventually reveal an unknown key. Previously, the best-known meet-in-the-middle attack against AES required roughly 2105 plaintext inputs, a number large enough to make the method infeasible.
Mythos helped to find a new meet-in-the-middle technique that relies on a Möbius Bridge, a more sophisticated fingerprinting algorithm used in meet-in-the-middle attacks. Using it, Green said, the code Mythos produced was able to reduce the number of required inputs to 289. Anthropic said that savings can reduce the time required for such attacks by 200- to 800-fold.
The ability to produce that many inputs makes the attack beyond reach outside of the laboratory. Further, the actual speed-up is unknown, since the weakened AES algorithm tested used only 7 rounds. Specification-compliant AES, Green said, uses 10, 12, or 14 rounds, depending on key size.
Anthropic is careful to explicitly spell out most of these caveats. The Monday blog post goes on to argue, however, that the results are nonetheless meaningful and could ultimately fundamentally disrupt the process of cryptanalysis, or the adversarial testing of cryptosystems.


