Claude Mythos Weakens HAWK, Speeds Reduced-Round AES Attack
HAWK is a third-round candidate in the U.S. National Institute of Standards and Technology’s competition for additional post-quantum digital signatures, intended to withstand future quantum attacks that could undermine RSA and ECDSA. The finding matters because Claude Mythos Preview identified a mathematical weakness in the design itself, rather than a coding error in a cryptographic library. Still, HAWK is not deployed, and the AES work targets only a deliberately weakened, seven-round version of the 10-round AES-128 standard.
Anthropic said on July 28, 2026, that Mythos spent about 60 hours finding an unexploited symmetry in HAWK’s lattice structure, cutting the estimated cost of full key recovery against HAWK-256 from 2^64 to 2^38 operations. The work cost roughly $100,000 in API usage. In a separate, mostly autonomous effort, the model devised a meet-in-the-middle attack on seven-round AES-128 that was 200 to 800 times faster than the previous best method, though Anthropic said neither result affects production systems.
All Coverage
5 original reportsThe Backstory
The history behind this eventAnthropic’s Claude Mythos Release Raises Security Concerns in Crypto Community
Anthropic has introduced Claude Mythos, also known as Fable 5, touting stronger code-analysis and vulnerability-detection capabilities. Such models can help defenders patch smart contracts but may also lower the technical barriers to launching cyberattacks, fueling concerns in the crypto community about the security of assets and protocols.
Anthropic said the new model includes general-purpose safety safeguards and routes cybersecurity-related queries to a specialized model to reduce the risk of misuse. The Uniswap founder, however, criticized the design of its “safety filter” as poorly calibrated. Related reports did not disclose the exact release date, any losses or the value of assets affected.
Anthropic Targets Japan’s Cybersecurity Market With Claude Mythos
Anthropic is targeting Japan’s cybersecurity market with its next-generation AI model Claude Mythos, focusing on vulnerability detection and pursuing Japanese government agencies and financial institutions. The strategy raises questions about cross-border reliance on critical computing power and cybersecurity capabilities. It has also drawn the U.S. government’s attention to computing sovereignty, prompting Japan to accelerate development of advanced domestic cybersecurity models.
As of July 20, 2026, the latest reports indicate that Anthropic is aggressively positioning itself in Japan’s government and financial markets, with Claude Mythos’s vulnerability-detection capabilities emerging as a key competitive focus. The Japanese government and industry are simultaneously advancing the development of sovereign models. Available information does not disclose the model’s release date, investment amount, procurement scale or any formal partner institutions.
Anthropic Flagship AI Model Claude Mythos Leaked, Raising Cybersecurity Concerns
Anthropic is developing its flagship Claude Mythos model with advanced coding, reasoning and autonomous cybersecurity capabilities. Its ability to rapidly chain vulnerabilities together could lower the barrier to cyberattacks, making the leak more than a product-secrecy issue. It also raises concerns about zero-day exploitation, responsible disclosure mechanisms and the defense of critical infrastructure worldwide.
As of July 19, 2026, Anthropic was investigating unauthorized access caused by a system configuration error. Reports said vulnerabilities could be attacked within as little as four hours of disclosure. The company is not making Mythos broadly available for now, instead prioritizing trials by cyber defense organizations and addressing risks through its Glasswing program and threat-intelligence sharing.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.