up:: For Press
Did AI just break post-quantum encryption?
No. An AI model found a real flaw in one experimental algorithm that had been submitted to a competition, and the people who submitted it withdrew it the next day. That algorithm was never a standard, was never in any product, and protected nothing belonging to anyone. The encryption actually shipping in your phone and your browser was untouched, and the company that ran the experiment said so in writing, in the same document that announced the result.
Much of the coverage got this right. The errors that did recur were narrow and specific, and they’re worth naming because the same shape will come back with the next result.
The short version:
- The algorithm was called HAWK. It was a candidate, meaning a proposal submitted to a public competition and still being tested by anyone who cared to try.
- On 28 July 2026 an improved attack against it was published, credited to Anthropic’s Claude Mythos Preview model.
- Another cryptographer checked the result and confirmed it in about 5 hours. The HAWK authors withdrew their own proposal the next day.
- Nothing you use was affected. The finalized standards rest on different mathematics, and Anthropic stated plainly that the attack “does not impact the other NIST post-quantum cryptographic schemes.”
- The genuinely new part is price: 60 hours of machine time and roughly $100,000 in API cost, against research programs that have historically taken teams years.
- Most outlets covered it accurately. One ran the headline “AI Broke a NIST Candidate. Not Your Encryption.” The recurring errors were narrower: calling a signature scheme a cipher, and dropping the word candidate.
What actually happened?
A public competition works by having people try to break the entries. That’s the entire mechanism, and it ran exactly as designed here, in about 2 days, on a mailing list anyone can read.
| When | What |
|---|---|
| 28 July 2026, morning | An improved attack on HAWK is posted to NIST’s public mailing list |
| 28 July 2026, afternoon | A second cryptographer replies that he reproduced it independently |
| 28 July 2026 | Anthropic publishes its account, crediting the discovery to its Claude Mythos Preview model |
| 29 July 2026 | HAWK’s own authors withdraw it, and NIST updates its page the same day to record that |
Source: pqc-forum thread, “HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1,” groups.google.com; Anthropic, “Discovering cryptographic weaknesses,” 28 July 2026, anthropic.com; NIST, “Round 3 Additional Signatures,” updated 29 July 2026, csrc.nist.gov.
Why does “candidate” carry the whole story?
Because a candidate is a proposal, and a standard is a decision.
The encryption protecting your traffic today comes from algorithms NIST finalized in August 2024 after roughly 8 years of public attack: ML-KEM, ML-DSA and SLH-DSA. Those are standards. Products implement them, governments mandate them, and phones ship them.
HAWK was in a separate, later, still-running competition to add more options. It had cleared 2 rounds of review and reached a third. No product implemented it, no government mandated it, and no phone shipped it. When it was withdrawn, the number of systems that had to change was zero, and the number of people who had to do anything was zero.
Reporting the withdrawal as a break of post-quantum encryption compresses that distinction to nothing. A drug that fails in trials and a drug recalled from pharmacy shelves are both “a drug that didn’t work,” and only one of them is a story about harm.
What did the coverage actually get right and wrong?
Better than the usual, and the errors were specific rather than sweeping. This section was rewritten on 2026-08-04 after checking the published headlines rather than assuming.
What went right. Several outlets carried the qualifiers that matter. One headline read “AI Broke a NIST Candidate. Not Your Encryption.” Another named the exact scope: “Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack.” A third named the parameter set and the cipher size directly, “…HAWK-256 and Accelerates AES-128 Attack.” Those are accurate, and the widely-repeated claim that the press uniformly botched this one does not survive contact with the headlines.
It helped that the limiting sentence was in the primary source. Anthropic’s own write-up states: “We believe the attack discovered by Mythos Preview does not impact the other NIST post-quantum cryptographic schemes or other schemes that use related methods.” The organization with the most to gain from a dramatic framing published the caveat on day one, unprompted.
What went wrong, and it was mostly vocabulary.
- “Cipher” for a signature scheme. Several outlets called HAWK a cipher. A cipher encrypts and a signature scheme authenticates, and they solve different problems. HAWK never encrypted anything.
- The dropped qualifier. Some headlines omitted candidate, which is the single word carrying the whole story. Without it, a proposal withdrawn before deployment reads as a deployed system falling.
- One timeline overreach. At least one piece framed the withdrawal as a threat to the NIST post-quantum timeline. The finalized standards were unaffected, and the process removing a weak candidate is that timeline working rather than slipping.
The pattern worth carrying forward: the failures here were precision failures, by writers who mostly had the story right, rather than hype.
So was any of it a real result?
Yes, and this part deserves more attention than it got.
The flaw was genuine. Earlier researchers had shown that if a particular kind of hidden symmetry existed in the mathematics under HAWK, the scheme would be attackable. Nobody had found one. The model found one, which turned a theoretical worry into a working attack, and the effect is to halve HAWK’s effective key size. That’s a legitimate contribution, and the cryptographers on the mailing list treated it as one.
The part that genuinely changes something is cost. 60 hours and roughly $100,000 in API cost is within reach of a very large number of organizations, and it’s far below what comparable human results have historically taken. A capability that used to require a specialist research team and years now has a price tag that a mid-sized company could pay.
Source: Anthropic, “Discovering cryptographic weaknesses,” 28 July 2026, anthropic.com; pqc-forum thread, “HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1,” groups.google.com.
That’s the story worth writing. It’s a story about how fast weaknesses get found in new proposals, which is an argument for trusting well-aged standards and for being able to change algorithms quickly. It reads nothing like “your encryption fell.”
What should I take from this if I’m covering it?
Four things, in order of how often they get missed.
- Ask whether the broken thing was ever deployed. Candidate, draft, proposal and submission all mean the answer is no. That single question resolves most AI-broke-cryptography headlines.
- Read the researchers’ own limiting sentence. Serious groups publish one. Here it was in the announcement, and it contradicted the coverage that followed.
- Check the parameter size and the round count. Attacks on reduced or undersized versions are normal research, and the qualifier is what separates an accurate headline from a misleading one. Note that several outlets did carry it here.
- Treat the withdrawal as evidence the system worked. A flaw was published, confirmed by an outsider in hours, and acted on by the authors the next day, before anyone deployed it. That’s the competition doing its job in public.
Common misconceptions
- “AI broke post-quantum encryption.” An AI helped break 1 experimental proposal that was never standardized and never deployed. The finalized standards use different mathematics and were unaffected.
- “This means the new standards can’t be trusted.” The opposite conclusion fits better. The standards survived roughly 8 years of exactly this kind of public attack before being finalized, and HAWK lasted 2 rounds.
- Related: “the press got this completely wrong” is itself an error. Checked against the published headlines, most coverage carried the right qualifiers. Repeating a media-failure narrative that the record doesn’t support is the same sin in the other direction.
- “Anthropic overhyped this.” The critique belongs to the coverage rather than to the company. Anthropic published the result with its limits attached, including the sentence stating that the other NIST schemes are unaffected.
- “AES is broken.” The AES result applies to a weakened 7-round version of AES-128. Real AES-128 runs 10 rounds and AES-256 runs 14, and both remain unbroken. AES-256 is the size recommended against quantum attack.
- “So the quantum threat was fake all along.” Separate question entirely. Nothing here touches harvest now, decrypt later, which is about data being copied today and read later, and which the finalized standards exist to prevent.
- “A machine now finds flaws humans can’t.” Humans had already identified the exact weakness class as dangerous. The model found an instance of it, and a human verified the finding within hours.
Questions people ask
Is my encryption affected? No. HAWK was never in any product, browser, phone, or protocol. Nothing you use changed.
Was HAWK a NIST standard? No. It was a candidate in a supplementary competition to add more post-quantum signatures, and that competition has produced no finished standard.
Did an AI really find it on its own? Anthropic credits the discovery to its Claude Mythos Preview model running for 60 hours at roughly $100,000 in API cost. A human researcher then published the improved attack, and a second human confirmed it independently within about 5 hours.
Could the same thing happen to the real standards? Nothing rules it out in principle, which is why the competitions exist and why being able to swap algorithms quickly is the standing advice. The finalized standards rest on much more heavily studied mathematics, and Anthropic states this attack doesn’t carry over to them.
Does this mean AI will break encryption soon? The evidence so far points the other way for deployed systems. AI is proving useful at finding flaws in new and immature designs, and the well-aged standards continue to hold. That’s an argument for preferring boring, thoroughly attacked algorithms.
What happens to the competition now? 8 candidates remain. HAWK was the only one of the 9 based on lattices, so that family now has zero representation among them.
Go deeper into the technical detail
The full technical version is Why HAWK Was Withdrawn.
This opens the Post-Quantum Field Guide, a separate site written for security professionals.
The useful version of this story is that a public competition caught a flaw in a proposal before anyone relied on it, and that finding flaws in new designs has become dramatically cheaper. Everything here is free to use with attribution, and every figure traces to the original document. I’m reachable at addie@lamarrlabs.com if you want a claim confirmed with the primary attached.
Last verified 2026-08-04 · Maintained by Addie LaMarr, LaMarr Labs.