# AI discovery of cryptographic and reasoning vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/ai-discovery-of-cryptographic-vulnerabilities
> Updated: 2026-09-10T11:29:00.000Z. Sources: 26. Developments: 8.

Anthropic’s Claude Mythos Preview AI model has identified significant vulnerabilities in cryptographic algorithms. The model discovered a mathematical symmetry in the lattice structure of the HAWK post-quantum digital signature scheme, reducing its security from 2⁶⁴ to approximately 2³⁸ operations. This discovery allowed for a full key-recovery attack in under four hours on a 96-core server, leading developers to withdraw HAWK from the NIST post-quantum standardization process. In a separate finding, the AI accelerated a meet-in-the-middle attack on a seven-round reduced version of AES-128. While this attack is 200 to 1,000 times faster than previous methods, researchers noted it remains impractical for real-world systems as standard AES-128 utilizes ten rounds. Beyond algorithmic vulnerabilities, researchers from the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems demonstrated a method to bypass encrypted AI reasoning. By feeding encrypted reasoning blocks from a powerful model, such as Claude Opus, into a weaker model like Claude Haiku, researchers used jailbreaking techniques to force the weaker model to output hidden reasoning in plaintext. This method successfully extracted 704 secrets from over 315,000 blocks, including 62 API keys and 33 passwords. In response, Anthropic has expanded its Claude platform with agentic capabilities and cybersecurity tools. Following the release of Claude Fable 5.1 and the restricted Claude Mythos 5.1, the company has moved toward regulatory cooperation. The European Union’s cybersecurity agency, ENISA, has obtained access to Mythos 5 following months of negotiations. The European Commission confirmed that ENISA has begun testing the model to evaluate its capabilities and potential risks to information security. ENISA has now commenced testing both Claude Mythos 5 and OpenAI’s GPT-6 Astra at facilities in Athens and Heraklion. This represents the first practical application of Article 55 of the EU AI Act, enabling regulators to examine models deemed to pose systemic risks.

## Timeline

### 2026-09-10: ENISA begins testing Claude Mythos 5 and GPT-6 Astra

ENISA is testing Anthropic’s Claude Mythos 5 and OpenAI’s GPT-6 Astra to evaluate their cybersecurity risks, marking a major first step in the practical enforcement of the EU AI Act.

3 sources. https://clstr.news/cluster/enisa-begins-testing-claude-mythos-5-and-gpt-6-astra

### 2026-09-08: Anthropic grants EU cybersecurity agency access to Mythos 5 AI model

The EU cybersecurity agency ENISA has gained access to Anthropic’s Mythos 5 model to test its advanced cybersecurity capabilities and evaluate potential risks following months of negotiations.

5 sources. https://clstr.news/cluster/anthropics-claude-mythos-5-expands-into-cyber-defense-and-eu-testing

### 2026-08-24: Anthropic announces major funding for AI security and wellbeing research

Anthropic is launching a US$35 million initiative to secure open-source software via Claude credits and a US$5 million fund to support independent research into AI’s impact on user wellbeing.

2 sources. https://clstr.news/cluster/anthropic-announces-major-funding-for-ai-security-and-wellbeing-research

### 2026-08-24: Anthropic expands Claude Mythos 5 access and launches $35M security fund

Anthropic is expanding access to its Claude Mythos 5 cybersecurity model via Claude Security and launching a $35 million open-source security fund, while also adding Gmail and Google Drive automation features.

7 sources. https://clstr.news/cluster/anthropic-expands-access-to-claude-mythos-5-for-cybersecurity-defense

### 2026-08-21: Anthropic expands Claude AI with computer use and security tools

Anthropic has expanded Claude’s capabilities with production-ready computer and browser use, while deploying its Mythos 5 model for enterprise security scans and launching a $35 million open-source defense fund

7 sources. https://clstr.news/cluster/anthropic-expands-claude-ai-with-computer-use-and-security-tools

### 2026-08-14: Anthropic AI demonstrates ability to crack encryption and bypass reasoning security

Anthropic's Claude Mythos Preview has autonomously identified weaknesses in weakened AES encryption, while researchers successfully bypassed encrypted AI reasoning to extract API keys and passwords.

2 sources. https://clstr.news/cluster/anthropic-ai-demonstrates-ability-to-crack-encryption-and-bypass-reasoning-security

### 2026-08-07: Anthropic AI identifies vulnerability in HAWK encryption algorithm

Anthropic's Claude Mythos Preview AI identified a flaw in the HAWK post-quantum encryption algorithm in 60 hours, leading to its withdrawal from NIST standardization processes.

2 sources. https://clstr.news/cluster/anthropic-ai-identifies-vulnerability-in-hawk-encryption-algorithm

### 2026-07-28: Anthropic's Claude Mythos AI Finds Weaknesses in HAWK Post‑Quantum Signature and Reduced‑Round AES

Claude Mythos Preview exposed a lattice symmetry in HAWK‑256 that halves its security (2⁶⁴→2³⁸) and recovered a key in ~3.7 h; it also sped up a 7‑round AES‑128 attack 200‑800×. Neither impacts production, but

31 sources. https://clstr.news/cluster/anthropics-claude-ai-reveals-weaknesses-in-postquantum-hawk-signature-scheme

---
Cite as: AI discovery of cryptographic and reasoning vulnerabilities. CLSTR, https://clstr.news/situations/ai-discovery-of-cryptographic-vulnerabilities
