[REVISION HISTORY]
AI discovery of cryptographic and reasoning vulnerabilities
Updated 10 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-11 05:24 UTC → 2026-09-11 09:05 UTC ·
added
removed
Anthropic’s Claude Mythos Preview AI model has identified significant vulnerabilities in cryptographic algorithms. The model discovered a mathematical symmetry in the lattice structure of the HAWK post-quantum digital signature scheme, reducing its security from 2⁶⁴ to approximately 2³⁸ operations. This discovery allowed for a full key-recovery attack in under four hours on a 96-core server, leading developers to withdraw HAWK from the NIST post-quantum standardization process. In a separate finding, the AI accelerated a meet-in-the-middle attack on a seven-round reduced version of AES-128. While this attack is 200 to 1,000 times faster than previous methods, researchers noted it remains impractical for real-world systems as standard AES-128 utilizes ten rounds. Beyond algorithmic vulnerabilities, researchers from the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems demonstrated a method to bypass encrypted AI reasoning. By feeding encrypted reasoning blocks from a powerful model, such as Claude Opus, into a weaker model like Claude Haiku, researchers used jailbreaking techniques to force the weaker model to output hidden reasoning in plaintext. This method successfully extracted 704 secrets from over 315,000 blocks, including 62 API keys and 33 passwords. In response, Anthropic has expanded its Claude platform with agentic capabilities and cybersecurity tools. Following the release of Claude Fable 5.1 and the restricted Claude Mythos 5.1, the company has moved toward regulatory cooperation. The European Union’s cybersecurity agency, ENISA, has obtained access to Mythos 5 following months of negotiations. The European Commission confirmed that ENISA has begun testing the model to evaluate its capabilities and potential risks to information security. ENISA has now commenced testing both Claude Mythos 5 and OpenAI’s GPT-6 Astra at facilities in Athens and Heraklion. This represents the first practical application of Article 55 of the EU AI Act, enabling regulators to examine models deemed to pose systemic risks.
Versions
- 2026-09-11 09:05 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-09-11 05:24 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-09-10 10:51 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-09-04 16:56 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-31 15:33 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-26 06:38 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-25 11:12 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-24 04:31 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-21 20:14 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-16 06:24 UTC AI discovery of cryptographic and reasoning vulnerabilities
- 2026-08-08 18:34 UTC AI discovery of cryptographic vulnerabilities
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.