On July 28, 2026, Anthropic published research showing that Claude Mythos Preview — its most capable model — had discovered genuine mathematical vulnerabilities in two cryptographic algorithms. In roughly 60 hours of work, at an estimated cost of $100,000 in compute, the model found weaknesses that human cryptographers had failed to surface across two years of peer review.
This is not a cybersecurity breach. No production systems are at immediate risk. But the research is a clear signal that AI is crossing a threshold: from tool that helps experts work faster to participant that does original research.
What Mythos Actually Found
The team targeted two algorithms.
HAWK is a post-quantum digital signature scheme, meaning it was designed specifically to withstand attacks from future quantum computers. It had passed two formal rounds of expert cryptanalysis without a significant weakness being found. Mythos improved the best-known attack against it significantly, effectively cutting its claimed key strength in half — in 60 hours of compute. HAWK is still a candidate algorithm at standards bodies; it is not yet deployed in production systems, so there is no immediate harm. But the finding means the algorithm is weaker than previously believed.
AES (Advanced Encryption Standard) is the backbone of most commercial encryption, from HTTPS connections to encrypted storage. The Mythos attack targets a “round-reduced” variant, not the full cipher that protects real data. However, the model did something notable: it autonomously discovered a new mathematical technique it named the “Möbius Bridge,” improving known attacks on this variant by 200 to 800 times. AES itself remains secure. The significance is what happened on the way there — the model invented a named technique.
Why the Process Matters as Much as the Results
The research note describes the human role as minimal. Researchers primarily encouraged Mythos to keep going when it showed signs of abandoning an approach. The model directed its own investigation, chose which techniques to pursue, recognised dead ends, and eventually produced findings that are being submitted to academic journals.
That is a meaningful distinction from AI assistance, where a human expert uses the model as a calculator or writing aid. Here the model was the researcher. The human was closer to a project manager telling someone not to give up.
Cryptanalysis is one of the most cognitively demanding fields in mathematics. The fact that an AI model is producing results in it — even partial results against non-deployed algorithms — suggests the same dynamic will appear in other research-intensive domains: drug discovery, materials science, climate modelling, and applied business research.
What This Means for Business
Most businesses will read this story and conclude it has nothing to do with them. That conclusion is worth questioning.
Post-quantum preparedness is now urgent. Governments and standards bodies have been urging businesses to plan for the “harvest now, decrypt later” threat — where adversaries collect encrypted data today intending to decrypt it once quantum computers are powerful enough. Findings that weaken candidate post-quantum algorithms mean some of the algorithms businesses were planning to migrate to may themselves need reassessment. If you have a data governance roadmap that includes a quantum-safe encryption transition, this research is relevant to which algorithms you select.
AI is accelerating the pace of security change. The cost of this research was around $100,000. That is within reach of a mid-size company, a well-funded startup, or a nation-state actor running an adversarial program. As frontier AI models become more widely available, the economics of cryptanalysis change. Security teams need to factor in AI-augmented attack research when assessing their threat landscape.
The capability frontier is moving. The business story around AI has largely been about productivity — faster drafts, automated workflows, cheaper code. This research points to a different category: AI that expands the frontier of what is knowable. For businesses that rely on data as a competitive asset, the question is not just “how do we use AI to work faster” but “what does it mean when AI is doing research our competitors can access too.”
The Practical Steps
For most businesses, the near-term actions are modest:
-
Audit your encryption stack. Know which algorithms you rely on and which ones appear on the national standards candidate lists. HAWK is not yet in production, so there is no immediate action required on that front.
-
Follow NIST post-quantum standards. NIST has standardised its first set of post-quantum algorithms (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+). Building your migration roadmap around the standardised set rather than candidates is the safer path.
-
Review long-retention data policies. Data you encrypt today and store for ten or more years is the most exposed to future quantum or AI-assisted attacks. If you hold sensitive customer records, financial data, or IP with a long shelf life, encryption-at-rest strategy deserves a revisit.
-
Brief your security team. The main thing business leaders should take from this is not alarm but awareness. The pace of change in what AI can do in a security context is accelerating. Security assessments that were done eighteen months ago may already be outdated.
Anthropic has not suggested that businesses panic. The research is being submitted through responsible disclosure processes. But the paper itself, and the speed at which Mythos reached publishable findings in a domain that defeated human experts, is the kind of signal that should change your priors about what AI is and what it can do — including in your business.
Enterprise DNA builds AI agent workforce solutions for businesses ready to work at the pace AI is now moving. Talk to us about your AI roadmap.
Source
Anthropic Research
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible