AI News Digest, July 29: The AI-Discovered Cryptographic Flaw That Should Worry Your Security Team
Claude just found an AI-discovered cryptographic flaw in a scheme the U.S. government’s own standards body had already reviewed for two years. The model, called Claude Mythos Preview, cut the cost of breaking a post-quantum signature scheme called HAWK by billions of times. It did the work in about 60 hours. Maybe you assumed cryptography research sits safely outside AI’s reach. This story should change your mind, and it has real implications for how you evaluate the vendors holding your company’s data.
What Happened: An AI-Discovered Cryptographic Flaw in Post-Quantum Cryptography
Anthropic’s Frontier Red Team published the finding on July 28. Working with an Anthropic researcher, Claude Mythos Preview found a new attack against HAWK. HAWK is one of nine finalist algorithms in a multi-year NIST competition to standardize signature schemes built to survive quantum computers. (Source: Anthropic)
HAWK had already cleared two rounds of expert human review over two years. Mythos found a mathematical shortcut instead: a previously unexploited symmetry in HAWK’s underlying lattice structure. That shortcut cut the cost of a full key-recovery attack on HAWK-256 from 2^64 operations down to 2^38. Think of it as the gap between “impossible for any attacker” and “a target a well-funded team could plausibly chase.” The attack is still exponential, not instant, so nothing breaks overnight. But the safety margin HAWK’s designers thought they had just got thinner. Anthropic disclosed the finding to NIST’s public mailing list on release day.
A second Mythos-led project found an unrelated weakness. This one hit a stripped-down, 7-round version of AES, the encryption standard protecting most internet traffic today. That attack ran 200 to 800 times faster than the previous best method, according to The Hacker News. It does not touch full AES-128, the version actually protecting your data. Still, the signal is the same: models are getting good at attacking cryptography itself, not just software built on top of it.
Why It Matters: The AI-Discovered Cryptographic Flaw Is a Warning Shot for HR Tech
Here is the part that should land on your desk, not just your security team’s. HAWK isn’t deployed anywhere yet. So this specific finding changes nothing about your payroll run tomorrow. But the pace is the real story. NIST’s own review process took two years of expert scrutiny. An AI model matched that scrutiny and found a flaw in 60 hours, for roughly $100,000 in compute. Cryptography research was supposed to be one of the safest, most specialist corners of knowledge work. It’s the kind of job nobody expected an AI model to touch anytime soon.
What this means for your “AI-proof roles” list
That assumption just took a hit. It matters for HR leaders specifically because you field the “which jobs are AI-proof” question from anxious employees. You also set hiring and reskilling budgets around the answer. Applied cryptography research is one of the hardest, most credentialed fields in tech. If a model working semi-autonomously can meaningfully advance it, your list of “safe” roles gets shorter. That’s a real input for your next workforce-planning conversation, not a hypothetical one.
There is also a direct vendor-risk angle. Most HRIS, payroll, and background-check platforms still run on classical cryptography, not post-quantum schemes like HAWK. AI models keep getting better at breaking cryptographic assumptions. Meanwhile, standards bodies move at the pace of committees. As a result, the timeline for “when do we need to worry about this” keeps compressing. Building or refreshing a strong cybersecurity policy now, one that actually asks vendors about migration plans, beats scrambling later.
Under the Hood: How Claude Found the Flaw
The two attacks were not discovered the same way, and the difference matters. For the HAWK attack, an Anthropic researcher worked directly with Mythos for about a week. They used a harness that let multiple Claude “worker” agents collaborate inside a sandboxed environment, with tools like Python and Sage. The human in the loop had a computer science background, but was not a lattice-cryptography specialist. Mythos handled the literature review, the mathematical reasoning, and the verification. The human mostly managed the process, nudging the agents toward which ideas to chase next.
The AES attack was closer to fully autonomous. A researcher built a scaffold, then let Claude run for roughly three days. It produced hundreds of millions of tokens while chasing an idea it initially insisted was impossible. Researchers pushed back with blunt, informal prompts, essentially telling the model to stop looking for easy wins. Only then did Mythos land on the winning technique: a fingerprinting method Anthropic’s researchers nicknamed the “Möbius Bridge.”
Anthropic is careful to flag what this is not. Neither attack runs in polynomial time, so nothing is “broken” in the everyday sense. Both results cost roughly $100,000 in compute to produce. HAWK is only a candidate standard. The AES result applies to a research variant, not the cipher protecting your bank login today. Still, the company disclosed responsibly, sharing the HAWK finding privately with the scheme’s own authors back in June, before going public.
What HR Leaders Do Monday About This AI-Discovered Cryptographic Flaw
Start with your vendor list. Ask your HRIS, payroll, and benefits providers two direct questions. First, what cryptographic standards are you running today? Second, what is your migration plan if post-quantum schemes get fast-tracked because of findings like this one? If a vendor can’t answer, that’s useful information on its own. Asanify’s HRIS and payroll infrastructure teams track NIST’s standardization work for exactly this reason. You should expect the same discipline from anyone storing your employee data.
Next, revisit how you talk about AI-resistant careers internally. If your L&D messaging still treats deep technical specialties as automatically safe, this story is a useful correction. Point people toward the broader AI skills gap in HR conversation instead of a static list of “safe” roles. The skills holding up best right now focus on verifying and applying AI output, not producing it from scratch alone.
Finally, if you own a security or IT vendor questionnaire, add a line about post-quantum migration timelines this quarter. It costs one email to ask. Waiting until an AI-discovered cryptographic flaw actually touches a deployed system costs a great deal more.
Frequently Asked Questions
What did Claude actually break in this cryptographic research?
Claude Mythos Preview found an AI-discovered cryptographic flaw in HAWK, a post-quantum signature scheme still under review by NIST. The attack cut the cost of breaking HAWK-256 from 2^64 operations to 2^38, roughly halving its key strength. The attack is still exponential, not instant, and HAWK isn’t deployed anywhere yet.
Does this AI-discovered cryptographic flaw affect systems businesses use today?
No. HAWK is only a candidate standard, not deployed in production software. The related AES weakness applies to a stripped-down, 7-round research version of AES-128, not the full 10-round cipher protecting real systems. Anthropic said no production software needs to change because of these findings.
Why should HR and business leaders care if it’s not an active threat yet?
Because the same capability that found this flaw shows how fast AI is moving into expert-level knowledge work once assumed safe from automation, including cybersecurity research. Use it as a trigger for two things. First, a vendor-risk review that asks HRIS and payroll providers about post-quantum migration plans. Second, an honest update to how you talk with your team about which skills stay valuable as AI capabilities keep compounding.
Not to be considered as tax, legal, financial or HR advice. Regulations change over time so please consult a lawyer, accountant or Labour Law expert for specific guidance.
