Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Overview
Anthropic's Claude Mythos Preview has successfully developed a key-recovery attack against HAWK-256, a post-quantum signature scheme. This new attack utilizes a previously unexploited symmetry in the underlying lattice structure, potentially compromising the security of systems relying on HAWK-256. Additionally, the researchers reported a significant speed increase for an attack on seven-round AES-128, achieving a 200- to 800-fold performance boost, which could make this encryption easier to break. The implementation is designed to run on a powerful 96-core server, completing in roughly three hours and 42 minutes. This advancement poses a major concern for organizations using these cryptographic methods, as it could lead to faster and more efficient attacks on sensitive data.
Key Takeaways
- Affected Systems: HAWK-256, AES-128
- Action Required: Organizations should consider transitioning to more secure cryptographic algorithms not affected by these vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
Impact
HAWK-256, AES-128
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Organizations should consider transitioning to more secure cryptographic algorithms not affected by these vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.