Skip to content

Claude Mythos finds a new attack against reduced-round AES encryption

Young man analysing colourful data visualisation on computer screen in a modern office with books and notes.

Anthropic researchers have used Claude Mythos to develop a new attack against a reduced-round version of AES encryption. This does not affect the security of your data, as this shortened AES variant is not used in production systems. It exists solely for research purposes. Nevertheless, the company has shown that, alongside software bugs, advanced AI can also uncover mathematical weaknesses in encryption algorithms.

Claude Mythos, Anthropic’s cybersecurity-focused AI, has already shown that it can identify security flaws in software code, including operating systems, browsers and more. Now, it has emerged that this powerful AI can also find mathematical vulnerabilities in the encryption algorithms on which our digital lives rely. Indeed, in a blog post published this week, Anthropic says its researchers used Mythos to discover a new way of attacking “reduced-round” AES.

Your data is not at risk

AES is the most widely used symmetric encryption standard and, as such, is a cornerstone of security in our digital lives. However, Anthropic has reassured the public: although these research findings matter, they do not compromise the security of your data. The “reduced-round” AES that Anthropic managed to attack is a simplified form of the real encryption method. Reduced-round ciphers are not used in production systems, but enable researchers “to better understand attack techniques that could, in the future, be generalised to encryption as a whole, and to help estimate its security level by studying simpler sub-problems.”

In any event, compared with earlier attacks, Claude Mythos was able to break the reduced-round version of AES 200 to 800 times faster. Anthropic’s latest work is chiefly intended to show that frontier AI models can help pinpoint weaknesses in encryption systems. “This is cryptographic research working as intended,” the AI laboratory also says, as Claude Mythos made it possible to “test the resilience of algorithms to build confidence and, ultimately, make systems safer.”

Claude Mythos also weakened a system designed for the post-quantum world

The fact that Anthropic’s AI found a new attack technique against AES is an achievement in itself. Having been used for decades, the algorithm has received more scrutiny and analysis than almost any other encryption algorithm. Beyond identifying this new AES attack method, Claude Mythos also significantly weakened another system, called HAWK, which was designed to withstand quantum computers.

However, just like the attack on a reduced-round AES version, this second discovery does not put your data at risk. HAWK is a “candidate” signature scheme for the post-quantum world, meaning it has not yet been deployed on the systems we use.

A system thought to be unbreakable

HAWK had already passed two rounds of expert assessment as part of a selection process run by the National Institute of Standards and Technology, a US government agency. Yet, according to Anthropic, Claude Mythos improved the best known attack against this system in 60 hours. As a result, the AI reportedly halved HAWK’s main advantage.

In its publication, Anthropic explains that it would now be necessary to “double the size of HAWK keys to reach the same level of security.” Doing so, however, would remove HAWK’s advantages for post-quantum signatures. Naturally, this finding concerns only one candidate system, not the other signature systems being considered for the post-quantum world.

Comments

No comments yet. Be the first to comment!

Leave a Comment