A language model found a crack in HAWK. This digital signature scheme was designed specifically to withstand quantum computers. The same team also identified a new avenue of attack against reduced-round versions of AES, the symmetric encryption that protects bank transfers, emails, and messages right now. Anthropic researchers published both findings using Claude Mythos Preview as a mathematical analysis tool. Neither attack compromises production systems. They are, however, real technical advances.
Cryptography is the mathematical guarantee holding up almost all digital infrastructure, because it turns a problem of social trust into a problem of computational complexity. You don't trust the bank. You trust that factoring a two-thousand-bit number takes longer than the age of the universe. When that equation shifts, even slightly, everything built on top of it shifts along with it.
HAWK belongs to the generation of post-quantum algorithms. Its purpose is to survive the day a quantum machine breaks RSA and the elliptic curves we use today. The attack discovered doesn't destroy it outright. It significantly reduces its safety margin — that cushion separating what's secure in practice from what's vulnerable in the lab. AES has encrypted nearly all symmetric traffic on the planet since 2001. The new attack targets only versions with fewer rounds. Real-world implementations use more. There's no immediate break. But each step like this shortens the cushion we assumed we had.
In Las Piedras No Mienten I devote a good part of the analysis to examining how technology amplifies power that already exists rather than redistributing it. Blockchain, artificial intelligence, and gamification all pass through the same lens. No tool is neutral. All of them inherit the intentions and limitations of whoever designs them — and of whoever attacks them. Cryptography fits perfectly. We use it without understanding it, trusting that distant experts keep it safe while we send photos and make transfers.
The book also touches on the tension between technical transparency and institutional opacity. I explored this before when writing about Anthropic's code leak and Ofcom's pressure on Telegram. The pattern repeats. Systems that promise absolute privacy end up revealing conditions, limits, and implicit expiration dates.
What does this finding add to that thesis? It confirms with concrete evidence something we already suspected: advanced language models can become genuine cryptographic research tools. That changes who is capable of attacking encryption systems. Before, you needed a team with years of highly specific mathematical training. Now a well-directed model measurably accelerates the process.
Anthropic published the findings openly, with a clear methodology. That contradicts the pattern of opacity I described earlier about the same company. Not every action by a powerful actor follows the same script. Sometimes transparency is genuine.
Who audits whom when the labs building the most powerful models are also the ones finding the most significant cryptographic vulnerabilities? The book doesn't fully resolve that uncomfortable question. In The Generosity in the Doorway I briefly address the problem of black boxes, but through the lens of algorithmic bias. This is different. The model becomes a double-edged sword, useful for strengthening and useful for weakening, depending on who gets there first.
I'll admit I don't have a clear answer. Anthropic's transparency allows the community to review, strengthen, and patch before someone with other intentions finds the same thing privately. That's the right move. But it also means any lab with similar capability and less ethical commitment could be doing exactly the same thing without publishing it. The window between discovery and exploitation no longer depends solely on scarce human talent. It depends on how well you know how to direct a model.
We've spent decades building digital trust on the idea that certain mathematical problems are too hard for any reasonable attacker. That premise always had an expiration date tied to computing power. We didn't fully anticipate that the bottleneck could also be applied mathematical reasoning. If a model finds cracks that generations of human cryptographers overlooked, the question is no longer just when current cryptography will break.
Post-quantum cryptography. Promises eroding faster than expected. Much like the work at Bletchley Park during the war, where breakthroughs in cryptanalysis shifted balances of power overnight. Three times over. That's sometimes what separates secure from broken.
The cracks are already showing up in the reports, and you can see them yourself. How much safety margin do we really have left, and who else is staring at that same crack right now?