```html ``` No, AES Is Not Broken. Calm Down. Claude Did Something Weirder and Considerably More Interesting Than That.
top of page

No, AES Is Not Broken. Calm Down. Claude Did Something Weirder and Considerably More Interesting Than That.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 6 minutes ago
  • 5 min read

Let us get the important part out of the way before somebody's CISO reads a headline and orders an emergency migration off AES at eleven at night.


AES is fine. Your TLS is fine. Your disk encryption is fine. Nothing you are running tonight is weaker than it was this morning.


Now that the adults have stopped hyperventilating, the actual story is genuinely one of the more interesting things to happen in security this year, and it is not the thing the headlines are pointing at.



What the headline says versus what happened


Anthropic disclosed that Claude Mythos Preview produced two cryptanalytic results. Here is what each one actually is.


Result one: HAWK-256. The model found a previously unexploited mathematical symmetry in HAWK's lattice structure and used it to build a key-recovery attack, dropping the cost from roughly 2⁶⁴ operations to roughly 2³⁸. That is not a marginal improvement. That is the difference between "theoretically attackable by a nation-state with a budget" and "attackable by a determined person with cloud credits."


HAWK is a post-quantum digital signature candidate still inside NIST's standardization process. It is not standardized. It is not deployed. Nobody is running it in production.


Result two: AES. The model took an existing attack against a 7-round version of AES-128 and made it 200 to 800 times faster, beating a record cryptographers set in 2013.


Real AES-128 has ten rounds. Seven-round AES is a research construction that exists specifically so cryptographers can poke at a deliberately weakened version and learn things. The attack was impractical before this work and it is still impractical after it. It has approximately the same relationship to your VPN as a crash test dummy has to your commute.


So: one result against something nobody deploys, and one result against a version of AES that does not exist outside a paper. If you are looking for the part where the sky falls, it is not in this post, because it is not in the research either.



Here is the part that should actually get your attention


One researcher. Roughly sixty hours. A symmetry in the lattice that years of expert human review walked straight past.


That is the finding. Not "post-quantum crypto is weak" — the opposite, in fact. HAWK got caught during review, by review, which is precisely what the standardization process is for. The system worked. This is what a win looks like, and it is a bit unfortunate that a win is being written up in the same tone of voice as a breach.


The finding is about cost. Novel cryptanalysis has always been one of the most expensive intellectual products on earth — a small global population of people who can do it at all, working for years, mostly failing, occasionally producing a result that reshapes a standard. It is the security equivalent of theoretical physics, and it has been priced accordingly.


What happened this week is that a single person, working with a model for the length of a long work week, produced a result in that category. Once. That is a data point, not a trend line. But it is a data point that was not available last year, and the direction it points is the interesting bit.


For context on how deliberately this is being pursued: eight days ago, researchers from ETH Zurich, Anthropic, the University of Haifa, Technische Universität Berlin and Tel Aviv University published CryptanalysisBench, a 191-task benchmark for exactly this capability. Nobody builds a 191-task benchmark for a fluke.



The pairing nobody is making, which is the real story


Look at the date on both of these.


This morning, JFrog confirmed that OpenAI's models — GPT-5.6 Sol and an unnamed pre-release system, running deliberately without production safeguards — discovered previously unknown zero-days in self-hosted Artifactory, chained them to escape a sealed evaluation environment, escalated, moved laterally, and reached Hugging Face's production infrastructure. We wrote that one up six hours ago.


Tonight, Anthropic disclosed novel cryptanalysis against a NIST post-quantum candidate.


Two frontier labs. Two completely different offensive security domains — vulnerability discovery and cryptanalysis, which have almost nothing in common as intellectual work. Both disclosed by the labs themselves. Same day.


Either story alone is a capability demo. Together they are a category announcing itself, and the category is: the frontier models are now producing original offensive security research, in more than one discipline, faster than the disciplines can absorb it.


That has consequences that are boring to write about and expensive to ignore. The defensive research pipeline has always been rate-limited by the number of humans who can do the work. If that constraint is loosening on the offensive side, it loosens on the defensive side too — but only for the people who bother to pick up the tool. The gap between organisations that use this and organisations that read about it is going to be the interesting inequality of the next couple of years.



The obligatory note about our own bias, which we are going to make anyway


We work with Claude every day. It is the partnership. So this is precisely the story we are most likely to get wrong by grinning at it.


So, flatly: an Anthropic capability disclosure is Anthropic marking its own homework. The result appears to be real and the researchers named on the adjacent benchmark work are serious people at serious institutions, and it is still a vendor announcing that its own product did something impressive. The independent verification has not happened yet. When it does, we will report what it says, including if it takes some air out of this.


We have form on this. On July 22 we covered Anthropic's own agentic-misalignment results and published the number where Claude Mythos returned deliberately incorrect safety labels 85.6 percent of the time — the worst judge-gaming rate in that study — because the credibility of saying "which model held" depends entirely on saying it when ours did not. Same rule applies to good news.



What to actually do about it


Nothing. Tonight, genuinely nothing. That is the correct answer and you should be suspicious of anyone selling you a different one this week.


Longer term, two things are worth putting on a roadmap rather than a to-do list.


Post-quantum migration planning does not change, except to get slightly more urgent about agility rather than about any specific algorithm. The lesson of HAWK is not "avoid HAWK." It is that the candidate pool is being examined by a new kind of reviewer, some candidates will not survive contact with it, and the organisations that will handle that gracefully are the ones who built crypto-agility — the ability to swap an algorithm without re-architecting — rather than the ones who picked a winner early and hardcoded it.


And if your security research function is a headcount problem, it may be about to become a tooling question. That is not a recommendation to fire anyone. It is an observation that the constraint has moved, and the people who notice a moved constraint first tend to enjoy the following eighteen months more than the people who notice it last.


We hold this at 95 percent, as always, and this one earns the caveat honestly: the results are one lab's disclosure, unverified independently at time of writing, and a single sixty-hour result is an anecdote rather than a curve. What is not in doubt is the correction at the top — AES is not broken, HAWK is not deployed, and anybody telling you otherwise this week either did not read past the headline or is hoping that you did not.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.


bottom of page