
Mythos helped find a new medium encounter technique that is based on a Mobius Bridgea more sophisticated fingerprinting algorithm used in meet-in-the-middle attacks. By using it, Green said, the code that Mythos produced was able to reduce the number of inputs required to 289. Anthropic said the savings can reduce the time required for such attacks by 200 to 800 times.
The ability to produce so many inputs makes the attack out of reach outside the laboratory. Furthermore, the actual speedup is unknown, as the tested weakened AES algorithm used only 7 rounds. Green said AES that meets the specifications uses 10, 12 or 14 rounds, depending on the size of the key.
Anthropic is careful to explicitly explain most of these warnings. However, Monday’s blog post goes on to argue that the results are nonetheless significant and could ultimately fundamentally alter the cryptanalysis process or adverse testing of cryptosystems.
“The cybersecurity community is now grappling with the fact that language models are capable of discovering so many bugs that standard human processes (such as vulnerability triage, verification, and remediation) struggle to keep up,” Anthropic wrote. “We predict that the same will soon occur in academic cryptography research. As language models increasingly produce novel research results autonomously, human researchers may be hampered in studying and validating these results for technical validity, novelty, and usefulness.”
The Anthropic report does not mention whether its researchers used Mythos to attack more proven cryptosystems, such as elliptic curve cryptography and RSA. Improvements in attacks against these systems would be more impressive. By achieving the most impressive result against an algorithm still in its infancy, it is unclear how much of an advantage Mythos actually provided. There is no way to know whether researchers who used conventional cryptanalysis techniques were already close to discovering the same attack.
Ultimately, the lesson of the research is simple. AI-assisted cryptanalysis is still unproven and the providers of these platforms have a vested interest in exaggerating its benefits. At the same time, there is growing evidence that LLMs can offer significant advantages when it comes to finding cryptographic weaknesses. It would be a mistake to conclude that LLMs will not one day play an important role in the race between securing and compromising our most vital assets.
The headline and body of this story have been updated to reflect HAWK’s withdrawal.





