For two years and across two rounds of expert review, cryptographers worldwide scrutinized HAWK for weaknesses. It passed. On July 28, 2026, Claude Mythos Preview, an AI model from Anthropic, delivered a finding after 60 hours of analysis that reversed that assessment: a fundamental flaw in HAWK's mathematical foundation that cuts its security guarantees in half. The HAWK team withdrew their proposal immediately from the US National Institute of Standards and Technology (NIST) candidate list.
Why Post-Quantum Cryptography Matters
Classical encryption like RSA relies on mathematical problems that current computers cannot solve. Powerful quantum computers could crack these using Shor's algorithm in a fraction of the time it takes classical computers. The cryptography community has spent decades developing methods resistant to quantum attack, known as post-quantum cryptography.
NIST ran a rigorous selection process starting in 2016. In August 2024, the institute published its first three standardized algorithms: ML-KEM for key exchange, and ML-DSA and SLH-DSA for digital signatures. HAWK was a competing candidate for the signature category, already through two rounds of intensive expert vetting.
What the AI Found
HAWK relies on the Lattice Isomorphism Problem (LIP), a mathematical puzzle on abstract grids. Claude Mythos Preview identified a previously undetected symmetry in HAWK's structure, a nontrivial automorphism. This symmetry enables an attack cutting HAWK's effective key strength in half. To maintain the same security level, key sizes would need to double, making HAWK far less efficient than competing methods.
The AI also developed a complete key recovery attack against HAWK-256 and accelerated a known attack on a reduced-round version of AES-128 by a factor of 200 to 800. The AES attack targeted a simplified test case, not the full standard. Anthropic published results on its research platform and coordinated the discovery with the HAWK team and NIST. The HAWK team confirmed the vulnerability and withdrew.
The timeline was decisive. Two years and two rounds of international expert scrutiny missed the flaw. The AI needed 60 hours.
Two Faces of the Discovery
The finding cuts both ways. On the positive side, the gap was caught before HAWK became a standard and entered production systems. No currently deployed communication system is compromised by this finding. The NIST-standardized algorithms, ML-KEM, ML-DSA, and SLH-DSA, remain unaffected and are considered robust.
On the concerning side lies the implication for the future. If AI models find weaknesses in 60 hours that expert review misses for years, the same may apply to other systems already in use. Security researchers cite the 'Harvest Now, Decrypt Later' threat: intelligence agencies and criminals collect encrypted data today for decryption once quantum computers or AI-powered cryptanalysis tools become available. A Cloud Security Alliance survey found 40 percent of security leaders expect cryptographically relevant quantum computers before 2030.
Cybersecurity expert Chris Hughes commented to GBHackers: 'This underscores that no algorithm can be considered permanently secure.' He called for AI-assisted cryptanalysis to become standard in future NIST processes.
By 2030: What Organizations Must Do Now
For organizations without post-quantum cryptography strategies, the HAWK discovery raises urgency, though the immediate threat is unchanged. Germany's Federal Office for Information Security recommends public agencies and enterprises complete migration to NIST-standardized post-quantum methods by 2030 at latest. The transition requires significant work. Many systems, from banks to government agencies, use encryption across decades and demand complete reconfiguration.
A fundamental question emerges for the cryptographic community: how do we validate AI-generated security findings? An AI can make errors or falsely claim vulnerabilities. In this case, the HAWK team and NIST independently verified the discovery before publication. The NIST process will likely adopt AI-assisted cryptanalysis as a standard step going forward. The practical difference from current practice: 60 hours instead of two years.
