On 29 July, Anthropic disclosed that one of its AI systems independently produced two notable advances in cryptographic research, as reported by Security Affairs. The results, including a stronger attack against a post-quantum signature scheme under active standardization review and a dramatically faster method for attacking a reduced form of AES, were achieved largely without human direction and underscore a shift in how original security research can be generated.

According to the report, Claude Mythos operated with minimal oversight when it identified an improved attack on HAWK, a lattice-based digital signature candidate currently being evaluated by NIST for post-quantum standardization. The same system also developed an attack against a reduced-round version of AES; Anthropic reports the method runs between 200 and 800 times faster than previously known techniques. Both findings were published by Anthropic as evidence that frontier models can now contribute original, high-impact work in a field long dominated by specialized human researchers.

The HAWK result carries particular weight because the scheme remains under formal consideration. Any newly discovered weakness, even if it does not fully break the construction, can influence parameter choices, security proofs, or the decision to advance or withdraw a candidate. Independent cryptographers will need to examine the AI-generated analysis carefully before its practical significance can be confirmed. The accelerated AES attack, while targeting a reduced variant rather than the full cipher used in production systems, demonstrates that automated methods can still surface non-trivial improvements in classical cryptanalysis.

These developments matter to the broader IT and open-source communities for several reasons. First, they compress the traditional research timeline. What once required months of expert effort can now emerge from an AI system in a far shorter cycle, raising the pace at which both defensive and offensive techniques appear. Second, they highlight the growing necessity of rigorous, independent peer review. When an AI system claims a new cryptanalytic result, the cryptographic community must still validate the mathematics, reproduce the attack, and assess real-world impact—steps that cannot be skipped simply because the source is automated.

The episode also illustrates a change in the role of large language models. Rather than serving solely as coding assistants or literature summarizers, systems such as Claude Mythos are beginning to act as autonomous research agents capable of formulating hypotheses, exploring attack surfaces, and producing publishable findings. That capability brings opportunity—faster identification of weaknesses in emerging standards—but also responsibility. Organizations relying on post-quantum algorithms, open-source cryptographic libraries, or long-term data protection will need processes that can absorb and verify AI-generated insights at speed.

Anthropic's decision to release the results publicly invites scrutiny and replication. Security researchers, standards bodies, and maintainers of cryptographic software now have concrete artifacts to examine. Whether the HAWK improvement ultimately affects NIST's evaluation or the AES speedup generalizes further remains to be determined through conventional scientific channels. What is already clear is that AI systems have crossed a threshold: they can generate original cryptographic knowledge with limited human guidance, and the security community must adapt its verification practices accordingly.

For practitioners, the immediate takeaway is vigilance rather than alarm. Existing deployments of AES and currently deployed post-quantum candidates are not automatically compromised. However, the accelerated discovery cycle means that monitoring AI-assisted research outputs, participating in open review, and maintaining agile update paths for cryptographic libraries will become increasingly important parts of responsible security engineering.


據Security Affairs報導,Anthropic於7月29日披露,其旗下一個人工智能系統自主取得了兩項加密研究的重要突破。成果包括對一個正處於標準化審查階段的後量子簽署方案更強大的攻擊方法,以及對簡化版AES加密算法進行攻擊的顯著更快方法。這些成果主要在無人類指導下實現,凸顯了原創安全研究產生方式的轉變。

報告指出,Claude Mythos在極少監督下運作時,識別出對基於格的數碼簽署候選方案HAWK的改進攻擊方法。HAWK目前正由美國國家標準與技術研究院評估用於後量子加密標準化。同一系統還開發了針對簡化輪次AES的攻擊方法;據Anthropic報告,該方法較已知技術快200至800倍。Anthropic發表了這兩項研究結果,作為前沿模型現能為長期由專業人類研究主導的領域貢獻原創性高影響力工作的證據。

HAWK的研究結果尤具重要性,因為該方案仍在正式考量中。任何新發現的弱點,即使未能完全破解其結構,都可能影響參數選擇、安全證明或候選方案的推進決策。獨立密碼學家需仔細審視這項人工智能生成的分析,才能確認其實際意義。加速版AES攻擊雖然針對的是生產系統中未使用的簡化版本,但證明了自動化方法仍能在傳統密碼分析領域帶來非平凡的改進。

這些發展對更廣泛的資訊科技與開源社區意義重大,原因有幾方面。首先,它們壓縮了傳統研究時間表。過去需要專家數月努力才能完成的工作,現可在更短週期內由人工智能系統完成,這提升了防禦與攻擊技術出現的速度。其次,它們凸顯了嚴格獨立同儕審查日益增長的必要性。當人工智能系統聲稱取得新密碼分析結果時,密碼學界仍需驗證數學原理、重現攻擊過程並評估現實影響——這些步驟不能僅因來源是自動化而省略。

此案例同時顯示大型語言模型角色的轉變。像Claude Mythos這類系統不僅作為編程助手或文獻摘要工具,更開始扮演自主研究代理角色,能提出假設、探索攻擊面並生成可供發表的研究成果。此能力帶來機遇——更快識別新興標準的弱點——但也伴隨責任。依賴後量子算法、開源密碼學庫或長期數據保護的組織,將需要能快速吸納驗證人工智能生成洞見的流程。

Anthropic決定公開發布成果,邀請學界審查與重現。安全研究人員、標準制定機構及密碼軟件維護者現有具體樣本可進行研究。HAWK的改進是否會最終影響NIST評估,或AES加速方法能否進一步推廣,仍需透過常規科學渠道確定。已然明確的是,人工智能系統已跨越門檻:它們能在有限人類指導下生成原創密碼學知識,安全社群必須相應調整其驗證實踐。

對從業者而言,立即的要點是保持警惕而非恐慌。現有AES部署及目前採用的後量子候選方案並非自動失效。然而,加速的發現週期意味著監測人工智能輔助研究成果、參與開放審查以及保持密碼學庫的敏捷更新路徑,將成為負責任安全工程中日益重要的環節。

新聞來源 / Original News Source