Researchers at Anthropic, a leading artificial intelligence company, have demonstrated that an advanced AI model, Claude Mythos Preview, can identify vulnerabilities in a weakened version of the Advanced Encryption Standard (AES), a widely used cryptographic protocol that underpins much of today’s internet security.
During controlled research tests, the AI model successfully executed new attacks against a diluted AES algorithm, enabling decryption efforts that were 200 to 1,000 times faster than those achieved in prior human-led research. AES is a foundational technology protecting a broad spectrum of digital activities, including online banking, wireless communication, and data storage, and is generally regarded as virtually unbreakable under current computing capabilities.
Anthropic emphasized that the flaws exposed do not affect the current full-strength AES standard in use today; instead, the model targeted a simplified variant designed for testing and analysis. Such weakened forms of encryption are often employed to anticipate whether future computational advancements could compromise standard protocols.
The findings point to the growing capabilities of AI in cryptographic research, a domain traditionally dominated by human expertise and complex mathematical problem-solving. Nicholas Carlini, a research scientist at Anthropic formerly with Google’s AI division, noted that the performance of AI in this field has rapidly improved. He stated that today’s models are capable of breakthroughs that previously eluded both humans and earlier AI systems.
In addition to the AES test, Claude Mythos Preview identified a novel attack against HAWK, a promising cryptographic system designed to resist both classical and quantum computing threats. Although HAWK is not yet in active use, it is under consideration by the U.S. National Institute of Standards and Technology (NIST) as a potential future encryption standard. The HAWK attack has been validated by the system’s authors, and independent experts have reviewed the AES-related findings. Anthropic shared the research details with U.S. government agencies and industry partners before public disclosure.
The development highlights increasing concerns among cybersecurity experts and intelligence officials about the potential for advancing AI to disrupt encryption systems that maintain digital privacy and national security. For decades, intelligence communities in the United States and allied countries have warned of the risks posed if current encryption standards were broken, with some governments alleged to be stockpiling encrypted data in hopes of future decryption capabilities.
The AI's ability to autonomously devise an improved cryptographic attack surprised researchers. Initially skeptical about its capacity to advance beyond existing methods, the model gradually formulated the novel approach after focused interaction over roughly a week. Human researchers subsequently spent several weeks verifying the technique’s validity.
AES, established as a government standard in 2001, is widely regarded as computationally infeasible to break through brute force, given its massive key space—comparable to the number of atoms in the observable universe. Still, the rapid evolution of AI has fueled discussions about whether machine learning models might someday undermine these assumptions, even ahead of anticipated breakthroughs in quantum computing.
Glenn S. Gerstell, former general counsel for the U.S. National Security Agency, remarked on the implications of these advances. While acknowledging that breaking strong encryption should theoretically remain out of reach with current technology, he warned against dismissing the potential capabilities of future AI models in the near term, which could pose significant challenges before quantum-resistant cryptographic methods are widely adopted.
Anthropic has restricted the public availability of Claude Mythos Preview due to concerns about its powerful abilities to uncover and exploit software vulnerabilities. The model’s debut in April was limited to select government agencies and organizations to mitigate risks of misuse. This cautious approach reflects broader debates over AI governance and security amid a rapidly evolving digital landscape.
