Matthew Green · 2026-07-29 · notable
Matthew Green — Anthropic's HAWK attack is real, the AES result is not
Johns Hopkins cryptographer Matthew Green reads Anthropic's Claude Mythos cryptanalysis. He calls the HAWK attack a real break with running code in hours, and calls the AES improvement a small step that still needs 2^105 chosen plaintexts.

Matthew Green splits Anthropic's cryptanalysis in two — the HAWK attack is a real break, the AES result is a small step.
What is it?
Matthew Green's July 29 post 'Some notes about Anthropic's new results' walks a cryptographer through the two attacks Anthropic released with Claude Mythos on July 27. Green agrees the HAWK attack is a real cryptanalytic break and pushes back on the AES claim.
How does it work?
The HAWK attack, Green explains, uses lattice tools that were already 'lying around' and applies them thoroughly enough to halve HAWK's security bits and ship working code that runs in hours. The AES side, by contrast, is a constant-factor improvement on a 2013 paper — 2^89 cipher operations and 2^105 chosen plaintexts, well outside anything practical.
Why does it matter?
Green's read tells cryptographers where to actually pay attention. HAWK is a post-quantum signature candidate; halving its security bits before deployment strengthens the ongoing PQC transition. Green also warns that AI cryptanalysis needs human verification: a model spitting out an apparent result does not make the result real.
Who is it for?
cryptographers, security engineers, and post-quantum standards followers
Try it
Read: blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results