By
Tony Rosati, Dr. Michele Mosca
August 5, 2026

The cryptanalytic results from Anthropic’s frontier models may not break a production system today, but they absolutely should be reflected in how you plan your migration to post-quantum cryptography.
The first result targets HAWK, a lattice-based digital signature scheme and a third-round candidate in NIST's call for additional post-quantum signatures. HAWK had survived two years of expert human review. Working alongside a single Anthropic researcher — one without a background in lattice-based cryptography — the model found a previously unexploited symmetry in HAWK's lattice and improved the best-known attack in roughly 60 hours of work, at an API cost of about $100,000.
This effectively cuts HAWK's keystrength in half. Restoring the intended security level would mean doubling key sizes, which removes much of what made HAWK an attractive candidate in the first place. It has since been withdrawn from the current process.
The second result concerns AES. Operating almost entirely autonomously, the Anthropic model improved the strongest known meet-in-the-middle attack on a seven-round variant of AES-128 by a factor of 200 to 800. While this has no practical implications for full AES-128, it demonstrates that frontier models can independently contribute meaningful advances in modern cryptanalysis.
These results are significant enough that they bear repeating. After only a few days of AI-assisted analysis, a post-quantum signature candidate that had survived years of expert scrutiny lost close to half of its estimated security margin. (Attack time scales exponentially with the security margin, so reducing the security parameter from 64 to 38 (a drop of 26) means the cipher becomes roughly 2^26,or about 64 million times weaker.) By contrast, the most heavily scrutinized symmetric cipher in widespread use was essentially unaffected, as the analysis only managed to modestly weaken a reduced-round variant. That difference is broadly what cryptographers would have predicted.
Anthropic is careful to state that neither attack has immediate operational security consequences. HAWK is not deployed. The AES work targets a deliberately weakened seven-of-ten-round variant under a chosen-plain text model requiring an infeasible number of queries. Full AES-128 remains untouched.
In other words, AI has not suddenly broken modern cryptography. But it is demonstrably changing the economics of cryptanalysis due to the pace at which frontier models can generate meaningful cryptanalytic insights.
Historically, the pace of cryptanalysis has been constrained by scarce human expertise. These results suggest frontier models can substantially reduce the cost and time required to explore large numbers of attack ideas, allowing experts to focus more on evaluating and validating the most promising results. As Anthropic notes, the human review process is already becoming the bottleneck: the model found the AES improvement in about a week, while validation took researchers nearly a month.
For defenders, these results increase the value of architectures that remain secure even as new cryptanalytic results emerge.
A common approach to post-quantum migration is to select and deploy a standardized algorithm with the expectation that continued public cryptanalysis will provide sufficient warning to migrate should its security deteriorate. Anthropic’s results make the limitations of this approach more tangible: as AI reduces the effort and compresses the time required to discover and operationalize cryptanalytic advances, the warning period for orderly migration may become shorter, less predictable, or disappear altogether.
This viscerally reinforces the value of architectures that remain secure and operational even if confidence in an individual cryptographic algorithm changes before a migration can be completed. Such architectures are built on three complementary principles: defence in depth, cryptographic agility and long-term security.
Cryptographic resilience is the discipline of building systems that survive the failure of any one of their cryptographic assumptions. It relies on three complementary elements:
Defence in depth. Cryptographic defence in depth reduces reliance on any single cryptographic assumption. By combining independent cryptographic mechanisms, communications and systems continue being protected even if one layer is weakened. Effective cryptographic defence in depth depends on diversity of cryptographic assumptions. Independent mechanisms reduce the likelihood that a single cryptanalytic advance compromises the entire system.
Cryptographic agility. As cryptanalytic capabilities advance, the ability to adopt stronger algorithms and retire weakened ones quickly without re-architecting infrastructure becomes increasingly important.
Long-term security. Cryptographic agility and defence in depth help systems adapt to changing cryptographic confidence and maintain operational continuity, but they cannot recover confidentiality once it has been lost. Data that must remain confidential for many years therefore benefits from cryptographic foundations that rely on the most conservative available assumptions. Symmetric-key cryptography and one-way-function-based mechanisms generally rest on more mature and broadly trusted assumptions than public-key systems.
While these three aspects of cryptographic resilience have guided serious cryptographic engineering for years, AI and post-quantum threats have made them more urgently necessary. Architectures like our BasejumpSKI product are built around exactly this set of principles, for organizations that want to act on this now rather than wait for the next warning.
BasejumpSKI uses a multimodal key establishment protocol that combines symmetric key infrastructure, classical asymmetric cryptography and post-quantum cryptography to derive end-to-end symmetric pre-shared keys. The mechanisms are independent by design, so the resulting keys retain strong computational security even if every asymmetric algorithm used in their establishment is later broken (HAWK is an example of an asymmetric algorithm). The asymmetric components also provide valuable additional properties, such as forward secrecy and post-compromise security.
BasejumpSKI is standards-based and designed to evolve quickly and at low cost, overcoming the limiting constraints associated with the speed and cost of change. And its use of asymmetric cryptography provides important operational properties while ultimately grounding long-term confidentiality in conservative symmetric-key assumptions.
Anthropic frames its work as cryptography research functioning as intended: stress-testing algorithms to build trust. We agree. Rigorous adversarial review is how the field earns confidence, and AI-assisted review will make future standards stronger.
However, if you manage cryptographic risk for a bank, a telecommunications carrier, a utility or a defence program, the operational reading is different. AI may make consequential cryptanalytic advances faster and harder to anticipate. Architectures that depend on a single cryptographic assumption remaining secure indefinitely carry increasing operational risk.
The lesson from Anthropic's work is not that modern cryptography has failed, but that the pace of cryptanalysis maybe changing. That places increasing value on architectures designed to remain secure as cryptographic assumptions evolve.
Schedule a BasejumpSKI demonstration, or talk to our team about a Quantum Risk Assessment for your organization.