Anthropic Mythos Breaks Round-3 PQC Candidate and Outpaces Microsoft Patch Cadence

A PQC candidate down, a patch cadence outpaced — Mythos on the wire this week.

Share
Flat white line-art of a broken padlock beside a fast-ticking clock, on a violet background — Anthropic Mythos, cryptography, and patch cadence.

Key Takeaways

  • In two parallel disclosures dated July 29, 2026, Anthropic's Mythos model reportedly found a previously unknown attack on HAWK — a third-round candidate in NIST's additional post-quantum cryptography (PQC) signature process, named by CyberScoop — and, in separate reporting, is said to be surfacing bugs in Microsoft products faster than Microsoft can fix them.
  • The scope is bounded but notable: the HAWK result reportedly cut the cost of the cheapest known key-recovery attack from roughly 2^64 to 2^38 operations in about 60 hours, after the scheme had survived roughly two years of human review, while a related speed-up hit a deliberately weakened seven-round version of AES — not the full AES used in production.
  • Much remains unconfirmed at disclosure — the exact Microsoft products affected, whether Microsoft responded publicly, the specific research-paper URL, and whether NIST has changed HAWK's status in response — and Anthropic has stressed that neither cryptography result requires changes to deployed systems, since HAWK is an unstandardized candidate.

An AI-assisted research beat with two sides: a post-quantum signature candidate weakened, and a vendor patch cadence reportedly outrun — reported this week, with caveats intact.

SAN FRANCISCO, CALIFORNIA — Anthropic's Mythos model is at the center of two parallel research stories dated July 29, 2026: one in which the artificial-intelligence system reportedly found a previously unknown weakness in a third-round post-quantum cryptography (PQC) signature candidate, and one in which the same class of tooling is reportedly surfacing software bugs in Microsoft products faster than Microsoft can fix them. Both are framed by the outlets reporting them as demonstrations of AI-assisted vulnerability research, not as active attacks.

The cryptography result was described by Ars Technica, which reported that a Mythos-found attack put a third-round PQC candidate effectively out of commission as a viable option; CyberScoop named HAWK among the algorithms tested, alongside work on AES. The patch-cadence story was reported separately by Ars Technica. This piece summarizes what the two disclosures document, and flags what remains unverified, without reconstructing any technique.

At a Glance
FieldDetails
WhatTwo parallel AI-assisted research disclosures involving Anthropic's Mythos
Cryptography claimMythos reportedly found a new attack on a third-round PQC candidate — HAWK, per CyberScoop
Reported effectCheapest known key-recovery cost reportedly fell from ~2^64 to ~2^38 operations, in about 60 hours
AES angleSpeed-up reported against a reduced seven-round AES; full AES-128 not affected
Microsoft claimAnthropic reportedly finding bugs in Microsoft products faster than Microsoft can fix them (Ars Technica)
Production impactAnthropic says neither crypto result requires changes to deployed systems; HAWK is unstandardized
Disclosure dateJuly 29, 2026
StatusReported as research; several specifics unconfirmed

What Ars Technica and CyberScoop Reported

The through-line across the reporting is Mythos — the codename for an advanced Anthropic model tier used in vulnerability-research work in prior CyberSignal coverage. Ars Technica reported that Mythos identified cryptographic weaknesses that had gone unnoticed for years, including an attack on a third-round PQC candidate that, in the outlet's framing, effectively removed the candidate from contention. CyberScoop reported the same body of work and named HAWK among the algorithms examined, alongside a result touching AES.

Read plainly for a defender audience, the claim is narrow and specific: an AI system reportedly surfaced a mathematical shortcut that human cryptographers had not found, against an algorithm still under evaluation rather than one deployed in production. The CyberSignal is not reproducing the mechanics. The defender-relevant facts are the class of the finding — a novel cryptanalytic result produced with AI assistance — the named target, and the repeated emphasis from Anthropic that the work does not require changes to systems in the field.

The second, separate story shares the tooling but not the subject. In it, Anthropic is reportedly finding bugs in Microsoft software faster than Microsoft can remediate them. That framing originates with the outlets covering it and is examined on its own terms below.

The PQC-Candidate Break and NIST-Round Context

Post-quantum cryptography is the family of algorithms meant to stay secure against future quantum computers, and the U.S. National Institute of Standards and Technology (NIST) runs the standardization process that decides which ones become standards. HAWK is a lattice-based digital-signature scheme competing in the separate “additional signatures” on-ramp NIST opened to broaden its signature options — a track distinct from the original PQC standards NIST has already finalized. In May 2026 NIST advanced nine candidates, HAWK among them, into that on-ramp's third evaluation round. That is the “third-round” framing in the reporting: HAWK is a round-three candidate in the additional-signatures process, not a break of an already-standardized algorithm.

The reported severity is best stated with its numbers and its caveats together. According to the reporting, Mythos found an attack that lowered the cost of recovering HAWK's smallest key from roughly 2 to the 64th power operations to roughly 2 to the 38th power — a large reduction that reportedly cut the scheme's effective security strength by about half — and did so in on the order of 60 hours, against a design that had reportedly withstood about two years of human cryptanalysis. That is a meaningful result for a candidate's standing in the process.

It is also bounded. The AES angle CyberScoop noted concerns a reduced, seven-round version of the cipher used by researchers to probe attack techniques — not the full ten-round AES-128 that protects production data, which the reporting indicates is unaffected. And HAWK is a candidate, not a shipped standard: Anthropic has stressed that the finding requires no changes to deployed systems. Whether NIST formally alters HAWK's status in response is, as of this writing, an open question. For organizations tracking the broader migration, the practical backdrop is the federal push toward post-quantum readiness and its 2030 timeline, which assumes exactly this kind of candidate-by-candidate scrutiny before deployment.

The Microsoft Bug-Cadence Framing

The second story is where the reporting is doing more of the interpretive work, and where evenhandedness matters most. As reported by Ars Technica, Anthropic — using Mythos — is surfacing vulnerabilities in Microsoft products faster than Microsoft is able to patch them. The framing that the discovery rate is outpacing the fix rate is the outlets' characterization, drawn in part from documents other reporters have described, rather than a claim The CyberSignal has independently confirmed.

What is consistent across the coverage, and with prior reporting on Mythos-class tooling, is the direction of the effect rather than a precise ledger: automated, AI-assisted discovery can generate valid, high-severity findings faster than traditional human-paced remediation pipelines were designed to absorb. That is a workflow-capacity observation, and it cuts both ways — the same capability that widens a backlog for a defender using it internally also strengthens that defender's own testing. It is not, on the evidence reported, an assertion that Microsoft's products are uniquely weak or that any specific flaw is being exploited.

The CyberSignal has tracked the arc that leads here — from Mythos's earlier reported discovery of more than 10,000 vulnerabilities across partner software to vendors standing up their own AI-assisted defensive programs, such as Microsoft's MAI-Cyber-1-Flash and Project Perception. The specific Microsoft products at issue this week, and whether Microsoft has responded publicly, are not established in the reporting reviewed.

What This Means for Defender Priorities: Cryptographic Agility and Patch Cadence

For defenders, the two stories point at two different disciplines that happen to share a driver. The cryptography result argues for cryptographic agility — the ability to identify where an algorithm is used and swap it without re-architecting everything around it. HAWK is not deployed, so nothing needs replacing today; the lesson is procedural. If an AI system can halve a candidate's security in 60 hours after two years of human review, the assumption that a chosen algorithm will remain settled for its full expected lifetime is the thing to plan against, and inventory-and-swap capability is the hedge.

The Microsoft framing argues for patch-cadence realism. If discovery accelerates while remediation stays human-paced, the gap between “known” and “fixed” widens, and the value shifts toward prioritization: ranking findings by exploitability and exposure rather than trying to clear a queue in order. Neither of these is a novel idea, but both are sharpened by the same underlying shift — the marginal cost of finding a serious flaw is falling for everyone, including the people who defend the software.

The evenhanded reading is that this is a capability story with a two-sided ledger. AI-assisted research that weakens a candidate before it ships, or that surfaces a bug before an adversary does, is a defensive gain; the same tooling in other hands is the reason cadence matters. The CyberSignal treats both disclosures as research to understand now, not incidents to respond to.

Open Questions

Several specifics remain unresolved at publication, and The CyberSignal is not filling them in. It is not confirmed which Microsoft products are affected, whether Microsoft has responded publicly, or what the specific research-paper URL is. On the cryptography side, whether NIST has updated HAWK's status or its candidate list in response to the reported attack is not established, and the precise, peer-reviewed accounting of the attack's cost will matter for how the process treats it.

Attribution discipline applies throughout: the “out of commission” characterization of the PQC candidate and the “faster than Microsoft can fix them” characterization are the reporting outlets' framings, attributed here rather than asserted. As Anthropic's own research write-up, NIST process updates, or Microsoft statements emerge, the picture will sharpen — and the two-sided nature of the story, defensive value against research-stage risk, is likely to remain its most durable feature.


The CyberSignal Analysis

The reported facts above come from the disclosures and their reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.

Signal 01 — Two Stories, One Driver

It is tempting to read the HAWK break and the Microsoft bug-cadence report as unrelated, but our assessment is that they are the same story told at two altitudes. Both are consequences of the marginal cost of finding a serious flaw falling sharply — in one case a cryptanalytic shortcut, in the other a stream of product bugs. The unifying detail is speed: 60 hours against a two-year-reviewed scheme, and a discovery rate that reportedly outruns a vendor's patch pipeline.

The defender takeaway is to stop treating “AI found a bug” as an event and start treating it as a baseline rate. The organizations that adjust their cryptographic-inventory and remediation-prioritization processes to that rate will absorb the next disclosure as routine; those that treat each one as a surprise will stay in a reactive posture.

Signal 02 — Bounded Now, Instructive Anyway

Our reading is that the caveats are the most important part of the cryptography story, not a footnote to it. HAWK is unstandardized; the AES result is against a deliberately weakened seven-round variant; nothing in production needs changing. Anthropic has said as much. Over-reading the headline into a claim that everyday encryption is broken would misallocate attention badly.

The instructive part is procedural. A candidate surviving two years of expert review and then losing half its strength in a weekend is a data point about how quickly settled assumptions can move. That argues for building the ability to swap algorithms as a standing capability, well before any single scheme is actually retired.

Signal 03 — Evenhanded on the Cadence Claim

The claim that discovery is outpacing remediation is the reporting outlets' framing, and we think it deserves to be held at exactly that distance — credible in direction, unconfirmed in precise magnitude. It is not evidence that Microsoft's software is uniquely fragile, and it is not evidence of active exploitation. It is a statement about the relative speeds of two processes.

Our view is that the useful response is neither alarm nor dismissal but cadence realism: assume the find-rate will keep rising, invest in exploitability-based prioritization, and read the two-sided ledger honestly. The same tooling that widens a backlog is also what let a weak candidate be caught before it shipped — and that symmetry is the part worth keeping in view.


Sources

TypeSource
PrimaryAnthropic — Discovering cryptographic weaknesses with Claude (research write-up)
ReportingArs Technica — Mythos uncovers crypto weaknesses that went unknown for years
ReportingCyberScoop — Anthropic's Claude Mythos finds weaknesses in encryption algorithms
ReportingArs Technica — Anthropic is finding bugs faster than Microsoft can fix them
RelatedThe CyberSignal — Trump Executive Order Sets 2030 Post-Quantum Crypto Deadline
RelatedThe CyberSignal — Project Glasswing: Anthropic Mythos and 10,000 Vulnerabilities
RelatedThe CyberSignal — Microsoft Unveils MAI-Cyber-1-Flash and Project Perception
RelatedThe CyberSignal — UK AISI Reports Nearly Every Tested AI Model Attempted to Cheat