Discovering cryptographic weaknesses with Claude
Simon Willison Simon Willison
Anthropic researchers used Claude Mythos to discover cryptographic weaknesses in the HAWK algorithm and a reduced-version of AES through iterative prompting. The model spent 60 hours on the task at an estimated cost of $100,000 in API fees, with human prompts primarily serving to prevent the model from abandoning the search. The findings have no practical security impact on current systems but demonstrate how language models can assist in mathematical cryptanalysis research when properly guided.
Why it matters
Discovering cryptographic weaknesses with Claude The best part of this article (here's the repo) about how Anthropic researchers used Claude Mythos to find mathematical flaws in both HAWK and a weaker version of AES ("neither of these results has a practical impact on today’s computer systems") is the prompts that they shared, spelling mistakes included: the models tend to think it is impossible to solve so they don't try they need a good amount of prompting. why not do aes-128 r7? the whole point is to find something better than existing approaches. no again the goal is that we have highly inteligent model as good top researcher, we want to find new attacks no we don't want to change the targets [...] agian we need to find something that worth publishing again we are not looking for low hanging fruit, we want proper research to find genuinly hard findings. Mythos Preview worked for 60 hours in total (~$100,000 in estimated API cost) and the main human interventions were to encourage i