Technology

Anthropic's AI Cracked HAWK-256 in 60 Hours, Validating Bitcoin's PQ Caution

Anthropic's unreleased Claude Mythos Preview cracked HAWK-256, a NIST third-round post-quantum signature candidate, in roughly 60 hours at a cost of ~$100,000, cutting the scheme's effective key strength in half. Bitcoin's BIP-360 migration path never touched HAWK.

4 min read
Abstract digital lattice structure dissolving into fragmented geometric nodes, cool blue and white tones, no text or logos
Share

Anthropic's Claude Mythos found a novel attack on a NIST post-quantum finalist that human researchers missed for years. Bitcoin's upgrade path avoided this scheme entirely.

Key takeaways

  • Anthropic's unreleased Claude Mythos Preview broke HAWK-256, the last lattice-based signature candidate in NIST's third-round process, reducing the attack cost from roughly 2^64 operations to 2^38 (approximately 67 million times less work) in about 60 hours at ~$100,000.
  • No Bitcoin held today is at risk: Bitcoin runs ECDSA, HAWK has never been deployed anywhere, and BIP-360 targets already-finalized NIST schemes (ML-DSA, SLH-DSA), not HAWK.
  • A $100,000, 60-hour AI cryptanalysis campaign is now a repeatable capability, not a one-time demo. Nation-state programs running classified compute have had this capability for an unknown duration.

Anthropic announced on July 28, 2026 that its unreleased Claude Mythos Preview model discovered a previously unknown attack against HAWK-256, a digital signature scheme that had survived multiple rounds of human expert review inside NIST's post-quantum cryptography standardization process, per the Anthropic research blog. The attack exploits a previously unused symmetry in HAWK's lattice structure, cutting effective key strength roughly in half and reducing the operation count from ~2^64 to ~2^38.

The finding required one researcher providing project-management guidance (not a lattice cryptography specialist) and approximately $100,000 in API costs. Anthropic coordinated disclosure with NIST and notified algorithm authors and U.S. government and industry partners before publishing. The fix, Anthropic noted, is roughly doubling HAWK's key size, which carries a cost: "Unfortunately, doubling HAWK's key size eliminates many of the reasons making the scheme (as it currently stands) an attractive PQC signature candidate."

What the Attack Actually Means

HAWK was the last lattice-based signature candidate remaining in NIST's third-round process, which advanced nine candidates on May 14, 2026 per NIST IR 8610. It is not deployed anywhere in production. The break matters not because systems are exposed today, but because of what it proves about the review process and the resources now required to stress-test cryptographic assumptions.

NIST's standardization process exists precisely for this: surface weaknesses before deployment, not after. As Anthropic's post states, "The purpose of NIST's standardization process is to discover weaknesses in candidate schemes before they are deployed." That process worked. The more unsettling question is what the same class of AI-assisted analysis looks like when run on classified compute by programs that don't publish results.

The comparison to SIKE is instructive. That post-quantum candidate survived years of expert review and was broken in roughly one hour on a laptop in 2022. HAWK required 60 hours and $100,000 of frontier AI. The cost and time are falling. The NIST process remains the public check; it no longer enjoys a monopoly on the capability to run it.

Bitcoin's Conservative Path Holds Up

Bitcoin's post-quantum migration framework never included HAWK. BIP-360, which entered the official BIP repository on February 11, 2026, proposes a new output type (P2QRH) using ML-DSA and SLH-DSA, both already fully finalized NIST standards with a much deeper public review record. BIP-361, proposed by Jameson Lopp and others in April 2026, addresses the ECDSA sunset question separately.

The quantum defense funding effort underway in the Bitcoin ecosystem has been oriented toward finalized schemes for the same reason. Rushing to adopt third-round candidates before they cleared review would have been the wrong call. This break is evidence of exactly why.

The thesis here is falsifiable. If ML-DSA or SLH-DSA, the schemes BIP-360 actually targets, fall to a similar AI-assisted cryptanalysis before Bitcoin's migration is complete, the "wait for NIST finalization" strategy is exposed as insufficient and the urgency argument for a faster, more aggressive migration timeline wins. That is the scenario to watch, not HAWK.

What this break does change is the economic math on the threat model. A $100,000 AI campaign that can stress-test a post-quantum candidate in 60 hours is no longer a proof-of-concept. It's a repeatable tool. Nation-states and well-capitalized adversaries are not constrained by the publication schedules of public research programs. The argument for moving faster on BIP-360 activation, and for running aggressive AI-assisted red-teaming of ML-DSA and SLH-DSA at the protocol level before any soft fork activates them, just got materially stronger.

What to Watch

NIST's next communication on HAWK's status will clarify whether the scheme continues in modified form or exits the process. The more pressing item for Bitcoiners is whether the community accelerates formal AI-assisted cryptanalysis of ML-DSA and SLH-DSA as part of pre-activation review, and whether the quantum readiness efforts already funded start incorporating this class of tooling explicitly.

Sources

Frequently Asked Questions

No. Bitcoin uses ECDSA on secp256k1, which is entirely separate from HAWK. HAWK has never been deployed in Bitcoin or any production system. The break affects a NIST candidate still under review, at exactly the stage it was meant to be stress-tested. Bitcoin wallets and UTXOs are unaffected.

No. BIP-360 targets ML-DSA and SLH-DSA, fully finalized NIST standards, not third-round candidates like HAWK. The break strengthens the case for BIP-360's conservative algorithm selection. The more pressing question is whether AI-assisted cryptanalysis should be formally applied to ML-DSA and SLH-DSA as part of Bitcoin's pre-activation review process.

That's the structurally important question. Anthropic's $100,000, 60-hour campaign is a public demonstration of a capability that classified programs at NSA, GCHQ, or the PLA could be running at scale, against every NIST candidate simultaneously, with results that never surface publicly. The NIST process assumes the best-funded adversaries are constrained by human researcher bandwidth. That assumption no longer holds.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.