Anthropic's AI model, Mythos, identified vulnerabilities in cryptographic algorithms that secure the internet. The model discovered mathematical weaknesses in encryption standards, including a reduced version of AES, the world's most widely used symmetric encryption standard. According to Anthropic, the findings do not affect systems currently in use. The model developed two attacks at an API cost of roughly $100,000 each. Human researchers primarily managed the project, provided simple prompts, and later verified the results.

Mythos found an improved attack on the post-quantum signature scheme HAWK and a new attack on a reduced version of AES. HAWK is a candidate in an ongoing standardization process by NIST, while the AES attack applies to a modified version using 7 of the full scheme's 10 rounds. The results highlight how AI models could challenge core assumptions behind internet security. Mythos worked semi-autonomously in a multi-agent system, with one agent initially dismissing the idea as infeasible, but a second agent found a way to fully exploit it.

The human researcher, with a background in theoretical computer science, played a limited role in project management. The model also found an attack on a reduced version of AES-128, developing a new fingerprinting method called 'Möbius Bridge' that improves on previous attacks by a factor of 200 to 800. Human prompting played a small role, with the model initially refusing to tackle the problem, citing the difficulty of further improvements. The researcher encouraged it to look for 'genuinely novel ideas,' leading to the discovery.

Source: thedecoder