A recent disclosure from Anthropic highlights how quickly AI is changing the cryptographic landscape.
According to the company, the Mythos AI system identified a previously undiscovered attack against HAWK, a candidate algorithm in the ongoing NIST post-quantum cryptography (PQC) evaluation process, leading the HAWK team to withdraw the algorithm from consideration.
While some may view this as a warning sign for post-quantum cryptography, the bigger story is actually encouraging: the evaluation process worked exactly as intended. The lesson for organizations is to prepare now for a future where AI accelerates both cryptographic innovation and cryptographic disruption.
Key Takeaways
- AI-assisted cryptanalysis is becoming a meaningful force in evaluating cryptographic strength.
- Organizations should expect cryptographic change to accelerate in the years ahead.
- Crypto-agility is becoming a foundational security requirement, not an optional capability.
- Security leaders need visibility and control over cryptographic assets to adapt quickly as standards evolve.
What Happened?
Earlier this week, reports emerged that Anthropic's Mythos AI system identified a material attack against HAWK, one of the algorithms under evaluation in NIST's fourth round of post-quantum cryptography review.
This development comes after more than a decade of NIST-led evaluation efforts that have already produced standardized post-quantum algorithms, including ML-KEM, ML-DSA, and SLH-DSA, with additional candidates still under review.
What Does This Mean?
This is not a failure of post-quantum cryptography. On the contrary, it’s evidence that the standardization process is working exactly as intended.
Cryptographic competitions are designed to expose weaknesses before widespread deployment. We saw a similar outcome in 2022 when the SIKE candidate was broken during evaluation. The strongest algorithms survive intense scrutiny, while weaker approaches are eliminated before they reach production environments.
What this also shows is that AI will dramatically accelerate cryptanalysis. Historically, discovering weaknesses in cryptographic algorithms often took years of research by specialized teams. AI has the potential to speed up that process, meaning future algorithms could face much more rigorous and rapid evaluation than ever before.
Why This Matters for Cryptographic Strategies
The cryptographic environment is more dynamic than at any point in recent decades.
Organizations are already navigating the migration to quantum-safe cryptography. At the same time, additional PQC algorithms will continue emerging through the NIST process, and AI-driven analysis may expose new weaknesses, implementation flaws, or entirely new attack techniques faster than expected.
This is why crypto agility has become essential. Organizations need the ability to rapidly transition their cryptography when security requirements or standards change.
The organizations best positioned for the AI era will be those prepared to adapt to algorithmic change.
What Should Organizations Do Now?
Most organizations do not need to change course because of this news. They should continue their post-quantum migration planning and implementation efforts.
Security leaders should take this opportunity to assess whether they can rapidly adapt to future cryptographic change. Key questions include:
- Do you know where cryptography is used across your organization?
- Can you quickly replace algorithms when standards evolve?
- Are you prepared for a faster pace of cryptographic innovation and disruption?
- Do you have visibility into cryptographic assets, keys, certificates, and policies?
To address these questions, organizations need three core capabilities:
- Find cryptographic assets.
- Control cryptographic policies, keys, and implementations.
- Automate cryptographic lifecycle management and future transitions.
The organizations that answer "yes" to those questions and put these capabilities in place will be better positioned not only for quantum computing, but also for the AI-driven future of cryptography.
Preparing for a Faster Pace of Cryptographic Change
For organizations preparing their cryptographic strategies, the takeaway is clear: do not wait for the cryptographic environment to stabilize before acting. Build the visibility, control, and automation needed to adapt as standards evolve, implementations mature, and AI-assisted cryptanalysis becomes part of the security landscape.
To learn more about preparing for the transition to quantum-safe cryptography, explore Entrust’s post-quantum guidance.