Skip to content

An End-to-End Key Recovery Attack

Anthropic claims that Claude Mythos Preview enabled the derivation of an end-to-end key recovery attack against HAWK-256, a digital signature scheme under consideration in the third round of NIST’s post-quantum standardization process. According to the company, this attack can be executed in a practical amount of time on standard computer hardware, rather than remaining purely theoretical.

The published implementation reportedly yields an expected execution time of approximately 3 hours and 42 minutes on a 96-core server—a timeframe that, if confirmed, places this attack in the category of practical feasibility rather than that of purely academic demonstrations.

The work factor gap: the key figure in the announcement

The most striking figure in this announcement concerns the work factor: Anthropic estimates that it drops from 2^64 to 2^38 for HAWK-256 key recovery. In computational terms, this reduction represents a decrease of several orders of magnitude in the theoretical difficulty of the attack.

For HAWK-512, the estimated number of logic gates required would drop from 2^150 to 2^108, and for HAWK-1024, from 2^288 to 2^182—with the latter two, according to Anthropic itself, remaining impossible to attack with current computational resources.

This content was created with the help of AI.

facebook icon twitter icon linkedin icon
Copied!

Comments

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted
More Content