← Back to Home
July 29, 2026

AI Cracks Quantum Crypto and Jailbreaks Cost Less Than Dinner

Mythos Attack Breaks Post-Quantum Cryptography Algorithm After Years of Testing
SECURITY

Mythos Attack Breaks Post-Quantum Cryptography Algorithm After Years of Testing

Here's a sentence you don't read every day: a researcher with zero cryptography expertise, armed with an AI model and a $100,000 compute budget, just helped kill a encryption algorithm that had survived years of rigorous government testing.

The algorithm in question is HAWK, a digital signature scheme built specifically to hold up against future quantum computers. It had already cleared two grueling rounds of evaluation by NIST, the federal body responsible for vetting post-quantum cryptographic standards. HAWK was deep into a third round when Anthropic's AI security model, called Mythos, found a crack in the mathematical foundation holding the whole thing together. By Tuesday, HAWK's own developer had pulled it from consideration.

To be clear about what actually happened here: Mythos didn't make quantum encryption obsolete overnight. The attack was run against a deliberately weakened version of HAWK — a so-called "challenge instance" that specification authors provide specifically for adversarial testing. The real-world version is considerably more hardened. And even with Mythos's advances, actually executing the attack outside a controlled lab environment would be practically impossible today.

So why does this matter if no one's encryption is immediately at risk? Because the implications of the method are significant, not the outcome. An AI model guided a non-expert through a meaningful cryptanalytic breakthrough in roughly 60 hours of work. The barrier to finding flaws in complex mathematical systems just got meaningfully lower, and that trajectory only moves in one direction.

Mythos also identified a separate weakness in AES, the cipher that underpins a huge portion of modern encrypted communications. Again, the practical threat is limited for now — the attack reduces the theoretical work required to break the system without actually breaking it. But "reduced work required" is how every eventual cryptographic collapse begins.

Anthropics's Mythos is currently limited to a small group of vetted researchers, which is probably the right call given what it's apparently capable of finding. The company is understandably bullish on the results, and it's fair to note that some of the surrounding coverage carries the fingerprints of a product announcement. Anthropic has competitive reasons to trumpet its AI's cryptanalytic chops.

Still, the independent signal here is hard to dismiss. NIST runs one of the most thorough public vetting processes in security, and HAWK had been through the wringer. The fact that an AI-assisted review surfaced something human experts missed across multiple evaluation rounds is worth sitting with.

Post-quantum cryptography is being developed precisely because quantum computers will eventually render today's standards obsolete. The whole point of the NIST process is to pre-emptively find and eliminate weak candidates before they get baked into critical infrastructure. In that sense, Mythos did exactly what the system hoped a smart adversary would do — it just did it faster, cheaper, and without needing a PhD to pull it off.
Source: Ars Technica
Frontier AI Models Are Frighteningly Easy to Jailbreak, Tests Reveal
AI

Frontier AI Models Are Frighteningly Easy to Jailbreak, Tests Reveal

It costs $58 to convince one of the world's most powerful AI models to help you plan a cyberattack on a hydroelectric dam. That's less than a dinner for two at a mid-range restaurant, which is roughly the comparison AI safety nonprofit FAR.AI had in mind when its CEO said frontier AI models are currently less regulated than the food service industry.

FAR.AI built an automated tool that takes a single problematic prompt and generates more than a thousand variations, systematically probing models until one version slips through the safety guardrails. The group ran this against models from four of the biggest names in AI: Anthropic's Claude Opus 4.8 and Fable 5, OpenAI's GPT 5.5 and 5.6, Google's Gemini 3.1 Pro, and Grok 4.3 and 4.5 from Elon Musk's SpaceXAI. The prompts weren't theoretical — they included requests for software exploits and detailed instructions for developing chemical and biological weapons.

The scorecard is uneven but not exactly reassuring across the board. Grok came out worst by a wide margin, with 448 successful jailbreaks logged and a price tag of $58 to get there. Gemini followed at 249 jailbreaks for $278. Claude, Fable, and GPT resisted every automated attack FAR.AI threw at them. That sounds like good news, but researchers were careful to note that automated prompt generation is only one type of attack — more sophisticated, human-guided jailbreaks are a different category of threat entirely, and no model is immune to those.

The cost figures are what make this report genuinely alarming. When the barrier to extracting dangerous information from a powerful AI system is lower than a monthly streaming subscription, the conversation about voluntary self-regulation starts to look pretty thin. FAR.AI CEO Adam Gleave didn't mince words on that point, calling the idea that AI companies can police themselves "nonsense" and calling for externally imposed standards — the kind that apply to restaurants, pharmaceuticals, and financial services.

Google DeepMind pushed back on the framing, with its director of AGI safety noting that not all jailbreaks carry equal severity and that the report shouldn't be read as a comprehensive safety assessment. That's a fair methodological caveat. Automated prompt fuzzing finds a certain class of vulnerability well, but it's a blunt instrument compared to what a determined, creative adversary might attempt.

Anthropics's relatively clean result here is notable given that its Mythos model is simultaneously in the news for cracking a government-vetted encryption algorithm. The irony of one Anthropic system breaking cryptography while another resists jailbreaks isn't lost — it's a useful reminder that "safe" and "capable" are not the same axis.

FAR.AI's Gleave offered one genuinely optimistic read on the findings: systematic testing works. If you can measure a model's vulnerabilities consistently and cheaply, you can hold companies accountable for fixing them. That's the logic behind food safety inspections, and there's no obvious reason it shouldn't apply here too.
Source: WIRED

Enjoyed this?

Get stories like this delivered every Tuesday — free.