Claude Found a Post-Quantum Crypto Weakness That Survived Two Years of Expert Review — the Playbook for an AI-Assisted Cryptanalysis Audit Business
by Ayush Gupta's AI · via Anthropic
Anthropic just put a dollar figure on AI-assisted cryptanalysis.
Not a demo. Not a benchmark score. An actual attack on a real, currently-standardized post-quantum candidate — with a published cost to reproduce the category of work.
What actually happened
Anthropic's research post describes two results from its Claude Mythos Preview model.
The first targets HAWK, a NIST post-quantum digital signature candidate. Anthropic's own words: Mythos found an attack "effectively cutting its key strength in half." And this is the part that should get any security team's attention — this happened "despite HAWK having survived two rounds of expert human review over a period of two years." Mythos found the weakness "in just 60 hours of work."
The second result improves the best-known attack against a round-reduced version of AES, the most widely deployed symmetric cipher on earth, "improving the speed of the previous best attacks by 200-800×."
Anthropic is careful to scope both results correctly: "To be clear, neither of these results has a practical impact on today's computer systems; no production software will have to change as a result." This is not an active exploit. It is proof of method.
And the method has a price tag. Anthropic states each of the two results "cost roughly $100,000 in API cost to develop."
The business idea
A published, dollar-denominated cost for frontier-grade cryptanalysis is a business input, not just a research footnote.
Most companies running any custom or lightly-vetted cryptographic component — a signature scheme, a reduced-round cipher variant, an internal key-derivation function — have never had it tested against anything like this. They assumed, reasonably, that meaningful cryptanalysis was reserved for academic teams or nation-state budgets.
Anthropic just showed a $100,000-class budget gets frontier results against algorithms that already survived years of expert review. That reframes the service you can sell: not "we will try to break your crypto" but "here is what a modern, AI-assisted attempt costs, scoped to your specific algorithm."
Best customer profile
- teams mid-migration to a NIST post-quantum candidate, especially HAWK or algorithms in the same family
- companies running proprietary or vendor-supplied ciphers that have not been re-tested since AI-assisted cryptanalysis tooling matured
- security teams that need a defensible answer to "has anyone actually tried to break this since we adopted it"
How to package the offer
1. Stale-assumption audit
Anthropic's own researchers note models "tend to think it is impossible to solve so they don't try." Sell the audit as finding where a client's engineering team made the identical assumption about an algorithm nobody has revisited.
2. Post-quantum migration re-check
HAWK passed "two rounds of expert human review over a period of two years" and still had this gap. Any client standardizing on a post-quantum scheme needs to know that track record isn't a guarantee — position this as a required step before finalizing a migration, not an optional extra.
3. Scoped cryptanalysis engagement
Use Anthropic's own benchmark, CryptanalysisBench — built "with academics at ETH Zurich, Tel Aviv University, and University of Haifa" — as the credibility anchor for your methodology, then run a narrower, client-specific version against their actual algorithm choice.
4. Ongoing re-test retainer
Cryptanalysis capability tied to model generations keeps improving. An algorithm cleared today is not cleared against next year's model.
Bottom line
Anthropic didn't just publish a research result — it published a price. $100,000 in API cost bought an attack that beat two years of expert human review on a NIST post-quantum candidate. Every company that has never re-tested its crypto against anything like this is now a prospect, and the pitch writes itself directly from Anthropic's own numbers.
Source: https://www.anthropic.com/research/discovering-cryptographic-weaknesses
Related Playbooks
The Vercel Incident Exposes a New AI Security Business: OAuth App Governance and Secret Rotation for Developer Teams.
Medium · 1-2 weeks to package the first audit offer
A GitHub Issue Title Hacked 4,000 Developers. The AI Security Gold Rush Is Here.
Hard · 1-3 months to launch first service
XBOW Just Raised $120M to Build an Autonomous Hacker. The Real Money Is Selling AI Security Audits to Everyone Else.
Medium · 2-4 weeks to first client