🟠 High | Source: The Hacker News
Anthropic’s Claude AI has independently derived a practical key-recovery attack against HAWK-256, a post-quantum digital signature scheme, exploiting an unused symmetry in its underlying lattice structure and achieving a full end-to-end attack in under four hours on commodity server hardware. It also found a 200- to 800-fold speedup for an existing attack on seven-round AES-128. This demonstrates that AI-assisted cryptanalysis is maturing rapidly, with implications for organisations relying on post-quantum cryptographic standards.
Security Architect’s Take: Review your cryptographic agility posture now — if you have dependencies on HAWK-256 in any signing or key-exchange workflows, treat it as compromised and plan migration to an alternative NIST-approved post-quantum scheme such as ML-DSA (CRYSTALS-Dilithium). More broadly, this is a signal to prioritise crypto-inventory tooling so you can respond quickly when future AI-assisted breaks emerge.
Original advisory: Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack