Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
A post-quantum cryptography candidate called HAWK has been withdrawn from NIST's third-round evaluation after Anthropic's Mythos model surfaced a structural weakness that two prior rounds of public cryptanalysis had missed. The developer pulled the algorithm the day after the disclosure.
The episode is less about HAWK than about the shifting economics of cryptographic review. For decades, the security of candidate standards rested on the assumption that a sufficiently large community of human researchers, given enough time, would eventually find the fatal flaw. That assumption is now being stress-tested by AI systems that can compress years of human scrutiny into a single pass. HAWK had already cleared two rounds of testing designed to catch exactly this class of vulnerability. Mythos found it anyway.
The practical consequence is procedural rather than dramatic. NIST's pipeline still works; one candidate was eliminated, and the remaining field is narrower and presumably stronger. But the implicit contract between standards bodies and the cryptographic community has changed. When an AI model can outperform years of distributed human review, the timeline for evaluating trust in a new primitive collapses. Standards that once took a decade to harden may now need to be re-examined on a much shorter clock, and the institutions responsible for that examination will need to decide whether AI-assisted cryptanalysis is an occasional tool or a permanent fixture of the process.
For anyone whose infrastructure depends on PQC migration timelines, the takeaway is straightforward: the standards themselves are not less trustworthy, but the window during which a published algorithm can be assumed fully vetted is shorter than it used to be. Plan accordingly.