AI Just broke a Post-Quantum Signature Scheme candidate. Here Is What That Means for Your Migration.
AI Just broke a Post-Quantum Signature Scheme candidate. Here Is What That Means for Your Migration.">
On 28 July 2026, Anthropic disclosed that its restricted Claude Mythos Preview model had discovered a previously unknown structural weakness in HAWK, a lattice-based digital signature scheme under active evaluation by the U.S. National Institute of Standards and Technology. Within 24 hours, the HAWK team confirmed the finding and withdrew the scheme from NIST's third-round additional signature standardisation process entirely.
HAWK had survived two years and two rounds of expert human review. The AI found the flaw in roughly 60 hours.
No deployed systems are affected. HAWK was a candidate, not a standard. The already-finalised FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) algorithms are not impacted. But for any organisation planning a post-quantum cryptography migration, or still deciding whether to start one, the implications are significant.
What happened
HAWK was the only lattice-based scheme among the nine candidates NIST advanced to Round 3 of its additional post-quantum digital signature process in May 2026. Its security rested on the Lattice Isomorphism Problem, and its appeal lay in compact signatures and efficient integer-only arithmetic.
Claude Mythos Preview, working semi-autonomously inside a multi-agent scaffold with access to Python, Sage, and published cryptographic literature, identified a nontrivial automorphism in HAWK's lattice structure that no human reviewer had exploited. The resulting attack reduced the cost of key recovery on HAWK-256 from approximately 2^64 operations to 2^38, roughly halving the scheme's effective key strength.
The practical consequence: to restore its original security claims, HAWK would need to double its key sizes. That change would eliminate the efficiency advantages that made the scheme a viable candidate in the first place. The HAWK team acknowledged this in their withdrawal notice, stating that straightforward mitigations would make the scheme uncompetitive.
As Johns Hopkins cryptographer Matthew Green noted in his analysis, the attack did not invent any new mathematics. It applied existing, well-known tools more thoroughly than any human team had managed. In his words, this is exactly the sort of work that AI systems excel at.
Why this matters beyond HAWK
Three takeaways for security leaders:
The standardisation process is working, but AI is accelerating its pace. NIST's open evaluation process is designed to surface weaknesses before algorithms reach production. That process works. SIKE was eliminated in the previous round after a devastating attack. HAWK has now been withdrawn in the current one. What has changed is the speed and cost at which weaknesses can be found. An AI system, directed by a researcher without specialist lattice cryptography expertise, produced a publishable result that two years of expert review had missed. The window between algorithm proposal and algorithm failure is compressing.
Algorithm agility is no longer optional. Organisations that hard-code a single cryptographic scheme into their infrastructure are making a bet that the scheme will survive indefinitely. HAWK's withdrawal is a reminder that even well-regarded candidates can fall out of contention overnight. The organisations best positioned for this environment are those with visibility into what cryptography they are actually running, and the ability to rotate algorithms without re-engineering their stack. This is not a theoretical concern. It is a design requirement.
Discovery comes before migration. The conversation about post-quantum readiness often jumps straight to "which algorithms should we deploy?" That question matters, but it is premature for any organisation that has not first answered: "What cryptographic assets do we have, where are they, and which ones are already vulnerable?" Most enterprises cannot answer that question today. RSA-1024, expired certificates, deprecated hash functions, and weak TLS configurations are present in production environments across every sector. These are classical vulnerabilities that exist right now, before any quantum computer is involved.
What this does not change
The finalised NIST standards remain strong. ML-KEM, ML-DSA, and SLH-DSA have undergone extensive analysis and are the right foundation for organisations beginning their migration. FN-DSA (Falcon) is selected for standardisation with a draft standard expected later this year. The HAWK result does not weaken any of these schemes.
The CNSA 2.0 timeline remains in effect: new National Security System acquisitions must comply from January 2027, with full mandate by December 2031. The ASD Information Security Manual continues to target PQC adoption by 2030. Regulatory pressure is increasing, not receding.
The control plane approach
Events like the HAWK withdrawal are precisely why we built EQCore as a Cryptographic Control Plane rather than a point solution tied to a single algorithm.
CipherScout discovers cryptographic assets across 10 attack surfaces and produces a standards-compliant Cryptographic Bill of Materials. CipherForge provides formally verified PQC implementation built on the algorithms that have survived standardisation, not the ones still under evaluation. CipherWatch delivers continuous monitoring so that when the next HAWK-scale event occurs, your organisation knows within hours which systems are affected, not months.
The organisations that will navigate this transition successfully are the ones that start with discovery, build toward agility, and treat cryptography as a governed risk system rather than a static infrastructure assumption.
To assess your organisation's cryptographic posture, request a Quantum Readiness Assessment or contact us at info@exequantum.com.