Jul 30, 2026, 4:16 a.m.
2 min read
Bitcoin's quantum plan assumes some algorithms break. AI just weakened one in 60 hours (Chris Ried/Unsplash)Summary
- Anthropic’s Claude Mythos Preview model uncovered a flaw in the proposed HAWK digital-signature scheme that effectively halves its smallest key strength, undermining one of the candidates to replace current web and banking signatures in a post-quantum world.
- The AI-driven attack, which cost about 60 hours and $100,000 in computing, slashed the work needed to break HAWK’s smallest parameter set from roughly 2^64 to 2^38 operations, while rendering larger, compensating key sizes far less attractive.
- Although today’s bitcoin and ether signatures are unaffected, the results reinforce warnings that classical cryptanalytic attacks are rapidly improving, just as bitcoin and other networks debate how and when to migrate to quantum-resistant cryptography.
AI heavyweight Anthropic said earlier this week that its Claude Mythos Preview model had discovered an attack that halves the effective key strength of HAWK, a proposed replacement for the digital signatures that protect online banking and web payments.
The work took about 60 hours and roughly $100,000 in computing costs, against an algorithm that had survived two years and two rounds of expert human review.
Digital signature schemes such as HAWK prove that a message or data set came from whoever holds a particular digital key that points to that exact message. Bitcoin uses one every time a coin moves, and so does every website showing a padlock in the browser.
The versions in use today are expected to fail to quantum computers, and HAWK is one of the candidates under review to replace them. It has not been publicly deployed anywhere.
Nothing in the research affects bitcoin or ether currently, as both secure transactions with elliptic curve signatures, which neither attack had targeted. HAWK is not one of the schemes bitcoin would migrate to.
BIP-360, the proposal to give bitcoin quantum-resistant addresses, specifies three algorithms NIST has already standardized, and includes several deliberately so users have fallbacks if one is later broken by quantum or classical advances.
What changed is the speed of the classical side. BIP-361, the companion proposal that would freeze more than a third of bitcoin's supply, argues that the migration window is closing because cryptographic attacks are improving by up to 20-fold. Anthropic's results align with that trend, with a model behind it.
Against HAWK’s smallest parameter set, Anthropic said the expected cost of recovering a key fell from about 2^64 operations to 2^38. Larger keys remain impractical to attack, but doubling key sizes to compensate removes most of what made HAWK attractive.
The company disclosed the attack to HAWK’s authors in June and coordinated publication with NIST’s public mailing list.
A second result improved attacks on a deliberately weakened version of AES, the cipher used across the industry to encrypt wallet files, by factors of 200 to 800.
Importantly for crypto developers, Anthropic said the model produced smaller improvements, under tenfold, against Poseidon, the hash function that underpins many zero-knowledge proof systems, including those securing rollups and privacy protocols.
Claude, the firm’s popular AI tool, initially refused the AES problem, telling researchers it was “genuinely hard" and that there was “nothing easy to find.” But after three short prompts, it produced a billion output tokens over three days and found the improvement. Verifying it took two Anthropic researchers nearly a month.
The timing sits oddly well. Privacy network Zcash activated an upgrade on Tuesday, introducing a new shielded pool designed to remain recoverable if quantum computers become available.
The schemes meant to carry both through that transition are now being stress-tested by something that works faster than the people designing them.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Anvil: The Missing Collateral Layer
Anvil: The Missing Collateral Layer
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
20 hours ago
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
Why it matters:
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
View Full Report




