Five plain-English questions every C-level should be able to answer after reading this.
Q1 — The Basics: What actually happened?
Status: No immediate threat
On 28 July, Anthropic revealed that its AI model Claude Mythos found two mathematical weaknesses in encryption algorithms in under a week. The first is in HAWK, a next-generation scheme being considered for future global standards. The second is in a simplified test version of AES, the cipher protecting most of the internet today.
Nothing protecting your business right now has been broken. HAWK is not deployed anywhere. The AES finding applies only to a deliberately weakened research variant. (Source: Anthropic)

Q2 — The HAWK Finding: So HAWK is broken — does that affect us?
Status: Watch and note
HAWK was a strong candidate to become part of the next generation of post-quantum encryption standards. The AI found a hidden mathematical shortcut that effectively cuts its security in half. To fix it, designers would need to double the key sizes — which makes HAWK far less efficient and largely defeats its purpose. It is very likely to be dropped from the standardisation process.
This does not affect any system you run today — but it is a signal that algorithms which passed years of human review can still harbour flaws. (Source: PostQuantum.com)
Q3 — The AES Finding: Headlines said AES was attacked 800 times faster. Is that true?
Status: Overstated — no action needed
Partially — and the nuance matters. The "200–800x faster" figure describes only one dimension of the attack. The full picture: it still requires more data than exists on the entire internet to execute. The real improvement is modest — roughly equivalent to 2.7 extra bits of work removed from a research puzzle that has not moved since 2013.
If a board member or regulator raises this, the correct framing is: "A theoretical research attack on a deliberately weakened test version of AES improved slightly. Full AES, as deployed everywhere, is unaffected." (Source: Matthew Green, Johns Hopkins)
Q4 — The Real Risk: If nothing is broken, why should I care?
Status: Strategic concern
Because the economics have changed. Each result cost roughly $100,000 and one week of AI compute. That cost will keep falling — putting publishable cryptographic attacks within reach of any well-funded adversary, not just nation-state labs.
Three separate AI-assisted attacks on three different cipher families appeared in the same two-week window. This is not a one-off. It is the beginning of a new pace of discovery.
The exposure that should concern you is not HAWK or AES. It is the proprietary, vendor-supplied, and legacy encryption in your own infrastructure — systems that have never been reviewed with tools this powerful.
Q5 — What To Do: What should we actually do about this?
Status: Action required
Three things, in priority order:
- Know what you have. Commission a cryptographic asset inventory. You cannot protect or replace what you have not mapped.
- Set a policy. Establish which algorithms are approved, which are on notice, and who owns the decision to rotate them.
- Prove you can switch. Test your ability to replace an algorithm under non-emergency conditions — before you are forced to do it under pressure. This capability, known as crypto-agility, is the single most valuable investment you can make right now.
Sources
- Anthropic — anthropic.com/research/discovering-cryptographic-weaknesses
- Matthew Green, Johns Hopkins — blog.cryptographyengineering.com
- Marin Ivezic — postquantum.com/security-pqc/ai-cryptanalysis-hawk-aes



