Morning Edition · Thursday, July 30, 2026Published at 1:29 AM EDT · New York
An Anthropic AI Model Broke a Post-Quantum Signature Candidate in 60 Hours, Testing Crypto's Quantum Timelines
The attack on HAWK cut the smallest configuration's key-recovery cost from 2^64 to 2^38 operations, roughly 67 million times less work, for an application programming interface (API) bill of about 100,000 dollars.

An unreleased model from the artificial-intelligence company Anthropic, identified as Claude Mythos Preview, found a practical key-recovery attack on HAWK-256, a lattice-based digital-signature scheme under active evaluation by the US National Institute of Standards and Technology (NIST), CoinDesk reported. The model worked semi-autonomously for roughly 60 hours, with a human researcher supplying project management rather than lattice expertise, and revealed a flaw that had survived about two years of expert human review.
The mechanism was a mathematical shortcut in the lattice structure that secures HAWK, a nontrivial automorphism that effectively halved the scheme's key strength. For the smallest configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38, roughly 67 million times less work, at an API cost Anthropic put near 100,000 dollars.
HAWK is not deployed anywhere, and neither Bitcoin nor Ethereum uses it. It is the only lattice-based scheme among the nine candidates NIST advanced in its additional post-quantum signature process. The result matters because it shows classical cryptanalysis accelerating with machine assistance precisely as networks debate how and when to migrate signatures that a future quantum computer could break.
The timing question is now concrete. Changpeng Zhao, the founder of the exchange Binance, argued that the Bitcoin community should give Satoshi Nakamoto 12 months to move early coins before any quantum-hardening upgrade that could freeze long-dormant balances, according to a translated summary of his remarks. That proposal highlights the core tension: a migration that protects the network can also lock up or invalidate coins whose owners never sign again.
- If true, who benefits
Anthropic and the AI-capability narrative, plus post-quantum cryptography vendors and the crypto outlets that convert a test-scheme result into a Bitcoin quantum scare.
- The nuance
Anthropic and independent cryptographers stress HAWK is deployed nowhere, the break does not extend to other lattice schemes or to the elliptic-curve keys securing Bitcoin and Ethereum, and the 60 hours was discovery time, not the roughly 3.7-hour key recovery itself.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The exposed asset is any chain that relies on elliptic-curve signatures, meaning most of the market value in Bitcoin and Ethereum, plus custodians holding long-dormant coins. The channel is not a live break but the compression of the migration timeline: if machine-assisted cryptanalysis keeps halving the safety margins of candidate schemes, the time available to standardize and deploy quantum-resistant signatures shrinks, and the cost of a contested hard fork over dormant balances rises. Holders of early coins and the developers who must choose whether to freeze them are the parties most directly exposed.
What to watch
- Whether NIST keeps HAWK in its additional signature process or removes it, which would signal how seriously standards-setters treat AI-assisted attacks.
- Any formal Bitcoin Improvement Proposal setting a deadline for moving legacy coins, because that turns the dormant-coin debate into a scheduled, contentious network decision.
- Follow-on results from frontier AI models against other post-quantum candidates, since a second break would move this from an isolated case to a trend.
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Polylog editors
Part of a tracked trend
Quantum Risk Moves From Theory to Crypto Roadmaps
Over the next 3-6 months, quantum-resistance becomes a concrete design and custody concern across major chains and institutional custodians, driving opt-in post-quantum schemes and 'long-dormant coin' risk discussion.
More from this edition
- Senators Race to Move Crypto Market-Structure Bill Before the August Recess
- Federal Reserve Holds Rate at 3.5 to 3.75 Percent as Bitcoin Trades Near 64,000 Dollars
- Privacy Layer-2 Networks Aztec and Miden Push Confidential Execution Toward Production
- DeFi Self-Dealing Exploits Drain Reward Vaults on Ethereum and BNB Chain
- Ethereum Foundation Adds SEAL 911 Co-Founder to Its Board as Security Takes Priority
- Perpetual Futures Boom Recasts Ethereum as the Settlement Layer for Layer-2 Trading Venues
- Twenty One Capital CEO Says the Debt-Funded Bitcoin Treasury Model Is Ending
- Robinhood Posts 1.31 Billion Dollar Quarter as Prediction Markets Offset Cooling Crypto
- Stablecoin Issuers Confront Fragmenting Liquidity as Custom Tokens Multiply
- Russia Detains BitRiver Founder in Mining-Equipment Fraud Case and Targets Telegram's Durov
- Ethereum Researchers Turn to Mechanism Design as Execution Becomes a Commodity