# An Anthropic AI Model Broke a Post-Quantum Signature Candidate in 60 Hours, Testing Crypto's Quantum Timelines

The attack on HAWK cut the smallest configuration's key-recovery cost from 2^64 to 2^38 operations, roughly 67 million times less work, for an application programming interface (API) bill of about 100,000 dollars.

- Published: 2026-07-30T05:29:14.457Z
- Canonical: https://polylog.news/crypto/2026-07-30/an-anthropic-ai-model-broke-a-post-quantum-signature-candida
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/07/29/bitcoin-s-quantum-plan-assumes-some-algorithms-break-ai-just-weakened-one-in-60-hours), [Polylog editors](https://polylog.news)

An unreleased model from the artificial-intelligence company Anthropic, identified as Claude Mythos Preview, found a practical key-recovery attack on HAWK-256, a lattice-based digital-signature scheme under active evaluation by the US National Institute of Standards and Technology (NIST), [CoinDesk reported](https://www.coindesk.com/tech/2026/07/29/bitcoin-s-quantum-plan-assumes-some-algorithms-break-ai-just-weakened-one-in-60-hours). The model worked semi-autonomously for roughly 60 hours, with a human researcher supplying project management rather than lattice expertise, and revealed a flaw that had survived about two years of expert human review.

The mechanism was a mathematical shortcut in the lattice structure that secures HAWK, a nontrivial automorphism that effectively halved the scheme's key strength. For the smallest configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38, roughly 67 million times less work, at an API cost Anthropic put near 100,000 dollars.

HAWK is not deployed anywhere, and neither Bitcoin nor Ethereum uses it. It is the only lattice-based scheme among the nine candidates NIST advanced in its additional post-quantum signature process. The result matters because it shows classical cryptanalysis accelerating with machine assistance precisely as networks debate how and when to migrate signatures that a future quantum computer could break.

The timing question is now concrete. Changpeng Zhao, the founder of the exchange Binance, argued that the Bitcoin community should give Satoshi Nakamoto 12 months to move early coins before any quantum-hardening upgrade that could freeze long-dormant balances, [according to a translated summary of his remarks](https://t.me/GokuCryptoNews/20240). That proposal highlights the core tension: a migration that protects the network can also lock up or invalidate coins whose owners never sign again.

## What this means

The exposed asset is any chain that relies on elliptic-curve signatures, meaning most of the market value in Bitcoin and Ethereum, plus custodians holding long-dormant coins. The channel is not a live break but the compression of the migration timeline: if machine-assisted cryptanalysis keeps halving the safety margins of candidate schemes, the time available to standardize and deploy quantum-resistant signatures shrinks, and the cost of a contested hard fork over dormant balances rises. Holders of early coins and the developers who must choose whether to freeze them are the parties most directly exposed.

## What to watch

- Whether NIST keeps HAWK in its additional signature process or removes it, which would signal how seriously standards-setters treat AI-assisted attacks.
- Any formal Bitcoin Improvement Proposal setting a deadline for moving legacy coins, because that turns the dormant-coin debate into a scheduled, contentious network decision.
- Follow-on results from frontier AI models against other post-quantum candidates, since a second break would move this from an isolated case to a trend.
