AI CRYPTANALYSIS / POST-QUANTUM STANDARDS
Qtonic Quantum Research Team | July 30, 2026
On Tuesday, July 28, a researcher posted an improved key-recovery attack against the post-quantum signature scheme HAWK to the public mailing list NIST uses for its post-quantum standardization process. The post credited the finding to Anthropic’s Claude Mythos Preview model, “with minimal technical guidance from people” [1].
Within about five hours, a cryptographer replied that the result checked out independently. The next morning, roughly 17 hours after the original post, the HAWK team withdrew their candidate from the standardization process entirely [1].
One important qualifier, because the number invites misreading. That 17 hours is public disclosure to public withdrawal, not evaluation time. Anthropic shared the attack with HAWK’s authors in June and coordinated the public release with them [2]. The team had weeks to check the mathematics before the clock the world saw ever started.
What compressed was not the analysis. It was the interval between a scheme being publicly trusted and publicly abandoned, on a candidate that had been open to attack since 2022 and had cleared two rounds of expert review.
No deployed cryptography broke. HAWK was a candidate, not a standard, and the researcher who posted the attack stated plainly that the result does not impact Falcon, ML-DSA, or other lattice-based schemes [1]. Nothing your organization runs today needs a patch because of this.
That is the accurate reading, and it is also the one that lets you put the article down. Here is why we think that would be a mistake.
What Was Actually Broken
HAWK’s security rests on a lattice problem. The attack works by exploiting a previously unused symmetry in the lattice HAWK is built on, which cuts roughly in half the work needed to recover an equivalent secret key [1][2].
The numbers, in the cost model HAWK’s own specification uses. For HAWK-512, the estimated key-recovery cost falls from two to the one hundred and fiftieth operations to two to the one hundred and eighth. For HAWK-1024, from two to the two hundred and eighty-eighth to two to the one hundred and eighty-second [1]. Both remain far outside anything achievable. Alongside those estimates, the researchers demonstrated a working end-to-end recovery of a HAWK-256 key in a few hours on a single server [1]. Precision matters here, and most coverage has blurred it: HAWK-256 is a challenge parameter set published as a target for cryptanalysts, not a security level anyone proposed deploying.
So the practical demonstration hit the practice target, and the security-level parameters were weakened on paper but not broken. On its own, that is a normal week in cryptanalysis.
What made it terminal was economics. Restoring the intended security level meant doubling parameters or moving to higher rank modules, and the HAWK team concluded that either fix would make the scheme uncompetitive [1]. HAWK’s pitch was compact signatures. A version that is no longer compact has no argument left. One participant in the thread had already observed that HAWK’s largest parameter set carried roughly the same combined public key and signature size as ML-DSA-44, the standardized scheme it hoped to complement [1]. The attack did not have to break HAWK. It only had to make HAWK boring.
The Detail Most Coverage Missed
This was not one model, one lab, or one lucky run.
In the same forum thread, a researcher disclosed a separate attack on HAWK produced with GPT-5.6, taking a mathematically different route and implemented with a coding agent. Its result was weaker, and its draft was dated July 17, eleven days before the Anthropic post [1]. Human cryptographers had been working the same scheme over the same period, and the thread references their results alongside the model-assisted ones [1].
Two unrelated teams, two different frontier models, two different mathematical routes, eleven days apart, on the same scheme. A single vendor result is easy to dismiss as a company advertising its own model. Two of them from unrelated groups is harder to wave off. It is evidence that the capability is beginning to diffuse beyond a single laboratory, and that HAWK was not singled out so much as it was standing in front of the capability when it arrived.
One more detail from the same thread, easy to skim past. A researcher mentioned, almost in passing, new structural key-recovery records against McEliece variants using an AI-extended version of an existing attack [1]. That is a second family of cryptography, in the same conversation, on the same day.
What Actually Changed
Not this: an AI can do cryptanalysis. That was already established, and the researchers involved were careful to bound their claims. The attack is still exponential. It is specific to HAWK.
This: the public status of a candidate changed in a working day. The private evaluation was orthodox and took weeks. What ran fast was everything downstream of disclosure. Standardization is built around human review throughput, measured in conference cycles and comment periods, and the visible part of this event did not move at that speed. The evaluation stayed sound. The publication tempo did not.
And this: the community immediately recognized it has a verification problem. Within hours, participants in the thread were arguing that AI-assisted cryptanalysis results should come with machine-checkable proofs or working demonstrations against scaled-down targets, so outsiders can validate claims cheaply. One called for a community-standard set of rules for adjudicating AI-generated cryptanalytic claims, warning that without them the field will be overwhelmed by more claims than humans can reach consensus on, and noting that nobody can afford to run their own verifier against every claim [1]. That is a serious field, in public, discovering in real time that its quality-control process was calibrated for a slower world.
What This Does Not Mean
Post-quantum cryptography is not in trouble. The standards selected for deployment are not implicated. The attack does not extend to ML-DSA, Falcon, or lattice cryptography generally [1]. If anything, a candidate being eliminated before deployment is the standardization process performing its exact function, which is why candidates are published for attack in the first place.
This is not a reason to slow down. Delay is the one conclusion the evidence cannot support. Nothing here changed the quantum timeline, and the harvest-now-decrypt-later exposure that drives it is unchanged. Reading “a post-quantum candidate was withdrawn” as “the standards are unsettled, so we will wait” inverts the finding.
And HAWK was already marginal. The size argument against it predates the attack. An honest account has to say that the attack was the proximate cause of the withdrawal, not the sole reason the scheme was struggling.
What It Means for Anyone Running Cryptography
The uncomfortable question this raises is not about HAWK, which almost nobody was using. It is about what happens the first time a result like this lands on something that is deployed everywhere.
On that day, the difference between organizations will not be who has the best cryptographers. It will be who can answer one question quickly: where do we run this, and in what. Every subsequent step, identifying affected vendors, choosing replacements, sequencing change windows, waits on that answer. Organizations holding a current, machine-readable cryptographic inventory can answer materially faster than organizations that have to begin with a manual discovery effort.
That capability is built before the news arrives or it is not available when it does. The same inventory also supports audit readiness, procurement diligence, incident response, and federal post-quantum migration planning. Nobody has ever regretted knowing what cryptography they run.
The Measurement Layer
This is the work Qtonic Quantum exists to do, and the sequence is deliberately unglamorous. Find what you run. QScout produces an approved-scope cryptographic exposure inventory with evidence, ownership, priority, and CBOM-ready context. It is a governed assessment, not a self-serve scan. The public page captures authorization context, and an analyst confirms the requester and the scope before any assessment work begins [3].
Prove what actually matters. QStrike applies provider-aligned modeled profiles across six provider configurations and four modalities, with zero quantum hardware connected and no live-hardware execution, and it keeps modeled, observed, and unproven results distinct [4]. Then fix in the order the evidence supports, with QSolve sequencing migration, owner routing, and exception handling [3]. Qtonic Quantum Lab sits alongside all three as a separate public evidence registry rather than a fourth product, and in that registry no vendor pays for inclusion, ranking, evaluation, or a specific score [3].
This material is for informational purposes only and does not constitute legal, regulatory, compliance, or professional advice, and it does not establish any professional relationship. Qtonic Quantum Corp is not responsible for decisions made in reliance on this material without an authorized engagement. References to Anthropic, NIST, OpenAI, and other third parties are based on publicly available information and are used for analysis and commentary. They do not imply any partnership, endorsement, or affiliation. Descriptions of published research and public mailing-list correspondence reflect our reading of the cited sources as of the date above and are not independent verification of their technical claims. Product capabilities are described as of the date of publication and apply within the authorized scope of an engagement. Forward-looking statements about cryptographic and regulatory timelines are subject to change.
[1] NIST pqc-forum, thread “HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1,” July 28 to 29, 2026. Cited within the thread: the attack announcement and the HAWK-512 and HAWK-1024 gate-count figures, the statement that the result does not impact Falcon, ML-DSA, or other lattice-based schemes, the attribution of the finding to Claude with minimal technical guidance, the independent confirmation posted the same evening, the separately disclosed GPT-5.6 attack and its July 17 draft date, the McEliece structural key-recovery records, the calls for machine-checkable evidence and community standards for adjudicating AI-generated cryptanalytic claims, the observation regarding HAWK-1024 sizes relative to ML-DSA-44, and the HAWK team’s withdrawal notice. groups.google.com/a/list.nist.gov/g/pqc-forum
[2] Anthropic, “Discovering cryptographic weaknesses with Claude,” Frontier Red Team, July 28, 2026. Source for the discovery process, the approximately 60 hours and roughly $100,000 in API cost, the nontrivial lattice automorphism, the statement that neither result affects production systems, and the accompanying reduced-round AES-128 result. anthropic.com/research/discovering-cryptographic-weaknesses
[3] QScout is delivered through governed assessment lanes, QScout Surface, Silver, and Gold, with QScout Pulse for recurring reassessment. No self-serve public scan runs from the website. The public page captures authorization context and routes the request to Qtonic Quantum Corp, and an analyst confirms the requester and scope before assessment work is fulfilled. Outputs include an approved-scope exposure inventory, evidence thresholds and confidence labels, control and compliance mapping, a remediation path by ownership lane, and CBOM and governed artifacts where approved. QSolve produces migration sequence, owner routing, solution-class decisions, and exception handling. Qtonic Quantum Lab is a separate public evidence registry and not a fourth engagement product. Sources: qtonicquantum.com/qscout and qtonicquantum.com/platform, accessed July 30, 2026.
[4] QStrike applies provider-aligned modeled profiles across six provider configurations spanning four modalities, superconducting, trapped-ion, neutral-atom, and annealing, with zero quantum hardware connected and no live-hardware execution. Published-benchmark calibration inputs are reference inputs only and do not run customer workloads. QStrike keeps modeled, observed, and unproven results distinct, and makes no claim that present-day hardware breaks production cryptography such as RSA-2048 or ECC-256. Sources: qtonicquantum.com/qstrike and qtonicquantum.com/platform, accessed July 30, 2026.
Request a scoped QScout cryptographic exposure assessment. An analyst confirms authorization and scope before anything runs. qtonicquantum.com/request-qscout-assessment











