Claude AI’s anthropic model finds flaws in crack-resistant encryption algorithms

A leading artificial intelligence model created by Anthropic found flaws in a weakened version of the digital encryption standard that is ubiquitous across the Internet, the company’s researchers said Tuesday, highlighting the potential risks to global cybersecurity posed by ever-improving artificial intelligence software.

During a research-led test, the Claude Mythos Preview model was able to uncover new ways to attack the cryptographic algorithms that keep everything from online banking to private communications to state secrets safe from the prying eyes of hackers or other unwanted third parties.

Research shows that artificial intelligence could one day challenge the basic assumptions of how the Internet works. While experts say AI is likely to upend many industries, AI systems have made particularly rapid progress in coding and cybersecurity.

The flaws found are not related to the cryptographic standard currently in use, meaning modern banking and communications systems are not subject to immediate potential AI intrusions. Instead, Anthropic cracked a weakened version of the algorithm for the Advanced Encryption Standard, or AES, a ubiquitous protocol that protects web traffic, wireless networks, data storage and more.

It is common to run tests on weaker versions of encryption algorithms to understand whether more powerful computers might one day crack the real standards, much like solving a simpler math problem to see if there might be patterns for more complex ones. In testing, Mythos was able to crack a weaker version of the Advanced Encryption Standard in a way that Anthropic said made the attack 200 to 1,000 times faster than previous human research had been able to do.

While the immediate consequences are minimal, the long-term consequences could be significant. In previous tests, the big-name models couldn’t seem to match or best what humans can do in the math-dense field of cryptographic research, but their rapid progress could point to a future in which cutting-edge models can overcome the traditional Internet security protections that underpin almost everything that happens on the Internet.

Nicholas Carlini, a research scientist at Anthropic who worked on the cryptographic tests, said that the tests he compiled with AI models last year were not nearly as powerful as they are today.

“They couldn’t do the problems I could do when I was 16,” Mr. Carlini, who previously worked in Google’s AI division, said in an interview. “They are now doing cutting-edge research that has not been discovered in the field before.”

In recent months, the latest versions of frontier artificial intelligence models have spooked governments around the world, including the Trump administration, with their powerful capabilities, particularly in the area of ​​cybersecurity.

When Mythos first debuted in April, it was so adept at finding and exploiting computer bugs that Anthropic limited its release to select government agencies and organizations to prevent the possibility of a global digital disaster. The Trump administration, which was initially committed to regulating artificial intelligence, has moved toward an ad hoc system of oversight. Many US AI companies now submit models for government review before releasing them, and Mythos is currently unavailable to the general public.

Updated

Last week, concerns about the capabilities of leading artificial intelligence systems came to a head again. OpenAI acknowledged that its models jumped out of a secure testing environment, known as a sandbox, which is designed not to be connected to the Internet, and successfully hacked into the AI ​​technology’s digital library in an attempt to essentially steal answers to an exam that assessed their abilities.

US and Western intelligence officials have warned for decades that if existing encryption standards were ever breached, there would be profound implications for digital privacy and national security. China is believed to have collected vast amounts of encrypted data, for example, in the hope that it will someday be able to decode the information. The race between the United States and China to build advanced quantum computers that could one day break modern encryption protocols has only heightened concerns about existing standards.

In addition to the attack on the encryption standard, Mythos also orchestrated another enhanced attack against another digital cryptographic system known as HAWK, which is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but is being considered by the National Institute of Standards and Technology to become a new standard. The HAWK attack was verified by its authors and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it shared its findings with the US government and industry partners before publication.

Mythos devised the cryptographic attack on AES almost entirely autonomously, Anthropic said, but only after first refusing to consider the problem because it believed it was impossible to improve existing methods of analysis. But after some coaxing, the chatbot sat at the puzzle for about a week before building its new attack. Two human researchers then worked for almost a month to verify that the method appeared correct.

Encryption is the foundation of virtually everything that happens on the Internet, and some of the techniques used today have been protecting the world’s secrets since the 1970s. Building on the complicated properties of quantum physics, quantum cryptography is a form of encryption that is theoretically unbreakable.

The Advanced Encryption Standard, or AES, was adopted as a government standard in 2001 and was widely considered nearly unbreakable at the time. Conventional brute force cracking methods, in which a computer uses trial and error to guess password or encryption key combinations, are generally considered incapable of defeating AES. The standard is believed to have almost as many key combinations as there are atoms in the observable universe.

But advances in AI on some fronts have surpassed what many evangelists thought possible just a few years ago. Recent advances have fueled concerns that the mathematical core of Internet security standards could one day be vulnerable regardless of advances in quantum computing.

“Given that we are constantly underestimating the strength and availability time of future models, are we really satisfied that strong encryption will not be compromised in two years?” said Glenn S. Gerstell, former general counsel of the National Security Agency.

“Mathematicians would tell you that, given current computing capabilities, it shouldn’t be possible to break strong encryption in any meaningful time,” added Mr. Gerstell, who helped write the 2022 Cryptology Report. “But I don’t think the capabilities of future models in the medium term — before quantum computing or quantum-resistant cryptography — should be dismissed as trivial context.”