Anthropic's Claude Mythos Preview model has exposed a vulnerability in the HAWK digital signature scheme, which is being considered as a potential replacement for current online banking and web payment signatures. This flaw effectively reduces the key strength of HAWK by half, raising concerns about its viability in a post-quantum computing environment.
HAWK is still in development but faces increased scrutiny from AI advancements
The AI-driven attack, which took around 60 hours and cost approximately $100,000 in computing resources, decreased the effort required to compromise HAWK's smallest parameter set from around 2^64 operations to just 2^38. This revelation has implications for the attractiveness of larger key sizes intended to compensate for this weakness.
While the current digital signatures used in Bitcoin and Ethereum remain secure against this specific vulnerability, the findings underscore the urgency for these networks to transition to quantum-resistant cryptography. As discussions continue about how and when to make this shift, these results highlight the rapidly evolving nature of cryptographic threats.
Anthropic noted that their Claude Mythos Preview model successfully identified the attack against HAWK, a digital signature candidate that has undergone extensive review without previously being compromised. Digital signatures play a crucial role in confirming the origin of messages and data, and are fundamental to the operation of cryptocurrencies and secure online transactions.
Although HAWK has not been deployed in any public context, it is under consideration as a replacement for current digital signatures, which are expected to be vulnerable to quantum computing attacks. The existing systems secure Bitcoin transactions and are integral to the functionality of secure websites.
Bitcoin Improvement Proposal (BIP) 360 aims to provide Bitcoin with quantum-resistant addresses, relying on three algorithms that have already been standardized by NIST, ensuring users have alternatives if one is compromised in the future. Meanwhile, BIP-361 argues for the urgency of migration due to the rapid advancements in cryptographic attacks, which are reportedly improving by up to 20 times.
Anthropic's findings indicate that the cost associated with recovering a key using HAWK's smallest parameters has been significantly reduced, while larger keys remain impractical to attack. However, increasing key sizes to mitigate this vulnerability diminishes many of HAWK's initial advantages.
The firm disclosed its findings to HAWK's developers in June and synchronized the publication with NIST's mailing list. Additionally, the research improved attacks on a weakened version of AES, the encryption standard used for securing wallet files, by factors ranging from 200 to 800.
Importantly, the Claude model also showed smaller, yet noteworthy improvements against Poseidon, a hash function essential for zero-knowledge proof systems that support various privacy protocols in the crypto space.
Interestingly, these developments align with the recent upgrade of the privacy network Zcash, which implemented a new shielded pool designed to remain functional in the event that quantum computers become operational. The cryptographic schemes being tested now face scrutiny from faster, AI-driven analysis tools, which could outpace their development and implementation.
