克劳德·米索斯破解了一个后量子算法

Claude Mythos met à mal un algorithme post-quantique

Silicon.fr by Clément Bohic 2026-07-30 08:31 Original
摘要
HAWK算法因发现格自同构对称性导致密钥有效长度减半的数学缺陷,已退出美国NIST后量子标准化竞赛。该攻击由Anthropic的Claude Mythos模型主导开发,非密码学专家协调,仅60小时和10万美元API成本即实现端到端私钥恢复,Anthropic已发布可4小时内破解HAWK-256的参考实现。此漏洞使算法若靠加长密钥补偿则竞争力大幅下降,影响其商业化前景。

HAWK签名算法已退出美国NIST后量子密码标准化竞赛。该算法的开发团队主动撤回了申请,原因是被发现存在一个数学弱点,使得密钥的“有效长度”几乎减半。这一漏洞利用了格密码中一种称为自同构的对称性,可大幅加速密钥枚举攻击。

这场攻击的实现来自Anthropic的人工智能模型Claude Mythos。在一名资深计算机理论研究员(非密码学专家)的“项目管理”指导下,模型仅用约60小时、花费10万美元API成本,便开发出了一套端到端的攻击方案。该研究员的任务包括引导模型记录思路、选择适当的软件库等。

Anthropic已公开了此次攻击的参考实现,通过单一命令和检查点,在96核英特尔至强Sapphire Rapids服务器上,不到4小时即可恢复HAWK-256的完整私钥。若采用朴素对策,将密钥长度延长一倍,虽能暂时弥补该缺陷,却会严重削弱算法的性能竞争力。目前的HAWK-512方案在标准台式机上的签名生成与验证时间应低于0.1毫秒,内存优化实现仅占用14 KiB内存。此次暴露的数学缺陷,为HAWK的标准化之路蒙上了阴影。

Summary
The HAWK post-quantum signature algorithm was withdrawn from the NIST standardization process after a mathematical weakness exploiting lattice automorphism was found, effectively halving key strength. Anthropic's Claude Mythos AI, with project management from a non-cryptographer researcher, crafted an end-to-end attack costing $100,000 and 60 hours of API time, capable of recovering a HAWK-256 key in under four hours on a high-core server. This breach undermines HAWK's competitiveness, as simply doubling key lengths to compensate would degrade its speed and memory advantages.

HAWK has been withdrawn from NIST’s post-quantum cryptography competition after researchers unearthed a mathematical flaw that nearly halves the effective security of its keys. The vulnerability hinges on an automorphism symmetry in the underlying lattice structure, which enables significantly faster enumeration attacks.

The attack was developed with the help of Claude Mythos, Anthropic’s AI model, at a cost of about $100,000 in API usage and 60 hours of compute. A researcher well-versed in theoretical computer science—but not a cryptographer—orchestrated the effort, guiding the model on how to structure its work, track ideas, and select appropriate software libraries.

Anthropic has released a reference implementation that can recover a HAWK-256 private key in less than four hours on a 96-core Intel Sapphire Rapids server, using a single command and checkpoints. Naïvely doubling key lengths could compensate for the weakness, but would render the scheme much less competitive. As it stood, HAWK-512 signature generation and verification were designed to take under 0.1 ms on a standard desktop PC, with a memory-optimized implementation consuming just 14 KiB of RAM. The discovery and subsequent withdrawal underscore the persistent challenge of designing lattice-based cryptography that is both efficient and secure against novel algebraic exploits.

Résumé
L'algorithme de signature post-quantique HAWK a été retiré de la compétition de standardisation du NIST après la découverte d'une faille mathématique réduisant de moitié la sécurité effective des clés. Cette vulnérabilité a été exploitée par le modèle Claude Mythos d'Anthropic, avec une implémentation capable de casser une clé HAWK-256 en moins de quatre heures, compromettant la compétitivité du candidat, car doubler la longueur des clés pour compenser le rendrait trop lent.

HAWK n’est plus candidat à la standardisation NIST.

L’équipe à l’origine de cet algorithme de signature vient de le retirer de la compétition. En toile de fond, la découverte d’une faiblesse mathématique qui diminue de près de moitié la « taille effective » des clés. Elle exploite une symétrie – dite automorphisme – dans le réseau de treillis, permettant une énumération plus rapide.

Il aura fallu à Claude Mythos environ 60 heures – et 100 000 $ de coûts d’API – pour développer une attaque de bout en bout. Un chercheur expérimenté en théorie informatique – mais pas spécialiste de la cryptographie – a orchestré la « gestion de projet ». Par exemple, expliquer au modèle comment garder trace de ses idées ou quelles bibliothèques utiliser.

Anthropic livre une implémentation de référence, avec une commande unique et des checkpoints. Elle permet de récupérer une clé HAWK-256 en un peu moins de 4 heures sur un serveurs à 96 cœurs Sapphire Rapids.

Une méthode « naïve » consisterait à utiliser des clés deux fois plus longues pour compenser cette vulnérabilité. Elle rendrait toutefois l’algo bien moins compétitif. En l’état, la génération et la vérification de signatures HAWK-512 sont censées prendre moins de 0,1 ms sur un PC de bureau standard. L’implémentation optimisée mémoire consomme 14 kiB de RAM.

À consulter en complément :

Quelques solutions françaises pour amorcer la transition post-quantique

En froid, GPG et OpenPGP avancent séparément sur la cryptographie post-quantique

Comment Anthropic est passé de Claude Mythos à Claude Fable

Illustration principale © Siarhei – Adobe Stock

The post Claude Mythos met à mal un algorithme post-quantique appeared first on Silicon.fr.

AI Insight
Core Point

AI模型Claude Mythos发现后量子签名算法HAWK的数学弱点,致其被从NIST标准化进程中撤回,影响后量子密码安全选型。

Key Players
  • Anthropic — 美国AI研究公司,开发了Claude Mythos模型,并提供了攻击实现。
Industry Impact
  • ICT: 高 — 直接威胁后量子密码标准化,可能延迟安全过渡。
Tracking

Strongly track — AI辅助密码分析能力突显,将加速后量子算法筛选与淘汰。

Highlights
Tech Breakthrough
Related Companies
neutral
Anthropic
startup
positive
Adobe
mature
neutral
Categories
人工智能 网络安全
AI Processing
2026-07-30 13:29
deepseek / deepseek-v4-pro