Claude Mythos and cryptographic vulnerabilities: what changes
- The result that surprised the cryptographic community
- What is HAWK and why is it relevant to post-quantum security?
- How Claude Mythos addressed the problem
- Immediate Impact for Italian Companies: No Alarm, But Strategic Attention
- The race between defense and offense: a shifting balance
- What no one is saying openly yet
- What to do now: three operational priorities
- Prospects: AI as a Digital Security Audit Tool
Claude Mythos Preview, Anthropic's advanced model, has identified vulnerabilities in cryptographic algorithms considered secure. Specifically, it found an improved attack on HAWK, a post-quantum signature scheme. Human experts had analyzed HAWK for over two years without similar results. The model took only 60 hours, with an API cost of approximately $100,000.
However, the discovered vulnerabilities do not compromise currently used cryptographic systems. Therefore, this is not an immediate operational emergency. Nevertheless, the result demonstrates that AI models can challenge fundamental assumptions about internet security. This opens new scenarios for cybersecurity research, but also for potential malicious actors with high computational resources.
At SHM Studio, we carefully monitor these developments. In fact, the implications for Italian companies managing digital infrastructure, e-commerce, or sensitive data are concrete. Therefore, understanding the trajectory of AI applied to security is today a strategic priority for the marketing and digital managers of SMEs and the mid-market.
The result that surprised the cryptographic community
On July 28, 2026, Anthropic announced an unexpected finding. Its Claude Mythos Preview model identified vulnerabilities in key cryptographic algorithms. Among these, it found an improved attack on HAWK, a post-quantum signature scheme.
HAWK had been reviewed by human experts for over two years. No one had identified that weakness. Claude Mythos found it in 60 hours, with an API cost of approximately $100,000.
According to reports by The Decoder, Anthropic stated that the findings do not affect cryptographic systems currently in production. However, the strategic implication is significant: AI can call into question the very foundations of digital security.
What is HAWK, and why is it relevant to post-quantum security?
HAWK is a digital signature scheme designed to withstand attacks from quantum computers. It is part of the post-quantum standardization process initiated by the National Institute of Standards and Technology in the United States. Therefore, its stability has global implications.
Post-quantum cryptography is a rapidly evolving field. In fact, as quantum computers advance, classical algorithms such as RSA and ECC will become vulnerable. As a result, the international community has been working for years to establish new standards.
The fact that an AI model found a vulnerability in HAWK in such a short time is, therefore, a sign that the human review process may not be sufficient. Similarly, other post-quantum algorithms may contain vulnerabilities that have not yet been identified.
For more information on the technical context, please refer to the official documentation of the NIST Post-Quantum Cryptography Program.
How Claude Mythos addressed the problem
Claude Mythos Preview is Anthropic's cutting-edge model, designed for complex and extended reasoning. In this case, it operated autonomously on an advanced math problem.
The cost of $100,000 in API calls may seem high. However, it needs to be put into context: two years of work by specialized human experts would cost significantly more. Furthermore, the model produced a result that those experts had not achieved.
This diagram — AI as a Catalyst for Security Research — is bound to happen again. Therefore, organizations that manage critical infrastructure must begin to view AI not only as a productive tool, but also as a variable in their risk model.
According to Gartner, By 2027, more than 40% of critical vulnerabilities will be identified or exploited with the help of AI models. Therefore, the window of opportunity to adapt is narrowing.
Immediate Impact for Italian Companies: No Alarm, But Strategic Attention
First of all, it is necessary to clarify: the vulnerabilities found by Claude Mythos do not compromise current systems in use. This is not an operational emergency for Italian SMEs or mid-market companies.
Despite this, the message is clear. Companies that rely on digital infrastructure—e-commerce, B2B platforms, payment systems—must begin planning their transition to post-quantum cryptographic standards. In particular, those that handle sensitive data over long time horizons.
Furthermore, marketing and digital leaders must understand that security is no longer just an IT issue. It affects customer trust, regulatory compliance, and brand reputation. Therefore, it becomes an integral part of the overall digital strategy.
In this context, the services of SHM Studio AI Consulting They also include an assessment of the strategic implications of emerging technologies for clients' businesses.
The race between defense and offense: a shifting balance
Anthropic's discovery raises a fundamental question: If AI models can find vulnerabilities, can they also exploit them? The answer, at least in theory, is yes.
However, there are significant differences between discovering a mathematical vulnerability and building a working exploit. Furthermore, models such as Claude Mythos are designed with explicit ethical constraints. Anthropic published the results responsibly, following best practices in Responsible disclosure.
Conversely, malicious actors with access to less restrictive models could use similar capabilities for offensive purposes. For this reason, the security community is accelerating the development of AI-assisted defenses. It’s a dynamic reminiscent of the history of antivirus software: the race between attack and defense never stops.
Strategies for digital marketing and companies' online presence must take this scenario into account. In particular, those who manage campaigns based on first-party data or platforms with advanced authentication.
What no one is saying openly yet
There is one aspect that technical fiction tends to underestimate. The real change isn't that AI has found a vulnerability. The real change is the speed and the cost the way he did it.
60 hours versus two years. $100,000 versus millions in researcher salaries. This cost-effectiveness ratio radically changes who can afford to conduct offensive security research. As a result, it lowers the barrier to entry for actors who previously lacked the resources to compete.
Furthermore, this same principle applies to other domains. An AI model's ability to analyze complex systems at a low cost will change competition in many sectors. Not just cryptography.
For marketing professionals planning investments in web infrastructure, SEO e Google Ads campaigns, Understanding this trajectory is part of strategic planning. It's not science fiction: it's the competitive landscape of 2026.
What to do now: three operational priorities
For digital and marketing managers at Italian companies, we recommend three concrete short-term actions.
- Mapping cryptographic dependencies. Identify which business systems depend on algorithms that may be at risk in the medium term. This includes e-commerce platforms, CRM systems, and authentication systems.
- Initiate a dialogue with IT vendors. Ask your technology partners what their roadmap is for the post-quantum transition. Any partner that doesn't have a clear answer is a risk.
- Monitor regulatory developments. The European Commission is working on guidelines for post-quantum cryptography within the framework of Cyber Resilience Act. Therefore, companies operating in the EU market must keep themselves updated.
In SHM Studio, we assist clients in understanding the strategic implications of AI. Our services include AI consulting and of digital marketing always start from an analysis of the technological and competitive context. For this reason, we invite the relevant managers to contact us to compare.
Perspectives: AI as a Digital Security Audit Tool
Looking ahead to 2027-2028, it is reasonable to expect that models like Claude Mythos will be integrated into cryptographic audit processes. This would be similar to what is already happening with tools such as penetration testing automated.
This will have positive effects: security research will become faster and cheaper. Additionally, organizations with fewer resources will be able to access levels of analysis previously reserved for major players.
However, the same democratization applies to the offensive side. Therefore, the regulatory framework and practices of Responsible disclosure will become even more critical. AI governance applied to security will be one of the central themes of the technological debate in the coming years.
To stay updated on the evolutions of AI and digital marketing, you can follow the SHM Studio Blog. Finally, for those managing B2B campaigns, the implications also extend to the LinkedIn strategy and to the production of SEO content that they speak authoritatively on these topics.
News Categories
Related articles
Discover other articles that explore similar topics in depth, selected to give you a more complete and stimulating view. Each piece of content is carefully chosen to enrich your experience.