- The result that surprised the crypto community
- What is HAWK and why is it relevant for post-quantum security
- How Claude Mythos tackled the problem
- Immediate impact for Italian companies: no panic, but strategic watchfulness needed
- The race between defense and attack: a shifting balance
- What no one is saying openly yet
- What to do now: three operational priorities
- Outlook: AI as a tool for digital security auditing
Claude Mythos Preview, Anthropic's advanced model, has identified vulnerabilities in cryptographic algorithms considered secure. Specifically, it found an improved attack on HAWK, a post-quantum signature scheme. Human experts had analyzed HAWK for over two years without similar results. The model took only 60 hours, with an API cost of around $100,000.
However, the vulnerabilities discovered do not compromise cryptographic systems currently in use. Therefore, this is not an immediate operational emergency. Despite this, the result shows that AI models can challenge fundamental assumptions about internet security. This opens new scenarios for cybersecurity research, but also for potential malicious actors with high computational resources.
At SHM Studio, we closely monitor these developments. In fact, the implications for Italian companies managing digital infrastructure, e-commerce, or sensitive data are very real. Therefore, understanding the trajectory of AI applied to security is a top strategic priority today for marketing and digital leaders in SMBs and mid-market companies.
The result that surprised the crypto community
On July 28, 2026, Anthropic announced an unexpected result. Its Claude Mythos Preview model identified vulnerabilities in key cryptographic algorithms. Among these, it found an improved attack on HAWK , a post-quantum signature scheme.
HAWK had been reviewed by human experts for over two years. No one had identified that weakness. Claude Mythos found it in 60 hours , with an API cost of about $100,000.
According to reports by The Decoder , Anthropic stated that the results do not impact cryptographic systems currently in production. However, the strategic implication is significant: AI can challenge the foundations of digital security.
What is HAWK and why is it relevant for post-quantum security
HAWK is a digital signature scheme designed to resist attacks from quantum computers. It is part of the post-quantum standardization process initiated by NIST in the United States. Therefore, its strength has global implications.
Post-quantum cryptography is a rapidly evolving field. In fact, as quantum computers advance, classical algorithms like RSA and ECC will become vulnerable. Consequently, the international community has been working for years to define new standards.
The fact that an AI model found a weakness in HAWK in such a short time is, therefore, a sign that human review might not be enough. Similarly, other post-quantum algorithms could contain flaws not yet identified.
To dive deeper into the technical context, please refer to the official documentation of the NIST Post-Quantum Cryptography Program .
How Claude Mythos tackled the problem
Claude Mythos Preview is Anthropic's frontier model, built for heavy-duty, extended reasoning. In this case, it ran autonomously on an advanced math problem.
The cost of 100,000 dollars in API calls might seem high. However, it needs to be put into perspective: two years of work by specialized human experts costs a lot more. Plus, the model delivered a result those experts hadn't achieved.
This scheme — AI as an accelerator for security research — is bound to happen again. Therefore, organizations managing critical infrastructure must start considering AI not just as a productive tool, but as a variable in their risk model.
According to Gartner , by 2027 over 40% of critical vulnerabilities will be spotted or exploited with the help of AI models. So, the window to catch up is shrinking fast.
Immediate impact for Italian companies: no panic, but strategic watchfulness needed
First of all, it is necessary to clarify: the vulnerabilities found by Claude Mythos do not compromise the systems in use today. This is not an operational emergency for Italian SMEs or mid-market companies.
Nevertheless, the signal is loud and clear. Companies that rely on digital infrastructure—e-commerce, B2B platforms, payment systems—need to start planning their transition to post-quantum cryptographic standards. This goes especially for those handling sensitive data with long retention horizons.
Also, marketing and digital leaders need to understand that security is no longer just an IT issue. It impacts customer trust, regulatory compliance, and brand reputation. Therefore, it becomes part of the overall digital strategy.
In this context, the services of AI consulting di SHM Studio also include assessing the strategic implications of emerging technologies for our clients' business.
The race between defense and attack: a shifting balance
Anthropic's discovery raises a fundamental question: if AI models can find vulnerabilities, can they also exploit them? The answer, at least in theory, is yes.
However, there are important differences between finding a mathematical vulnerability and building a working exploit. Furthermore, models like Claude Mythos are designed with explicit ethical constraints. Anthropic published the results responsibly, following practices of responsible disclosure .
On the flip side, malicious actors with access to less restricted models could use similar capabilities offensively. For this reason, the security community is speeding up the development of AI-assisted defenses. It is a dynamic that reminds us of the history of antivirus software: the race between offense and defense never stops.
The strategies of Digital marketing and online presence of businesses must take this scenario into account. In particular, those who manage campaigns on first-party data or platforms with advanced authentication.
What no one is saying openly yet
There is an aspect that the technical narrative tends to underestimate. The real change is not that AI found a vulnerability. The real change is the speed and the cost with which it was done.
60 hours versus two years. 100,000 dollars versus millions in researcher salaries. This cost-effectiveness completely transforms who can afford to do offensive security research. So, it lowers the barrier to entry for actors who previously didn't have the resources to compete.
Plus, this same principle applies to other domains. An AI model's ability to analyze complex systems on the cheap is going to shake up competition in lots of industries. Not just in cryptography.
For marketing managers planning investments in web infrastructure , SEO and google ads campaigns , understanding this trajectory is part of strategic planning. It's not sci-fi: it's the competitive context of 2026.
What to do now: three operational priorities
For digital and marketing managers of Italian companies, we suggest three concrete actions in the short term.
- Map cryptographic dependencies. Identify which corporate systems depend on algorithms that are potentially at risk in the medium term. This includes e-commerce platforms, CRMs, and authentication systems.
- Start a dialogue with IT vendors. Ask your tech partners what roadmap they have for the post-quantum transition. Anyone without a clear answer is a risk.
- Monitor regulatory developments. The European Commission is working on guidelines for post-quantum cryptography as part of the Cyber Resilience Act . Therefore, companies operating in the EU market must stay updated.
At SHM Studio, we help clients understand the strategic implications of AI. Our services of AI consulting and of Digital marketing always start with an analysis of the technological and competitive context. Therefore, we invite interested leaders to contact us for comparison.
Outlook: AI as a tool for digital security auditing
Looking ahead to 2027-2028, it's pretty safe to expect models like Claude Mythos to be baked into crypto auditing processes. Kind of like what's already happening with penetration testing automated.
This is going to have some awesome perks: security research is about to get faster and cheaper. Plus, smaller organizations will finally get access to a level of analysis that used to be reserved for the big players.
However, the same democratization applies to the offensive side. Therefore, the regulatory framework and practices of responsible disclosure will become even more critical. AI governance applied to security will be one of the central themes of the tech debate in the coming years.
To stay updated on AI and digital marketing developments, you can follow the SHM Studio blog . Finally, for those managing B2B campaigns, the implications also extend to the LinkedIn strategy and to the production of SEO content who speak with authority on these topics.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.