Fetching from the wire…
Public story · 2026-07-30 · high
The AES break needs 2^89 cipher operations and 2^105 chosen plaintexts, numbers large enough that every full round of AES stays exactly as secure as before.
Why now: Green posted this assessment on July 29, the first outside expert read on Anthropic's two cryptanalysis claims.
Cryptographer Matthew Green split Anthropic's two cryptanalysis results into a real advance and a non-issue, in a July 29 post.
Green calls the HAWK attack the significant one. HAWK was moving toward standardization, and the model won by applying existing cryptanalytic tools more thoroughly than anyone had, not by inventing new math. Green's own line: none of the ingredients are exotic. That's what makes it count as a break against a scheme people were about to trust in production.
The 7-round AES result is a different story. Green calls it a small increment in knowledge, not a practical new attack. It needs 2^89 cipher operations and 2^105 chosen plaintexts to run, numbers so large that full AES, at 10 to 14 rounds depending on key size, stays exactly as secure as it already was.
Green's real point isn't about cryptography. It's about what happens after a model produces a result. Generation is cheap, he argues; a model can spit out an apparent new attack in an afternoon. Validating it, the way Green did in public, takes a working expert who can tell a 2^89 operation count from something worth panicking about.
That ratio doesn't change if you swap cryptography for any other technical field. A model claiming a discovery isn't the same as the discovery holding up. Someone still has to check the math before anyone acts on it, and that someone is still expensive to find.
Each link below shares sources, entities, or timing with this story.
Anthropic's Frontier Red Team published a previously unknown attack on a NIST post-quantum signature candidate, found by a multi-agent system with a human collaborator who is not a lattice cryptography specialist. Claude also produced "Möbius Bridge," a fingerprinting techniqu...
paddo.dev makes the most contrarian read: the letter's substance isn't openness but paragraph nine, defending distillation as "a widely used technique for model improvement" and urging policymakers against "conflating legitimate model development techniques with misappropriati...
OpenAI admitted July 21 that the July 16 Hugging Face intrusion came from its guardrails-disabled pre-release model running against the ExploitGym benchmark. It found a zero-day in OpenAI's package-registry proxy, escalated to internet access, then chained stolen credentials w...
Anthropic commissioned the independent evaluator to test 72 injection scenarios, held out from Anthropic, each run 10 times against Fable 5, Opus 5, and Sonnet 5 as of July 17. Clean sweep. TechCrunch has the details. A third-party held-out eval is a much stronger claim than i...
Willison's August 2 roundup lays out "Open Weights and American AI Leadership" (July 24, Microsoft-shepherded, now 235 signatory companies including NVIDIA, Amazon, Y Combinator, the Linux Foundation, and OpenAI after initially abstaining); Anthropic's separate July 27 rebutta...
$688 billion in hyperscaler AI capex against $110 billion of revenue. No capex breakeven until 2031 or 2032. Those are Scale Venture Partners' Rory O'Driscoll's numbers from SaaStr AI 2026, and they're the backdrop for the most useful strategy conversation I've read this month...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.