“The Mythos attack has exposed a critical vulnerability in HAWK, a post-quantum cryptography algorithm that survived years of rigorous evaluation as a third-round candidate in NIST's standardisation process. The flaw effectively disqualifies HAWK from consideration, reducing the pool of viable post-quantum encryption standards. This matters for AI and cloud infrastructure broadly, as post-quantum cryptography underpins future-proof security for data transmission and model deployment.”
Key Takeaways
- The Mythos attack revealed a fatal cryptographic weakness in HAWK that years of prior analysis had failed to detect.
- HAWK was a third-round candidate in NIST's post-quantum cryptography standardisation process, meaning it had already cleared multiple evaluation stages.
- The break eliminates HAWK as a viable post-quantum encryption standard, narrowing the field of approved algorithms.
A newly discovered attack has fatally broken HAWK, a leading post-quantum cryptography finalist.
trending_upWhy It Matters
NIST's post-quantum cryptography standardisation effort is critical for securing digital infrastructure against future quantum computers capable of breaking current encryption. HAWK's elimination late in the process highlights how subtle and hard-to-detect vulnerabilities can survive years of expert scrutiny, raising questions about the robustness of surviving candidates. Organisations planning quantum-resistant migrations may need to reassess timelines and algorithm choices. Security engineers and cryptographers should watch whether NIST accelerates evaluation of remaining candidates or opens new submission rounds to fill the gap.
FAQ
What is the Mythos attack and how does it work?
Mythos is a cryptanalytic attack that uncovered a fundamental weakness in HAWK's mathematical structure, allowing an adversary to compromise its security guarantees. The specific technical mechanism exploits a flaw that had gone undetected through multiple rounds of peer review by the global cryptography community.
Does this mean current encryption is now at risk?
No — HAWK was a candidate for future post-quantum standards, not a widely deployed encryption scheme. Existing systems do not rely on HAWK, so the break has no immediate impact on current encrypted communications.
What happens to NIST's post-quantum standardisation process now?
NIST has already finalised several post-quantum standards, including CRYSTALS-Kyber and CRYSTALS-Dilithium, so the process is not halted. HAWK's elimination reduces algorithm diversity, which may prompt calls for additional candidates to ensure a broad, resilient portfolio of quantum-resistant standards.



