NoFuckery AI logo

NF-021 / evidence brief / published 2026-07-29

NoFuckery AI

Verdict

CLAUDE FOUND THE FLAW. HAWK LEFT NIST.

Claude-assisted cryptanalysis produced a consequential HAWK attack that the scheme's designers confirmed before withdrawing the undeployed candidate. It did not break production AES.

Accountable editor: Chris McNosky · Evidence rechecked: 2026-07-29 · Published: 2026-07-29

Primary sources linked Limits explicit Published

The record

StatusClaimReceipt
source reportedHAWK's designers confirmed the attack and withdrew HAWK. NIST records the candidate as withdrawn.HAWK team · NIST
source reportedUnder the paper's gate-count model, estimated HAWK-512 key-recovery cost fell from 2150 to at most 2108; HAWK-1024 fell from 2288 to at most 2182. Both remain impractical.HAWK attack paper
source reportedThe released implementation recovered an equivalent signing key only for HAWK-256, an intentionally small challenge parameter below NIST's submission threshold.Demonstration repository
source reportedAnthropic attributes about 60 hours and approximately $100,000 in API cost to finding, developing, and verifying the HAWK result.Anthropic disclosure
inferenceModel output is a candidate claim. Reproducible evidence, expert review, and responsible disclosure determine whether it earns trust.NoFuckery method

The workflow matters

Anthropic describes a semi-autonomous, multi-agent process using literature, tools, computational experiments, scaffolding, occasional human direction, and later expert review. The time and cost are Anthropic's estimates, not independent measurements.

HAWK's designers publicly confirmed the central weakness. Their response and NIST's status record are separate from Anthropic's institutional account, but the paper, disclosure, and executable demonstration share one Anthropic research lineage.

The separate AES result

Claude-assisted research also improved an impractical attack on seven-round AES-128 by roughly 200–800 times. Full AES-128 has ten rounds and remains unaffected.

The reduced-round attack assumes 2105 chosen plaintexts and could not be executed end to end at full scale. Anthropic reports that the model produced the main idea in roughly a week, while two researchers then spent several hundred hours and nearly a month gaining confidence in it. That supports a validation-bottleneck concern. It does not turn the result into a break of production AES.

Strongest countercase

The HAWK attack remains exponential, standard-sized parameters remain impractical to attack, and HAWK was never deployed. The withdrawal also shows the public standardization process doing its job: finding a consequential weakness before adoption.

What this does not prove

Where Stinger is relevant—and where it is not

Stinger did not evaluate the mathematics. Its relevance is procedural: treat a model's answer as a candidate claim and require inspectable evidence before allowing that claim to authorize a score, release, or decision.

Conflict disclosure: Chris McNosky built Stinger. Its use here is a disclosed methodological analogy, not evidence that Stinger evaluated or validated the cryptanalysis.

Operator decision

Keep AI-generated research claims at candidate/HOLD until reproducible evidence, expert review, and responsible disclosure support them.

Primary sources and exact limits

SourceWhat it supportsLimit
Anthropic disclosureWorkflow, time, cost, human role, HAWK scope, reduced-round AES scope, and validation burden.First-party research account; broad capability conclusions are Anthropic's interpretation.
NIST Round 3 statusHAWK is recorded as withdrawn.NIST did not reject HAWK or independently publish the attack analysis.
HAWK-team statementConfirmation, consequence, and withdrawal.Statement from the scheme's own submission team, not an independent implementation report.
HAWK attack paperAttack construction and exact gate-count estimates.Author paper; standard-sized attacks are modeled and remain impractical.
HAWK demonstrationExecutable HAWK-256 equivalent-key recovery and reference verification.Challenge parameter only; not a HAWK-512 or HAWK-1024 recovery.
Reduced-round AES paperSeven-round attack, 2105 chosen-plaintext assumption, and modeled improvement.Full-scale attack is impractical and was not run end to end; full AES-128 is unaffected.

Source access date: 2026-07-29. Every mutable source must be rechecked within 24 hours of any approved publication.