Loading market data...

Claude AI Discovers Attack on Post-Quantum Signature Scheme Under Federal Review

Claude AI Discovers Attack on Post-Quantum Signature Scheme Under Federal Review

Anthropic's AI model Claude has uncovered a new attack on a post-quantum signature scheme that was being considered for U.S. federal standardization. The discovery, made during internal testing, targets a candidate algorithm in the National Institute of Standards and Technology's ongoing effort to develop cryptography resistant to quantum computers.

The discovery

Claude, the large language model developed by Anthropic, identified the vulnerability while analyzing the mathematical structure of the scheme. The attack exploits a weakness in the algorithm's design that could allow an adversary to forge signatures or recover private keys. The company has not yet released technical details, but the finding has been shared with the relevant standards body.

This is not the first time an AI has been used to probe cryptographic systems, but it is one of the few instances where a model discovered a novel attack on a scheme under active consideration for government use. The attack was found without human guidance, highlighting the growing role of machine learning in cryptanalysis.

The scheme in question

The targeted signature scheme is one of several post-quantum algorithms being evaluated by NIST for future federal standards. These schemes are designed to replace current public-key cryptography, which will be vulnerable to large-scale quantum computers. The specific algorithm's name has not been disclosed by Anthropic, but it is understood to be a candidate in the third round of NIST's post-quantum cryptography standardization process.

Post-quantum signature schemes are critical for ensuring the authenticity and integrity of digital communications in a quantum era. A successful attack on any candidate raises concerns about the robustness of the entire standardization pipeline.

The discovery could delay or alter the selection of the affected scheme. NIST has been working for years to finalize a set of post-quantum algorithms, with a deadline for the first standards expected in 2024. The impact of this new attack on that timeline is not yet known. The standards body has not commented on the finding.

Anthropic's role in the discovery also raises questions about how AI models should be integrated into security research. The company has not said whether it will publish the attack details or work with the scheme's developers to patch the vulnerability.

Researchers in the cryptographic community will likely scrutinize the attack once details emerge. The scheme's designers may need to revise their algorithm or provide a countermeasure. For now, the discovery serves as a reminder that even algorithms vetted by experts can harbor hidden flaws — and that AI can find them faster than humans alone.

The full technical report from Anthropic is expected in the coming weeks. Until then, the cryptographic community waits to see whether this attack is a one-off or a sign of more to come.