Anthropic's Mythos AI Found Hidden Weaknesses in Two Major Encryption Systems
The cracks are small, not catastrophic. But an AI model quietly chipping away at the maths that protects your data is worth understanding.

Key points
- Anthropic's Mythos model identified weaknesses in the mathematical foundations of two encryption algorithms in 2025.
- The findings are incremental: no encryption system in everyday use is broken or immediately at risk.
- The results show reduced "hardness", meaning less computational work would theoretically be needed to crack the affected systems.
- Anthropic has not yet published peer-reviewed results, so independent verification is still outstanding.
An AI model built by Anthropic, the San Francisco company behind the Claude family of chatbots, has found previously unknown weaknesses in the maths underpinning two cryptographic algorithms, the systems that scramble your messages, passwords and financial data to keep them private.
The model is called Mythos. Anthropic describes it as a specialist AI security tool, designed to probe mathematical problems that human researchers might take years to crack, or miss entirely.
What did Mythos actually find?
It found ways to reduce the "hardness" of two algorithms, meaning the theoretical amount of computing work required to break them is somewhat lower than previously assumed. That is a meaningful finding in cryptography research, but it is not a disaster.
To be plain: nothing Mythos uncovered breaks any encryption system that banks, hospitals, governments or ordinary people rely on right now. Your WhatsApp messages, your online banking, your medical records are not newly exposed.
What the findings do is chip away at the margins. Cryptographic security is built on the assumption that certain maths problems are so hard that no computer could solve them in any practical timeframe. Mythos found that two such problems may be slightly less hard than the field believed.
Should anyone be worried?
Not urgently, but not never.
Incremental findings like these are how cryptographic collapses tend to begin. A small reduction in hardness today can combine with tomorrow's faster hardware and next year's smarter model into something more serious. Cryptographers take these signals seriously even when no alarm bells are ringing yet.
There is also a transparency problem worth naming. As first reported by Ars Technica AI, it is genuinely difficult at this stage to separate a significant scientific result from a polished company announcement. Anthropic has not published these findings in a peer-reviewed journal, where independent mathematicians could stress-test the claims. Until that happens, the results carry an asterisk.
What happens next?
The next step that matters is independent review. Cryptographers outside Anthropic need to examine the methods, reproduce the results and say whether the threat is real and how large it is.
For most people, the practical advice is unchanged: use strong, unique passwords; keep software updated; and trust that the security community is watching this closely. If Mythos's findings hold up under scrutiny, the organisations responsible for setting global encryption standards will need to weigh whether any of the affected algorithms should be phased out or reinforced.
AI tools that can probe mathematical weaknesses faster than human researchers are a genuinely new variable in this field. That is worth watching carefully.
Common questions
Does this mean my passwords or messages have been compromised?
No. The weaknesses Mythos found are theoretical reductions in mathematical difficulty, not active exploits. No data protected by current encryption systems is known to be at risk as a result of these findings.
How is an AI able to find flaws in encryption maths?
Encryption relies on problems that are easy to set up but very hard to reverse, like multiplying two huge prime numbers together. AI models can search enormous mathematical spaces for shortcuts or patterns that human researchers might overlook across years of work.
Why does it matter if the findings have not been peer-reviewed?
Peer review means independent experts check whether the method is sound and the result holds up. Without it, there is no way to know whether the finding is a genuine advance or an overstatement. In cryptography especially, the difference matters enormously.



