
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Anthropic's AI models, including Claude and Claude Mythos, have discovered previously unknown weaknesses in cryptographic algorithms, including post-quantum candidates and reduced versions of AES. While no production systems were compromised, these findings highlight AI's growing capability in cryptanalysis and the potential for future security risks if exploited.[AI generated]
Why's our monitor labelling this an incident or hazard?
The AI system Claude was used to analyze and find weaknesses in cryptographic algorithms, which is a direct use of AI in the development and testing of security systems. Although no current harm has occurred (no blockchain or wallet was broken), the AI's findings reduce the security margin of a quantum-resistant scheme, indicating a credible risk that future quantum computers combined with AI could break Bitcoin's cryptography. This fits the definition of an AI Hazard because it plausibly leads to an AI Incident in the future if such quantum computers and attacks materialize. The event does not describe realized harm, so it is not an AI Incident. It is not Complementary Information because the main focus is the AI's discovery of new vulnerabilities, not a response or update to a past incident. It is not Beneficial Use since the AI is not deployed to counter an external harm but is used to find weaknesses that could cause harm. It is not Unrelated because the AI system's involvement is explicit and central.[AI generated]