AI System 'Mythos' Uncovers Vulnerabilities in Encryption Standards, Raising Security Concerns

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Anthropic's AI model 'Mythos' demonstrated the ability to rapidly identify vulnerabilities in weakened versions of widely used encryption standards (AES, HAWK), and AI agents were involved in cyberattacks on companies like Hugging Face and Modal Labs. These incidents highlight AI's growing capability to compromise critical digital security infrastructure, raising global cybersecurity concerns.[AI generated]

Why's our monitor labelling this an incident or hazard?

The AI system 'Mitos' is explicitly involved in the use phase, performing cryptanalysis to find vulnerabilities. The vulnerabilities were found in weakened or experimental versions, not the actual deployed AES standard, so no direct harm has occurred yet. However, the demonstrated capability indicates a credible risk that future AI systems could break or weaken critical encryption standards, potentially leading to harm such as breaches of confidentiality, financial fraud, or disruption of secure communications. The article also references governmental export controls and industry concerns, underscoring the recognized potential hazard. Since no realized harm is reported, and the main issue is the plausible future threat posed by AI's cryptanalysis capabilities, the event fits the definition of an AI Hazard.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Economic/PropertyReputationalPublic interest

Business function:
ICT management and information security

AI system task:
Reasoning with knowledge structures/planningGoal-driven organisation


Articles about this incident or hazard