BTC $64,699.37 +0.45%
ETH $1,917.55 +0.78%
BNB $586.72 +3.07%
XRP $1.08 +1.01%
SOL $74.41 +1.22%
TRX $0.3278 +0.49%
DOGE $0.0703 -0.26%
ADA $0.1681 +2.48%
BCH $219.07 +4.05%
LINK $8.48 +1.82%
HYPE $53.63 -2.81%
AAVE $99.46 +0.78%
SUI $0.6959 +1.26%
XLM $0.1727 -0.39%
ZEC $474.12 +1.82%
BTC $64,699.37 +0.45%
ETH $1,917.55 +0.78%
BNB $586.72 +3.07%
XRP $1.08 +1.01%
SOL $74.41 +1.22%
TRX $0.3278 +0.49%
DOGE $0.0703 -0.26%
ADA $0.1681 +2.48%
BCH $219.07 +4.05%
LINK $8.48 +1.82%
HYPE $53.63 -2.81%
AAVE $99.46 +0.78%
SUI $0.6959 +1.26%
XLM $0.1727 -0.39%
ZEC $474.12 +1.82%

discove

All
Article
Flash

Claude discovered vulnerabilities in the encryption algorithm, posing a theoretical threat to post-quantum security

Anthropic announced that the Claude Mythos Preview model has made breakthroughs in cryptographic research, discovering improved attack methods against the post-quantum digital signature candidate HAWK. HAWK is a post-quantum signature candidate solicited by NIST to combat quantum computer attacks, which has already passed two rounds of expert review. However, Claude reduced the effective key strength of HAWK-256 from 2^64 to 2^38 in just 60 hours, significantly lowering the theoretical cost of cracking. HAWK has not yet been deployed in practice, and this attack currently does not affect any production systems.Claude also discovered an improved attack against 7-round AES, achieving a speed increase of 200 to 800 times. During the research process, Claude independently completed literature reviews, mathematical reasoning, and experimental validation with limited guidance from cryptographers. The HAWK attack took about 60 hours and had an API cost of approximately $100,000; the AES attack was completed independently by Claude, which generated about 1 billion tokens before proposing core innovative ideas. Anthropic researchers then spent hundreds of hours validating the results. Anthropic stated that AI models can now help identify significant flaws in cryptographic algorithms, and the cryptography community may face bottlenecks similar to those in the software vulnerability field—AI-generated research results far exceed human verification capabilities. Anthropic has collaborated with academic institutions to launch the CryptanalysisBench benchmark and coordinated disclosures with NIST authors and government partners. The research team has achieved preliminary results on algorithms such as LEA and Serpent-128. Anthropic warns that as AI capabilities improve, actual attacks against deployed systems may be discovered in the future, necessitating the establishment of response mechanisms in advance.

The Ledger security team discovered an Android vulnerability that can extract cryptocurrency wallet recovery phrases in 45 seconds

According to The Block, Ledger's security research team Donjon has discovered a vulnerability in the secure boot chain of MediaTek processors, allowing attackers to extract encryption keys via USB connection before the operating system loads, provided they have physical access to the phone. This could enable them to decrypt device storage and obtain the device PIN code and encrypted wallet mnemonic within approximately 45 seconds.In proof-of-concept tests, the vulnerability successfully extracted sensitive data from wallet applications such as Trust Wallet, Kraken Wallet, and Phantom. Researchers indicate that this vulnerability may affect about 25% of Android phones, involving models that use MediaTek chips and Trustonic's Trusted Execution Environment. Ledger's Chief Technology Officer Charles Guillemet stated that smartphones were never designed to be vaults. Although the vulnerability can be patched, it highlights the inherent risks of storing keys on non-secure devices, and users are advised to update security patches as soon as possible.According to data from TRM Labs, over 80% of the $2.1 billion in stolen crypto assets in the first half of 2025 stemmed from infrastructure attacks such as private key theft, mnemonic theft, and front-end hijacking. Chainalysis data shows that losses from crypto asset theft exceeded $3.41 billion in 2024, with the proportion of stolen personal wallets rising from 7.3% in 2022 to 44% in 2024.
app_icon
ChainCatcher Building the Web3 world with innovations.