HAWK Lattice Signature Scheme Withdrawn from NIST Round 3 After AI-Assisted Key-Recovery Attack
Key Takeaways
Rapid Withdrawal: The HAWK team withdrew the only remaining lattice-based candidate from NIST’s third-round additional signatures process the morning after the public attack disclosure.
AI Application of Known Tools: Claude Mythos Preview reduced HAWK key-recovery cost by exploiting a lattice automorphism, applying existing techniques more thoroughly than prior human review.
Standards Unaffected: Finalized ML-KEM and ML-DSA remain secure; the episode highlights the practical value of measured crypto-agility for organizations planning post-quantum migrations.
On July 28, 2026, Anthropic researchers disclosed an improved HAWK key-recovery attack on the NIST pqc-forum against HAWK, a lattice-based digital signature scheme that had advanced as one of nine candidates to the third round of the Additional Digital Signatures for the Post-Quantum Cryptography Standardization Process. The attack, discovered primarily by the company’s Claude Mythos Preview model with minimal human guidance, reduces HAWK key recovery to polynomially many exact Shortest Vector Problem (SVP) calls in dimension at most roughly n/2 + 1. An independent cryptographer confirmed the reduction within hours. The following morning the HAWK development team withdrew the submission, stating that parameter adjustments needed to restore claimed security margins would make the scheme uncompetitive. The finding does not affect NIST’s finalized standards ML-KEM or ML-DSA.
Lattice Automorphism and Cost Reduction
HAWK relies on the hardness of the module Lattice Isomorphism Problem over power-of-two cyclotomic rings. The new attack, detailed in a paper by Zygimantas Straznickas and Stephen A. Weis, identifies a nontrivial Galois automorphism whose associated cocycle can be recovered as a shortest vector of a publicly computable near-hypercubic lattice, reducing the relevant SVP dimension to roughly n/2 + 1. In the gate-count model used by the HAWK specification, the attack lowers estimated key-recovery cost for HAWK-512 from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182.
A practical end-to-end implementation recovers HAWK-256 challenge keys in a few hours on a single server. Anthropic reported about 60 hours of work and roughly $100,000 in API costs, with an Anthropic researcher providing occasional guidance despite not being a lattice-cryptography specialist. The construction does not transfer to Falcon or other lattice schemes based on different hardness assumptions.
The attack does not make the larger HAWK-512 or HAWK-1024 parameters practically breakable today; instead, it substantially reduces their estimated security margins. Johns Hopkins cryptographer Matthew Green argued that the significance lies partly in how the attack systematically combines and extends existing cryptanalytic tools rather than introducing fundamentally new mathematics.
Crypto Agility and Migration Planning
The HAWK withdrawal occurred roughly 17 hours after the public mailing-list post. The scheme had undergone two rounds of evaluation in NIST’s Additional Digital Signatures process before the third-round advance. Straightforward mitigations, such as doubling parameters or moving to higher-rank modules, were judged by the designers to eliminate the efficiency advantages that had made HAWK competitive.
NIST updated its Round 3 candidate page to reflect the withdrawal. The finding does not affect NIST’s finalized ML-KEM or ML-DSA standards, and the researchers said the attack is specific to HAWK because it targets HAWK’s specific module-Lattice Isomorphism construction and does not transfer to ML-DSA or ML-KEM. The remaining eight third-round candidates continue under evaluation.
The episode illustrates that algorithm selection alone is insufficient for long-term post-quantum readiness. Organizations must also measure and maintain the operational capacity to replace cryptographic primitives when security assessments change. Migration timelines measured in years contrast with discovery-to-withdrawal intervals measured in hours once AI-assisted cryptanalysis is applied.
Bottom Line
An AI-assisted lattice attack led to HAWK’s rapid withdrawal from NIST’s additional signatures process, reinforcing the need for measured crypto-agility.
Find out more here.
—
Further articles, reports, and the latest quantum computing news may be found at The Qubit Report.
Related Articles
Saab UK, Aquark Technologies and Royal Navy Complete World-First Quantum Timing Radar Trial
Saab UK, Aquark Technologies and the Royal Navy DCTO completed a trial showing Giraffe 1X radars can maintain a coherent air picture using independent AQlock
Alice & Bob Joins €4.6 Million QuBriC Network for Quantum Error Correction Doctoral Training
Alice & Bob has joined QuBriC, Europe’s first doctoral network entirely dedicated to quantum error correction. The €4.6 million Horizon Europe programme will train 15
Quantinuum and Oracle Partner to Bring Helios Quantum Computer to Oracle Cloud Infrastructure for Hybrid Quantum-AI Workloads
Quantinuum and Oracle announced a multi-year partnership on August 11, 2026, to deploy the Helios quantum computer inside a U.S. Oracle Cloud Infrastructure AI data