AI가 암호를 깼다는 소식이 나왔다.

제목만 보면 인터넷 암호가 뚫린 것처럼 읽힌다.

앤트로픽 공식 발표를 열어보니 정반대 문장이 적혀 있었다..

먼저 그 문장부터. 앤트로픽은 이번 결과 두 건이 현재 쓰이는 컴퓨터 시스템에 실질적 영향을 주지 않으며, 이 때문에 바꿔야 할 상용 소프트웨어는 없다고 못 박았다.

그러니 지금 쓰는 은행 앱이나 메신저를 걱정할 일은 아니다. 그런데 그렇다고 별일 아닌 것도 아니다.

2026년 7월 28일, 앤트로픽 프론티어 레드팀이 발표한 내용이다. 클로드 미토스가 암호 알고리즘 두 곳에서 새 약점을 찾았다.

하나는 'HAWK'다. 미국 국립표준기술연구소(NIST)가 진행하는 양자내성 전자서명 표준화의 3라운드 후보였다. 표준 후보이지 실제로 쓰이던 게 아니다.

미토스가 찾아낸 건 HAWK가 쓰는 격자 구조 안의 특정 대칭성이었다. 그걸 이용하면 키를 복구하는 비용이 2의 64승에서 2의 38승으로 떨어진다. 사실상 유효 키 길이가 절반이 되는 셈이다.

다른 하나는 AES인데, 여기가 오해가 생기는 지점이다. 전체 10라운드가 아니라 7라운드로 줄인 축소판이 대상이었다. 그 축소판에 대한 기존 최고 공격보다 200~800배 빠른 방법을 찾았다. 온전한 AES는 영향을 받지 않는다.

정작 눈에 걸린 건 암호가 아니라 '누가 했나'였다.

HAWK 쪽은 앤트로픽 연구자 한 명이 클로드와 함께 작업했는데, 발표문 표현으로는 미토스가 대체로 자율적으로, 사람 개입 없이 진행했다. 약 60시간이 걸렸다.

AES 쪽은 더 세다. 거의 전적으로 자율적으로 찾아냈다고 적혀 있다. 3~5일 자율 작업이었고, 연구자들은 모델의 주장을 검증할 수 있을 만큼 암호학을 배우는 데 수백 시간을 썼다.

결과를 검증하는 쪽이 결과를 만드는 쪽보다 오래 걸렸다는 얘기다.

비용은 발견 하나당 API 사용료로 약 10만 달러가 들었다.

AI가 60시간에 찾은 걸, 사람이 검증하려고 수백 시간 암호학을 공부했다.

앤트로픽은 6월에 HAWK 개발자들과 공격 내용을 공유하고 NIST 공개 메일링 리스트를 통해 조율된 공개 절차를 밟았다.

그리고 HAWK는 NIST 추가 전자서명 표준화 과정에서 철회됐다.

실제로 쓰이기 전에 걸러졌다는 뜻이다. 표준화 과정이 이런 걸 잡으려고 있는 절차라, 이번엔 그 절차가 작동한 사례로 봐도 되겠다.

그래서 이 소식의 무게는 '암호가 깨졌다'가 아니다.

사람이 오래 들여다본 후보에서 AI가 새 약점을 찾아냈고, 그 결과 표준 후보 하나가 빠졌다는 것이다.

이게 방어 쪽에 좋은 소식인지 공격 쪽에 좋은 소식인지는 아직 모르겠다. 이번엔 표준화 전에 잡혔지만, 같은 능력이 이미 쓰이는 것에 향할 수도 있다.

개인이 당장 할 일은 없다. 다만 헤드라인만 보고 놀랄 필요도 없다.

발표문에 적힌 그대로다. 바꿔야 할 소프트웨어는 없다..

News broke that an AI cracked encryption.

From the headlines it reads like internet encryption fell.

Then I opened Anthropic's own write-up and found the opposite sentence..

That sentence first. Anthropic states plainly that neither result has a practical impact on today's computer systems, and that no production software will have to change because of it.

So your banking app is fine. That doesn't make it nothing, though.

On July 28, 2026, Anthropic's Frontier Red Team published the findings: Claude Mythos found new weaknesses in two cryptographic algorithms.

One is HAWK, a third-round candidate in NIST's post-quantum signature standardization. A candidate — not something in use.

What Mythos found was a particular symmetry inside the lattice HAWK relies on. Exploiting it drops the cost of key recovery from 2^64 to 2^38 operations — effectively halving the useful key size.

The other is AES, and this is where the confusion starts. The target was a reduced 7-round variant, not the full 10 rounds. Against that variant it found an attack 200 to 800 times faster than the previous best. Full AES is unaffected.

What stuck with me wasn't the cryptography. It was who did the work.

On HAWK, one Anthropic researcher worked together with Claude, but by the write-up's own description Mythos proceeded mostly autonomously and mostly without human intervention. It took about 60 hours.

The AES side goes further: discovered almost entirely autonomously, over three to five days of autonomous work. The researchers then spent several hundred hours learning enough cryptography to validate the model's claim.

Verifying the result took longer than producing it.

The cost came to roughly $100,000 in API usage per finding.

The AI found it in 60 hours. Humans spent hundreds of hours learning enough to check it.

Anthropic shared the attack with HAWK's authors in June and ran a coordinated disclosure through the public NIST mailing list.

HAWK was then withdrawn from NIST's additional signature standardization process.

Which means it was caught before deployment. Standardization exists to catch exactly this, so this reads as the process working.

So the weight of this story isn't "encryption is broken".

It's that an AI found a new weakness in a candidate humans had studied at length, and a standardization candidate dropped out as a result.

Whether that's good news for defenders or attackers, I don't know yet. This one was caught before standardization — the same capability could be pointed at something already in use.

Nothing for an individual to do today. And no reason to panic at a headline either.

It's right there in the write-up: no software has to change..