메뉴
BL
The Decoder 13시간 전

앤스로픽 '미토스' 모델, 인터넷 보안 암호 알고리즘 취약점 발견

IMP
8/10
핵심 요약

앤스로픽(AI 기업)의 최신 AI 모델인 '클로드 미토스 프리뷰(Claude Mythos Preview)'가 양자 후기 서명 방식 HAWK 및 축소 버전의 AES 암호화 알고리즘에서 수학적 취약점을 독자적으로 발견했습니다. 다중 에이전트 시스템을 통해 인간 개입을 최소화한 상태로 약 60시간 만에 새로운 해킹 기법을 찾아냈으며, 이는 AI가 향후 인터넷 보안의 근간을 이루는 암호학을 연구하고 위협하는 데 핵심적인 역할을 할 수 있음을 시사합니다. 현재 사용 중인 시스템에 즉각적인 영향을 미치지는 않지만, API 호출에 약 10만 달러가 소모된 이번 사례는 보안 연구의 패러다임을 전환할 중요한 의미를 지닙니다.

번역된 본문

Anthropic(앤스로픽)은 자사의 AI 모델인 Claude Mythos Preview(클로드 미토스 프리뷰)가 디지털 보안을 뒷받침하는 암호화 알고리즘에서 수학적 약점을 발견했다고 밝혔습니다. Anthropic에 따르면, 이 모델은 양자 후기(Post-quantum) 서명 방식인 HAWK에 대한 개선된 공격 방식과 AES(고급 암호화 표준)의 축소 버전에 대한 새로운 공격 방식을 개발했습니다.

암호화는 우리가 인터넷에서 하는 거의 모든 일을 보호하며, AES는 전 세계적으로 가장 널리 사용되는 대칭형 암호화 표준입니다. Anthropic은 이번 발견이 현재 사용 중인 시스템에는 영향을 미치지 않는다고 밝혔습니다. HAWK는 미국 국립표준기술연구소(NIST)가 진행 중인 표준화 과정의 후보일 뿐이며, AES 공격도 전체 10라운드 중 7라운드만 사용하는 변형 버전에만 적용되기 때문입니다. 하지만 이번 결과는 AI 모델이 인터넷 보안의 핵심적인 가정에 어떻게 도전할 수 있는지를 잘 보여줍니다.

Mythos, 10만 달러와 60시간 만에 HAWK 공격 방식 발견 HAWK는 미래의 양자 컴퓨터 공격에도 안전하게 유지되도록 설계된, NIST의 추가 양자 후기 서명 경쟁 3라운드에 남아 있는 방식 중 하나입니다. 인간 전문가들은 2년 넘게 HAWK를 검토했지만, Anthropic에 따르면 Mythos Preview는 단 60시간 만에 개선된 공격 방식을 찾아냈습니다.

이 공격은 HAWK의 보안이 의존하는 수학적 격자(Lattice)에서 이전에 발견되지 않았던 대칭성을 악용합니다. Mythos는 다중 에이전트 시스템에서 반자율적으로 작동하여 이를 찾아냈습니다. 보고서에 따르면, 하나의 에이전트는 처음에 이 아이디어를 실행 불가능하다고 기각하려 했지만, 두 번째 에이전트가 이를 완전히 악용할 방법을 찾아냈습니다. Anthropic에 따르면, 참여한 인간 연구원은 이론적 컴퓨터 과학 배경을 가지고 있었지만 격자 기반 암호학 전문가는 아니었으며, 그의 역할은 주로 프로젝트 관리에 국한되었습니다. 이 과정의 API 비용은 총 약 10만 달러(약 1억 3,500만 원)가 들었습니다.

Mythos, 처음에는 AES 작업을 거부했다가 새로운 공격 방식 발견 또한 이 모델은 AES-128의 축소된 버전에 대한 공격 방식을 거의 완전히 독자적으로 발견했습니다. 연구원은 Claude가 가설을 세우고 실험을 통해 이를 테스트할 수 있는 기반(Scaffold)을 마련했습니다. 그 후 Mythos는 Anthropic이 '뫼비우스 브릿지(Möbius Bridge)'라고 부르는 새로운 지문(Fingerprinting) 방식을 개발했습니다. 이 방식은 공격자가 해야 하는 추측 중 하나를 제거하여 기존에 알려진 최고의 공격보다 200~800배의 성능 향상을 이뤄냈습니다.

인간의 프롬프트는 매우 적은 역할을 했습니다. 모델은 처음에는 더 이상의 개선은 불가능하다고 생각하여 문제 해결을 거부했습니다. 심지어 모델은 "다른 결과를 원한다면 목표 자체가 바뀌어야 합니다... AES-128 r5/r6은 정말로 어렵습니다"라고 작성하기도 했습니다. 하지만 연구원이 '진정으로 새로운 아이디어'를 찾아보라고 격려한 후에야 Mythos는 더 창의적인 접근 방식을 모색하기 시작했습니다.

이후 3일 동안 모델은 수억 개의 토큰을 생성했으며, 방향을 잡아주기 위한 3개의 핵심 프롬프트만을 추가로 받았습니다. 그중 하나는 단순히 "다시 말하지만 우리는 쉬운 문제를 찾는 것이 아닙니다. 우리는 진정으로 어려운 결과를 찾는 적절한 연구를 원합니다"라고 적혀 있었습니다. 이 작업 역시 약 10억 개의 토큰을 처리하며 약 10만 달러의 API 비용이 발생했습니다. Anthropic에 따르면, 암호학 전문가가 아닌 인간 연구원들은 이어서 결과를 검증하는 데 수백 시간을 소모했습니다.

원문 보기
원문 보기 (영어)
Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet Matthias Bastian View the LinkedIn Profile of Matthias Bastian Jul 28, 2026 Nano Banana Pro prompted by THE DECODER Key Points Anthropic's AI model Claude Mythos Preview found mathematical weaknesses in cryptographic algorithms, including a reduced version of AES, the world's most widely used symmetric encryption standard. Anthropic says the findings have no immediate impact on systems currently in use. Working largely on its own in a multi-agent system, the model developed two attacks at an API cost of roughly $100,000 each. According to Anthropic, the human researchers mostly handled project management, provided simple prompts, and later verified the results. Ask about this article… Search Anthropic's AI model Claude Mythos Preview found mathematical weaknesses in cryptographic algorithms that underpin digital security. According to Anthropic, the model developed an improved attack on the post-quantum signature scheme HAWK and a new attack on a reduced version of the Advanced Encryption Standard (AES). Encryption protects nearly everything people do online, and AES is the world's most widely used symmetric encryption standard for digital data. Anthropic says neither finding affects systems in use today. HAWK is only a candidate in an ongoing standardization process run by the U.S. National Institute of Standards and Technology (NIST) and the AES attack applies to a modified version that uses 7 of the full scheme's 10 rounds. Still, the results show how AI models could challenge core assumptions behind internet security. Ad Mythos found the HAWK attack in 60 hours for $100,000 HAWK is one of the remaining schemes in the third round of NIST's competition for additional post-quantum signatures. These schemes are designed to stay secure even against future quantum computers. Human experts had reviewed HAWK for over two years, but Mythos Preview found an improved attack in just 60 hours, according to Anthropic. Ad DEC_D_Incontent-1 The attack exploits a previously undetected symmetry in the mathematical lattice that HAWK's security relies on. Mythos worked semi-autonomously in a multi-agent system to find it. One agent initially tried to dismiss the idea as infeasible, according to the report, but a second agent found a way to fully exploit it. The human researcher had a background in theoretical computer science but wasn't an expert in lattice-based cryptography, Anthropic says. His role was mostly limited to project management. The API costs totaled about $100,000. Ad Mythos initially refused the AES task before finding a new attack The model also found the attack on a reduced version of AES-128 almost entirely on its own, according to Anthropic. A researcher built a scaffold that allowed Claude to form hypotheses and test them through experiments. Mythos then developed a new fingerprinting method that Anthropic calls "Möbius Bridge." The method removes one of the guesses an attacker must make and improves on the best previously known attacks by a factor of 200 to 800. Ad DEC_D_Incontent-2 Human prompting played a small role. The model initially refused to tackle the problem because it considered further improvements impossible, writing that "If you want a different outcome, the target has to change … AES-128 r5/r6 is just genuinely hard." Mythos only began pursuing more creative approaches after the researcher encouraged it to look for "genuinely novel ideas." Ad Over three days, the model then generated several hundred million tokens and received only three more substantive prompts, mostly to keep it on track. One simply read, "gain we are not looking for low hanging fruit, we want proper research to find genuinly [sic] hard findings." This run also cost about $100,000 in API fees for roughly 1 billion tokens. Human researchers who weren't cryptography experts, according to Anthropic, then spent several hundred hours checking the results. Anthropic shared the findings and still restricts access to Mythos Anthropic shared the findings in advance with the U.S. government and industry partners. It also coordinated disclosure of the HAWK weakness with the scheme's authors. Mythos Preview remains unavailable to the public. Together with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa, Anthropic also developed a benchmark called CryptanalysisBench that lets others systematically evaluate the cryptanalytic abilities of language models. AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: Anthropic | HAWK Paper | AES Paper