Markets Open
Global Markets
S&P 500 7,375.43 ▲ +0.8% DOW 51,723.15 ▲ +0.3% NASDAQ 24,933.96 ▲ +2.0% RUSSELL 2K 2,914.86 ▲ +0.3% VIX 18.92 ▼ -8.4% GOLD 4,153.1 ▲ +2.9% CRUDE OIL 84.54 ▲ +0.1% EUR/USD 1.15 ▲ +1.2% BTC 64,678 ▲ +1.1% ETH 1,916.84 ▲ +1.3%
Fintech

Anthropic cryptography weaknesses raise bank security migration questions

Anthropic said frontier AI found weaknesses in HAWK and reduced-round AES, adding pressure on banks to map and replace embedded encryption.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

Anthropic cryptography weaknesses raise bank security migration questions
Photo: PYMNTS

Anthropic cryptography weaknesses disclosed in a Tuesday research report showed that the company’s frontier AI systems could identify previously unknown flaws in several cryptographic algorithms, including HAWK and a reduced-round version of AES. Anthropic said the findings do not affect current production banking systems and do not compromise full-strength AES, but the work points to a possible shift in the economics of cyber risk for financial institutions.

According to Anthropic, models developed under its Mythos AI systems found weaknesses in cryptographic designs that had been considered resilient. HAWK is a post-quantum digital signature scheme, a type of mechanism intended to verify that a message or transaction is authentic even in a future computing environment that includes quantum threats. AES, or Advanced Encryption Standard, is the encryption standard used across much of the internet, though Anthropic’s finding involved only a reduced-round version rather than the full-strength standard used in practice.

Can AI break bank encryption today?

Anthropic said its discoveries do not break the encryption protecting bank accounts today. The broader issue for banks is whether frontier AI can shorten the time needed to find and develop cryptographic attacks, which has historically required scarce expertise, substantial computing resources and years of research.

Financial security depends in part on that cost barrier. Encrypted systems support payment authorization, mobile banking, ATM withdrawals, cloud infrastructure, software signing, token vaults and the exchange of credentials among banks, processors, networks and financial technology providers. If advanced models reduce the cost or time needed to test cryptographic systems for weaknesses, banks may need to treat encryption agility as a core operational requirement rather than a periodic technology upgrade.

Why replacing encryption is hard for banks

Bank encryption is embedded across many layers of infrastructure, including payment terminals, mobile apps, APIs, databases, cloud services, authentication systems, card-processing platforms, ATMs, hardware security modules and older core banking systems. Replacing an algorithm can require a detailed inventory of applications, vendor dependencies, hardware updates, interoperability testing and compliance recertification.

The difficulty rises at industry scale. A bank may be ready to change a cryptographic standard, but payment networks, processors, cloud providers and other technology partners also need to update systems in a coordinated way. In a fast-moving security event, the constraint may be less about finding a replacement algorithm and more about locating every place where the old one remains in use.

PYMNTS Intelligence has separately reported that large enterprises can be more exposed to AI-powered identity document spoofing because of wider digital footprints and the use of deepfakes and automated data scraping by fraudsters. That finding relates to identity fraud rather than cryptographic research, but it underscores the broader operational issue: AI can expand the scale at which attackers test financial defenses.

Scott Aaronson, a scientific adviser at StarkWare, told PYMNTS in February that banks should begin considering migration to quantum-resistant encryption methods. Anthropic’s findings add a separate AI dimension to that planning debate, because the concern is not only future quantum computing capacity but also the ability of current frontier models to accelerate cryptanalysis.

For financial institutions, the practical response suggested by the research is preparation rather than alarm. Banks can assess where cryptography is used, whether systems can be updated quickly and whether vendors are obligated to support future migrations. Anthropic’s report leaves today’s production banking encryption intact, while raising a governance question that banks may find harder to defer: how quickly they can change security standards if a theoretical weakness becomes commercially relevant.

This story draws on original reporting from PYMNTS.

More from Fintech

All Fintech →