Improved key-recovery attack on HAWK
Can the best known key-recovery attack against the HAWK signature scheme be made substantially faster?
References
Primary source
Progress summary
A public preprint confirms a much faster attack that breaks the practical security target of HAWK-256 and led to HAWK’s withdrawal from standardization.
The problem asks whether the best known key-recovery attack on HAWK can be substantially accelerated. A public preprint now gives a deterministic reduction that does so, together with an experimental recovery of a HAWK-256 secret key.
Known results
- Key recovery for HAWK- reduces to exact SVP in dimension .
- The reported costs fall from to for HAWK-512 and from to for HAWK-1024.
- HAWK-256 key recovery was demonstrated in a few hours on one server.
- The attack exploits a previously unused Galois involution and lattice structure; the construction does not transfer to Falcon.
2026 attack and withdrawal
An Anthropic researcher working with Claude Mythos Preview discovered the exploitable automorphism and developed the attack. HAWK’s team announced withdrawal from NIST’s additional signature-scheme process. A separate GPT-5.6 approach was weaker and still undergoing verification.
Current status (as of July 2026): The improved attack is established by a public preprint and an HAWK-256 experiment; HAWK has been withdrawn, while verification of the separate GPT-5.6 attack remains open.
Solutions 0
No solutions have been posted yet.