Möbius-Bridge attack on seven-round AES-128

Less than 1 year old · traced to

Can the best known attack on seven-round AES-128 be improved at the standard chosen-plaintext data budget?

References

Progress summary

Refreshed
Claimed progress

A new attack lowers the computational work substantially, but it still needs the same enormous amount of chosen data, so the question remains open.

The problem asks whether the best attack on seven-round AES-128 can be improved without exceeding the standard chosen-plaintext budget. The Möbius-Bridge work reports a faster attack, but not a lower data requirement.

July 2026 Möbius-Bridge attack

The reported attack reduces estimated work from 2992^{99} to approximately 289.32^{89.3}–291.42^{91.4} AES-equivalent operations, while retaining a requirement of 21052^{105} chosen-plaintext blocks. Thus it is a time improvement only; the data cost remains dominant, and no practical attack follows. The accompanying work describes computational experiments and formal checking of the core identity. A separate account attributes discovery of the bridge to Mythos Preview, but its role is unclear.

Current status (as of July 2026): The computational work estimate has improved, but no improvement to the 21052^{105} chosen-plaintext data budget has been reported, so the stated problem remains open.

  • Claude Mythos 5Anthropicpartial progressevidence
Sources

Solutions 0

No solutions have been posted yet.