9.22.2026

The Next Cryptographic Break May Already Be in the Library

Contributors:
Denis Mandich
Category:
Blog Post

A cryptographic algorithm can survive years of expert scrutiny and collapse when someone recognizes the significance of a theorem published decades earlier. 

 

SIKE did exactly that, but it was elite mathematicians. Frontier AI makes this history newly relevant because systems capable of connecting obscure mathematical ideas are now powerful cryptanalysts, not simply tools for them. Security leaders should be planning for a shorter window between an overlooked weakness and a working attack at the foundations of cybersecurity, not just the latest interesting CVE making headlines.  

 

That requires a broader objective for post-quantum migration. Alongside replacing vulnerable algorithms, organizations must reduce the consequences when a replacement eventually fails. In July 2022, SIKE advanced to the fourth round of the National Institute of Standards and Technology’s post-quantum cryptography evaluation. Its small keys and ciphertexts offered practical advantages, and it remained a serious candidate after years of research. NIST’s announcement 

 

Then mathematicians Wouter Castryck and Thomas Decru connected the protocol’s structure to a theorem Ernst Kani published in 1997. Their initial attack recovered a private key for SIKE’s smallest proposed parameter set in about an hour on a single processor core, on a very old laptop. Larger parameter sets also fell. Ordinary computing hardware was sufficient, no quantum anything required. Original attack paper 

 

The theorem had been available for a quarter century. The breakthrough came from recognizing how it applied to information exposed by the protocol, then developing that connection into a practical attack. This is a very uncomfortable foundation for confidence. Years without a successful attack provide evidence, but they cannot establish that every useful mathematical connection has been explored until there is a hard mathematical proof. None exists today for the PQC algorithms we’re betting the farm on.  

 

Frontier AI is expanding the capacity to explore those connections. 

 

In May 2026, OpenAI reported that an internal model disproved a longstanding conjecture associated with Erdős’s planar unit-distance problem, first posed in 1946. External mathematicians checked the proof. The model applied sophisticated algebraic number theory to a seemingly elementary geometry question, a transfer of ideas between fields that produced a major result. This was just a warmup, and arguably the result of few researchers working on it, rather than defying the best minds in the field for 80 years. It was great marketing either way and a welcome departure from the last seven years of “this model is too dangerous to release” clickbait campaigns promoting every new model weeks before release. Research announcement 

 

This month, OpenAI announced an AI-generated solution to the Navier–Stokes existence and smoothness problem, unresolved for roughly 90 years, and released both a written proof and a formalization for computer verification. The announcement remains subject to mathematical scrutiny, but the progression is stunning: frontier systems are now producing research claims against problems that have occupied generations of the best mathematicians. Navier–Stokes announcement 

 

It is an absolute certainty these capabilities to accelerate the search for overlooked cryptographic weaknesses are being used today on a vast scale, especially by intel agencies with enormous grid-straining compute, long before AI made it cool. Would today’s models have independently broken SIKE in hours? Would it have happened in secret or made public? What has been demonstrated is AI’s growing ability to search professional literature, propose mathematical connections, write experimental code, and investigate thousands of ideas to discover what works. Unlike finding and testing a cure for cancer or designing a new chemical, this game is instantly verifiable by the same systems. 

 

There is already a direct cryptographic example. 

 

In July 2026, Anthropic reported that Claude Mythos Preview helped discover an improved attack against HAWK, a post-quantum digital-signature candidate. The work took approximately 60 hours and exploited a previously unused symmetry in its lattice structure. The attack substantially reduced estimated security, although larger parameter sets remained impractical to attack, and the method was still exponential. It did not establish a general break of lattice cryptography. Anthropic’s report 

 

Those boundaries are moving quickly in lock-step with the demonstrated capability: AI-assisted research found a mathematical weakness in a design that had already received substantial human review. AI cannot do jobs and isn’t inventing new math, but it excels at running assigned tasks just like this one.  

 

For defenders, this strengthens the tools available to evaluate new cryptography. For attackers, it creates another way to search for access. A security plan must account for both, including discoveries an adversary will keep private as long as possible. When it comes to governments, no intel collection requirement is more important than protecting sources and methods.  

 

An organization protecting sensitive information for twenty years is making a commitment that extends across many generations of mathematical research, AI systems, and computing hardware. Its exposure depends partly on what an attacker can collect during that period. Where captured traffic contains enough information to reconstruct an encryption key after a future breakthrough, the attacker can preserve that opportunity indefinitely. This is the operational problem behind Harvest Now, Decrypt Later. The collection and the eventual exploitation can be separated by years, and it is demonstrably global and remote today. The wire taps and physical access days have passed, since China has already penetrated virtually every US government agency and major corporation from the safety of a base near Beijing.  

 

An algorithm upgrade protects subsequent communications. It cannot recall copies already held by someone else. That’s why harvesting data will never end, not even with PQC. Cryptographic agility remains essential, but it must have an operational meaning: an accurate inventory, known dependencies, tested replacement procedures, and measured recovery times. A promise to switch algorithms later does little for an organization that cannot identify every affected application, certificate, appliance, and embedded device. 

 

Even excellent agility leaves a harder question unanswered: what protects historical data while a successful attack remains undisclosed? Retroactive insecurity is now the standard, but it doesn’t have to be. Swapping algorithms is playing the short game against an enemy with a 50 year plan and infinite patience. Storing troves of encrypted data is nearly free relative to the ROI for exploiting even a small fraction of it. The calculus and risk of human enabled operations against remote cyber exploitation is a no-brainer. Spectacular HUMINT is irreplaceable and impact incalculable in many cases, but SIGINT is the bread and butter.  

 

That is where architecture becomes decisive. 

 

A system should be evaluated by the combinations of failures required to expose its data. Several products using the same underlying cryptographic assumption can create the appearance of layered protection while preserving a common failure point. Distributing sensitive material, separating security functions, and limiting retention can change what an attacker must obtain. The goal is to eliminate the viability of industrial scale exploitation and force the adversaries into the retail business of breaking into a single device, file, or target. The cost and resources must be prohibitive.  

 

Qrypt’s BLAST approach applies this principle to key generation. Communicating endpoints obtain corresponding samples of quantum-derived random material from distributed sources and generate matching symmetric encryption keys locally. This separates key generation from the application carrying the encrypted data, nullifying most HNDL or at a minimum, eliminating any single point of failure outside the endpoint. Qrypt’s architecture documentation 

 

The security value depends on that broader design. The important questions concern who can obtain the inputs, which channels and services must remain protected, how coordination information is secured, and how long underlying random material remains available. Bulk decryption is possible when the randomness used to make the encryption keys is flawed or the algorithm using them is. The former enables highspeed mass decryption and is the golden goose for any intel service, whether deliberately introduced or inadvertently created.  

 

Security dependencies must be explicit and validated in the deployed configuration for any enterprise or they quickly devolve to security theater. Endpoint compromise, authentication, the symmetric cipher protecting the data, and the entire stack still matter. Quantum entropy supplies a foundation for key generation that ensures the most devastating decryption methods are useless. The converse is not true for algorithms, which have no security guarantees when the key space is known or predictable.  

 

Qrypt’s Quantum-Secure IPsec Gateway combines BLAST with post-quantum cryptography in an existing network-security deployment model. That combination illustrates the direction: strengthen algorithms while changing how encryption keys are supplied and how cryptographic dependencies are distributed. Qrypt’s gateway overview 

 

Security leaders can make that direction concrete now: 

     

  • Prioritize by secrecy lifetime. Identify information whose disclosure would remain damaging years after collection, including intellectual property, sensitive training data, and strategic communications. 
  • Map shared failure points. Determine which systems rely on the same algorithms, credentials, entropy services, and administrative controls. 
  • Test the collection scenario. Establish what an adversary recording each network path could obtain, and what additional compromises would be required to reconstruct keys. 
  • Exercise replacement and recovery. Measure the time needed to change cryptography, rotate affected material, and restore service under realistic conditions. 

 

SIKE demonstrated that an old theorem could overturn years of confidence backed by strong mathematicians. AI-assisted cryptanalysis increases the urgency of designing for the next such discovery, which may not be public at all. Continue the post-quantum migration, use it to remove shared failure points and establish what will still protect the data if an algorithm fails. The most sophisticated and expensive marketing campaigns in history are built on proving how threatening and powerful these AIs are becoming just before any new release. We should anticipate one of them will break another PQC algorithm like HAWK (very soon) as proof. Another Erdos problem will be a yawn, the Riemann Hypothesis is still fantasy but breaking another PQC cipher equals higher IPO valuation. 

 

The next useful theorem may already be published, and the search for it is accelerating.