Back to News
RSS feedai-frontiers.org

How AI Could Undermine Public-Key Encryption? Actually, How AI Could Endanger Public-Key Encryption

Summary

AI models have recently made progress on difficult mathematical and cryptanalytic problems, prompting concern that they could eventually discover efficient methods for breaking the mathematical assumptions behind public-key encryption. The article cites Anthropic research in which Claude Mythos Preview found attacks against two cryptographic algorithms, including a post-quantum method under evaluation by NIST, and notes an AI-assisted attack on McEliece estimates published in August 2026. These examples do not prove that all public-key systems can be broken, but they illustrate the risk that increasingly capable models could examine far more possible leads than the small human cryptanalysis community. Public-key encryption already faces a separate long-term threat from quantum computing through Shor’s algorithm, which is why post-quantum cryptography is being developed; proposed replacements have also suffered serious breaks, including SIKE and possibly McEliece. The author explains this risk through Russell Impagliazzo’s distinction between Minicrypt, where symmetric encryption, hashes, and signatures remain possible, and Cryptomania, where public-key encryption is also feasible. If public-key encryption became impractical, secure messaging users might need to establish keys in person, while web traffic could depend on trusted intermediaries that distribute keys and could be compelled to decrypt communications. Such intermediaries would create new chokepoints for surveillance, identity checks, and deplatforming, and governments might conceal a breakthrough rather than warn the public. Because replacing widely deployed algorithms can take 10 to 20 years, the article recommends preparing Minicrypt-ready protocols in advance, including browser and operating-system support and multiple intermediaries using secret sharing across jurisdictions. The author presents this as a precaution against a possible future, not as evidence that current public-key encryption has already failed.