Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines
Abstract
1. Introduction
- A cryptographic architecture model treating Mythos as a non-human system actor in PQC migration.
- A lifecycle-aligned PQC migration model incorporating AI-accelerated analysis.
- An updated PQC migration cost and timeline model under AI-accelerated adversarial pressure.
- Governance and risk recommendations for frontier-model access.
1.1. Method
1.2. Epistemic Status
1.3. Analysis Parameters and Assumptions
2. Definitions and Scope
2.1. PQC Migration as a System-of-Systems Transformation
- Cloud and enterprise applications.
- Mobile and endpoint clients.
- IoT and embedded devices.
- OT/ICS systems.
- Tactical radios and RF systems.
- Satellites and space systems.
- Cross-domain gateways.
- PKI and identity infrastructure.
2.2. Mythos as a System Actor
- Advanced reasoning and extended autonomous task execution, with the ability to chain multiple vulnerabilities into working exploits without human intervention [9].
- Autonomous zero-day vulnerability discovery, per Anthropic’s Frontier Red Team brief: thousands of zero-day vulnerabilities identified, including some in every major operating system and every major web browser, with long-lived bugs surfaced after decades of human review [9].
- Cross-domain protocol and system analysis, including reverse-engineering exploits on closed-source software and converting N-day disclosures into working exploits [9].
- Anthropic-reported pre-launch briefings to U.S. federal officials, per Platformer reporting [15], including conversations with the Cybersecurity and Infrastructure Security Agency (CISA) and the Center for AI Standards and Innovation (CAISI); these are briefings reported by Anthropic rather than confirmed ongoing-access arrangements, and as of 21 April 2026, Axios reported that CAISI and the National Security Agency were assessing the model while CISA had not been granted access [28].
3. Background and Related Work
3.1. PQC Standards and Migration Guidance
3.1.1. NIST Standards
3.1.2. NSA CNSA 2.0
3.1.3. OMB M-23-02 and CISA Guidance
3.2. Frontier Model Capabilities
3.2.1. Anthropic System Card and Risk Documentation
3.2.2. Frontier Red Team Technical Brief
3.2.3. Independent Analysis and High-Credibility Reporting
3.3. AI-Accelerated Vulnerability Discovery
3.3.1. Mythos-Era Step-Change in Discovery
3.3.2. Positioning Relative to Traditional Vulnerability Management
4. Cryptographic Architecture Layers
4.1. Crypto-Touchpoint Topology
4.2. Protocol Decomposition Layer
4.3. Firmware and Embedded Dependencies
4.4. Cross-Domain Gateway Architecture
5. Migration Dynamics
5.1. Acceleration Loops
5.1.1. Automated Mapping Loop
5.1.2. Automated Redesign Loop
5.1.3. Automated Validation Loop
5.2. Stress Loops
5.2.1. Exploit-Discovery Loop
5.2.2. Attack-Path Generation Loop
5.2.3. Legacy-System Pressure Loop
5.3. Combined Dynamics
6. Migration Lifecycle Model
6.1. Phase 1: Pre-Migration Discovery
6.2. Phase 2: Migration Planning
6.3. Phase 3: Migration Execution
6.4. Phase 4: Validation and Testing
6.5. Phase 5: Post-Migration Assurance
7. Cost and Timeline Model
7.1. Cost Drivers
7.1.1. Embedded-System Gravity
7.1.2. Simultaneity Pressure
7.1.3. Cross-Domain Complexity
7.2. Timeline Compression
7.3. Methodology and Limitations of the Compressed-Track Projection
7.4. Updated Cost Model
- Accelerated timelines and the resulting concurrency premium.
- Increased testing at both interoperability and adversarial levels.
- Increased red-team requirements, including AI-assisted continuous testing.
- Cryptographic-agility investments that reduce the cost of the next transition.
7.5. Partial-Migration and Failure Scenarios
7.6. Sensitivity of the Compressed-Track Window
8. Governance and Risk
8.1. Frontier-Model Access Controls
8.2. Evaluation Requirements
8.3. Red-Team Requirements
9. Concluding Remarks
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| ACDI | Automated Cryptography Discovery and Inventory |
| AISI | AI Security Institute (UK) |
| ATO | Authority to Operate |
| CAISI | Center for AI Standards and Innovation |
| CBOM | Cryptographic Bill of Materials |
| CDG | Cross-Domain Gateway |
| CETaS | Centre for Emerging Technology and Security |
| CISA | Cybersecurity and Infrastructure Security Agency |
| CNSA | Commercial National Security Algorithm Suite |
| DAST | Dynamic Application Security Testing |
| DNSSEC | Domain Name System Security Extensions |
| FIPS | Federal Information Processing Standard |
| HSM | Hardware Security Module |
| IKEv2 | Internet Key Exchange version 2 |
| ML-DSA | Module-Lattice-Based Digital Signature Algorithm |
| ML-KEM | Module-Lattice-Based Key-Encapsulation Mechanism |
| MTU | Maximum Transmission Unit |
| NCCoE | National Cybersecurity Center of Excellence |
| NIST | National Institute of Standards and Technology |
| NSA | National Security Agency |
| NSS | National Security System |
| OMB | Office of Management and Budget |
| OT/ICS | Operational Technology/Industrial Control Systems |
| PKI | Public Key Infrastructure |
| PQC | Post-Quantum Cryptography |
| RF | Radio Frequency |
| RSP | Responsible Scaling Policy |
| SAST | Static Application Security Testing |
| SLH-DSA | Stateless Hash-Based Digital Signature Algorithm |
| TLS | Transport Layer Security |
References
- FIPS 203; Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM). National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024.
- FIPS 204; Module-Lattice-Based Digital Signature Standard (ML-DSA). National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024.
- FIPS 205; Stateless Hash-Based Digital Signature Standard (SLH-DSA). National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024.
- National Security Agency. Announcing the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0); NSA Cybersecurity Advisory (NSA): Fort Meade, MD, USA, 2022.
- Office of Management and Budget. OMB M-23-02: Migrating to Post-Quantum Cryptography; Executive Office of the President: Washington, DC, USA, 2022.
- Anthropic. System Card: Claude Mythos Preview. 7 April 2026. Available online: https://www.anthropic.com/claude-mythos-preview-system-card (accessed on 22 April 2026).
- TechCrunch. Anthropic Debuts Preview of Powerful New AI Model Mythos in New Cybersecurity Initiative. 7 April 2026. Available online: https://techcrunch.com/2026/04/07/anthropic-mythos-ai-model-preview-security/ (accessed on 22 April 2026).
- Anthropic. Alignment Risk Update: Claude Mythos Preview. 7 April 2026. Available online: https://www.anthropic.com/claude-mythos-preview-risk-report (accessed on 22 April 2026).
- Carlini, N.; Cheng, N.; Lucas, K.; Moore, M.; Nasr, M.; Prabhushankar, V.; Xiao, W.; Angulu, H.; Asher, E.B. Anthropic Frontier Red Team. Assessing Claude Mythos Preview’s Cybersecurity Capabilities. 7 April 2026. Available online: https://red.anthropic.com/2026/mythos-preview (accessed on 22 April 2026).
- Anthropic. Project Glasswing. 7 April 2026. Available online: https://www.anthropic.com/glasswing (accessed on 22 April 2026).
- Centre for Emerging Technology and Security (CETaS), Alan Turing Institute. Claude Mythos: What Does Anthropic’s New Model Mean for the Future of Cybersecurity? April 2026. Available online: https://cetas.turing.ac.uk/publications/claude-mythos-future-cybersecurity (accessed on 22 April 2026).
- AI Security Institute (AISI). Our Evaluation of Claude Mythos Preview’s Cyber Capabilities; UK Department for Science, Innovation and Technology: London, UK, 2026. Available online: https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities (accessed on 22 April 2026).
- World Economic Forum. Anthropic’s Mythos Moment: How Frontier AI is Redefining Cybersecurity. April 2026. Available online: https://www.weforum.org/stories/2026/04/anthropic-mythos-ai-cybersecurity/ (accessed on 22 April 2026).
- Fortune. Anthropic Says Testing Mythos, Powerful New AI Model, after Accidental Data Leak Reveals its Existence. 26 March 2026. Available online: https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/ (accessed on 22 April 2026).
- Newton, C. Why Anthropic’s New Model has Cybersecurity Experts Rattled. Platformer, April 2026. Available online: https://www.platformer.news/anthropic-mythos-cybersecurity-risk-experts/ (accessed on 22 April 2026).
- Mosca, M. Cybersecurity in an Era with Quantum Computers: Will We Be Ready? IEEE Secur. Priv. 2018, 16, 38–41. [Google Scholar] [CrossRef] [Scilit]
- Shor, P.W. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM J. Comput. 1997, 26, 1484–1509. [Google Scholar] [CrossRef] [Scilit]
- NIST SP 800-208; Recommendation for Stateful Hash-Based Signature Schemes. National Institute of Standards and Technology: Gaithersburg, MD, USA, 2020.
- Cybersecurity and Infrastructure Security Agency. Zero Trust Maturity Model; Version 2.0; CISA: Arlington, VA, USA, April 2023.
- Campbell, R. Synchronizing Concurrent Security Modernization Programs: Zero Trust, Post-Quantum Cryptography, and AI Assurance. Systems 2026, 14, 233. [Google Scholar] [CrossRef] [Scilit]
- Campbell, R. Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks. Computers 2026, 15, 9. [Google Scholar] [CrossRef] [Scilit]
- Glazunov, S.; Brand, M.; Project Zero; DeepMind. From Naptime to Big Sleep: Using Large Language Models to Catch Vulnerabilities in Real-World Code. Google Project Zero, 1 November 2024. Available online: https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html (accessed on 22 April 2026).
- Bhatt, M.; Chennabasappa, S.; Nikolaidis, C.; Wan, S.; Evtimov, I.; Gabi, D.; Song, D.; Ahmad, F.; Aschermann, C.; Fontana, L.; et al. Purple Llama CyberSecEval: A Secure Coding Benchmark for Language Models. arXiv 2023, arXiv:2312.04724. [Google Scholar] [CrossRef] [Scilit]
- Defense Advanced Research Projects Agency (DARPA). AI Cyber Challenge (AIxCC) Final Competition Results; DARPA: Arlington, VA, USA, 2025. Available online: https://www.darpa.mil/news/2025/aixcc-results (accessed on 22 April 2026).
- Moody, D.; Perlner, R.; Regenscheid, A.; Robinson, A.; Cooper, D. Transition to Post-Quantum Cryptography Standards; NIST Internal Report (IR) 8547 (Initial Public Draft); National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [CrossRef] [Scilit]
- National Cybersecurity Center of Excellence (NCCoE). Migration to Post-Quantum Cryptography Project; NIST: Gaithersburg, MD, USA, 2022–2026. Available online: https://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc (accessed on 22 April 2026).
- Cybersecurity and Infrastructure Security Agency. Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools; CISA: Arlington, VA, USA, 2024. Available online: https://www.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools (accessed on 22 April 2026).
- Sabin, S. CISA Doesn’t Have Access to Anthropic’s Mythos. Axios, 21 April 2026. Available online: https://www.axios.com/2026/04/21/cisa-anthropic-mythos-ai-security (accessed on 29 April 2026).
- Bernstein, D.J.; Lange, T. Post-Quantum Cryptography. Nature 2017, 549, 188–194. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Chen, L.; Jordan, S.P.; Liu, Y.-K.; Moody, D.; Peralta, R.C.; Perlner, R.A.; Smith-Tone, D.C. Report on Post-Quantum Cryptography; NIST Internal Report (IR) 8105; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2016. [CrossRef] [Scilit]
- U.S. Congress. Quantum Computing Cybersecurity Preparedness Act; Public Law 117-260; U.S. Government Publishing Office: Washington, DC, USA, 2022. Available online: https://www.congress.gov/117/plaws/publ260/PLAW-117publ260.pdf (accessed on 22 April 2026).
- Brundage, M.; Avin, S.; Clark, J.; Toner, H.; Eckersley, P.; Garfinkel, B.; Dafoe, A.; Scharre, P.; Zeitzoff, T.; Filar, B.; et al. The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation. arXiv 2018, arXiv:1802.07228. [Google Scholar] [CrossRef] [Scilit]
- Biggio, B.; Roli, F. Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning. Pattern Recognit. 2018, 84, 317–331. [Google Scholar] [CrossRef] [Scilit]




| Compression Claim | Source Evidence | Inference Step | Uncertainty | Falsification Criterion |
|---|---|---|---|---|
| 2–4-year compressed-track scenario envelope for highest-exposure systems (vs. 5–10-year small organization, 12–15+-year large enterprise traditional baselines) | Frontier Red Team capability disclosures [9]; CETaS open-weight convergence framing [11]; peer-reviewed enterprise migration baselines [20,21]; NIST IR 8547/NCCoE timeframe [25,26] | Capability-to-task transfer by analogy from software-engineering benchmarks to PQC sub-tasks; phase-concurrency restructuring under AI-augmented governance; bound above by adversary-capability convergence window | High | Longitudinal case studies of AI-augmented migration programs publishing before/after throughput data showing crown-jewel-asset migration completing at sequential-baseline rates (5+ years) despite full AI augmentation and governance restructuring |
| Cryptographic-touchpoint discovery compresses from 6 to –18-month enterprise baselines to days at AI-augmented throughput | Frontier Red Team CycloneDX-style enumeration [9]; Big Sleep precedent [22]; DARPA AIxCC Final results (86% discovery, 68% patching) [24] | Direct extension of demonstrated software-architectural reasoning to cryptographic-touchpoint enumeration; transfer is empirically plausible because the analytical primitive (program-structure analysis) is identical | Medium | Vendor-reported ACDI pilot data under CISA automated-inventory strategy [27] showing AI-augmented enterprise discovery campaigns measuring weeks-to-months rather than days for comparable touchpoint counts |
| Cost-per-exploit on adversary side shifts by approximately one order of magnitude relative to traditional pen-test and bug-bounty programs | Anthropic disclosed campaign costs (USD < 20,000 OpenBSD SACK; ~USD 10,000 FFmpeg; <USD 2000 N-day pipelines) [9]; standard-industry pen-test contracting rates and bug-bounty payout tables | Practitioner-grade comparison of disclosed AI-augmented costs against contracted-baseline rates; not a controlled per-exploit benchmark because workflows produce different exploit classes against different target sets | Medium | Published controlled benchmarks comparing AI-augmented vs. traditional exploit pipelines on identical target sets producing comparable per-exploit cost signatures |
| Discovery, Planning, Execution, and Validation phases operate concurrently rather than sequentially under AI-augmented governance | Frontier Red Team cross-component vulnerability chaining [9]; continuous-integration multi-track software-engineering practice | Transfer of phase-concurrency reasoning from continuous software-engineering practice to PQC migration program structure under the governance restructuring developed in Section 8 | Medium–High | AI-augmented PQC programs adopting phase concurrency but demonstrating no compression—indicating sequential bottlenecks elsewhere (institutional change-management, FIPS validation, ATO renewal) dominate the timeline |
| Adversary-capability window defining the compressed-track upper edge is months-scale (three-month average, 5–22-month range) | CETaS at Alan Turing Institute analysis [11]; Epoch AI proprietary-to-open-weight convergence data | Extension of historical model-class diffusion patterns to Mythos-class capability; cyber-offensive-specific convergence not separately estimated in cited analysis | Medium | Empirical observation of open-weight Mythos-equivalent capability appearing at horizons substantially shorter (weeks) or substantially longer (multi-year) than the 5–22-month range |
| External cadence (FIPS 140-3 module validation, ATO renewal, CNSA 2.0 audit, spectrum-allocation certification) remains non-compressible and is the binding constraint for embedded, regulated, and tactical domains | NSA CNSA 2.0 [4]; FIPS 140-3 module-validation timelines; spectrum-allocation interoperability cycles (years-scale) | External cadences are governance-imposed rather than engineering-imposed; frontier-model capability does not alter regulatory-body throughput | Low | Observed shortening of FIPS validation cycles, ATO renewal cadences, or spectrum-certification timelines below their currently documented years-scale duration |
| PQC Artifact | Affected Protocol | Size/Latency Issue | Downgrade Risk | Mythos-Enabled Analysis | Validation Control | Source |
|---|---|---|---|---|---|---|
| ML-KEM-768 | TLS 1.3 handshake | 1088-byte ciphertext; combined with ML-DSA cert chain crosses IPv6 1280-byte minimum MTU | Hybrid-mode rollback to classical KEM if peer advertises both | Per-bearer handshake-size budget enumeration; round-trip count modeling | Interoperability matrix; path-MTU black-hole regression | FIPS 203 [1] |
| ML-DSA-65 | TLS 1.3 certificate chain | 3309-byte signatures (~35× expansion vs. Ed25519); exceeds initial congestion window | Cert-chain manipulation; signature-substitution probes | Cert-chain-depth enumeration; downgrade-probe generation | Cert-chain-depth red-team; downgrade-protection regression | FIPS 204 [2] |
| SLH-DSA-SHA2-192s | Bootloader and firmware signing | 16,224-byte signatures (~500× expansion); ROM-constrained embedded targets | Signature replay across versioned firmware; OTA rollback exposure | Firmware dependency extraction; per-image ROM/RAM budget analysis | Signed-update verification; rollback-protection test | FIPS 205 [3] |
| ML-DSA cert chain | Cross-Domain Gateway over IKEv2 | Cert chain pushes handshake record past guard’s per-message length ceiling | Guard reject; silent truncation; permissive-failure modes | Cross-domain attack-path reasoning; parse-length boundary mapping | CDG byte-level rule-set red-team; parse-fuzz across PQC handshakes | [9] |
| ML-KEM-768 | Tactical RF narrowband waveform | 1088-byte ciphertext fragments across multiple ~256-byte waveform frames; airtime and reassembly state | Fallback to PSK or classical KEX over RF link under contention | Per-frame airtime budget; hybrid-mode configuration enumeration | Spectrum-certification regression; airtime/reassembly stress test | [1,9] |
| LMS/XMSS | Long-lifetime code signing (firmware, anchors) | Stateful key management; signature size plus state-file overhead | State loss → catastrophic key reuse; signing-state corruption | State-management dependency analysis; signing-call audit | State-management red-team; signing-event audit and replay test | SP 800-208 [18] |
| Scenario | Capability-Transfer Assumption | Throughput Multiplier, m | Compressed Software Path, S/m (year) | Projected Window, T = max(F, S/m) (year) |
|---|---|---|---|---|
| Conservative | Transfer limited to benchmark-adjacent tasks | 2× | 4.0 | 4.0 |
| Central | Moderate transfer to PQC-adjacent sub-tasks | 3× | 2.7 | 2.7 |
| Aggressive | High transfer approaching benchmark-observed deltas | 5× | 1.6 | 2.0 (floor-bound) |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Campbell, R. Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines. Cryptography 2026, 10, 41. https://doi.org/10.3390/cryptography10030041
Campbell R. Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines. Cryptography. 2026; 10(3):41. https://doi.org/10.3390/cryptography10030041
Chicago/Turabian StyleCampbell, Robert. 2026. "Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines" Cryptography 10, no. 3: 41. https://doi.org/10.3390/cryptography10030041
APA StyleCampbell, R. (2026). Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines. Cryptography, 10(3), 41. https://doi.org/10.3390/cryptography10030041

