July 28, 2026

The lockpick heard round nerd-dom

Anthropic publishes a practical key-recovery attack on HAWK-256

Anthropic says it can actually crack a once-fancy lock, and commenters are split between “old news” and “okay, that’s huge”

TLDR: Anthropic published code showing it can realistically recover secret keys from HAWK-256, turning a theoretical weakness into something much more concrete. Commenters are split between “this was already broken” and “practical proof changes everything,” which is why the release is getting attention.

Anthropic just dropped code and research showing a practical way to recover keys from HAWK-256, a digital security system that’s supposed to help prove something is real and untampered with. In plain English: they didn’t just say a lock has weaknesses — they showed how to actually open it. And while the GitHub repo itself is dry, tiny, and very much in “research artifact, not maintained” mode, the real sparks are flying in the community chatter.

Over on Hacker News, the vibe is classic internet tech drama: one camp is basically shrugging and saying, “Wasn’t this family of systems already considered broken?” That’s the energy behind the blunt hot take from commenter alexnewman, who boiled it down to: yes, maybe the flaw was known in theory, but this matters because it’s practical now. And that word — practical — is doing a lot of work. In security, the difference between “someone might break this someday” and “here’s code that does it” is the difference between a rumor and a scandal.

The humor here is subtle but savage. The repo has 11 stars, 1 watcher, 2 forks, which gives the whole thing a weird indie-drama feel: world-shaking cryptography news, posted like a side project with almost no fanfare. That contrast is the joke. The hottest reaction isn’t panic — it’s that deliciously nerdy mix of “called it”, “show me the benchmark”, and “okay, fine, this is cooler than I expected.”

Key Points

  • Anthropic published a public GitHub repository called cryptography-research-demo.
  • The repository is labeled as a research artifact and explicitly says it is not maintained and not accepting contributions.
  • The repository contains cryptanalysis code accompanying associated papers.
  • Its contents are divided into three independent components: AES, HAWK, and LEA.
  • The repository is licensed under Apache 2.0 and included repository metrics showed 11 stars, 2 forks, and 1 watcher.

Hottest takes

"discussion / article" — joshka
"this class was broke" — alexnewman
"cool cause practical" — alexnewman
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.