A cryptographic algorithm advancing through the final selection round for post-quantum cryptography standards has been eliminated after researchers discovered a fatal vulnerability using a new attack method called Mythos.

HAWK, which had survived extensive peer review and testing over multiple years, fell victim to the attack that exposed a previously undetected weakness in its design. The algorithm was competing as a third-round candidate in the National Institute of Standards and Technology's post-quantum cryptography standardization process, which aims to identify encryption methods resistant to attacks from quantum computers.

The Mythos attack represents a significant validation of emerging cryptanalysis techniques designed specifically to test lattice-based cryptographic systems. HAWK relied on lattice mathematics for its security, a common approach among PQC candidates. The attack successfully identified structural weaknesses that traditional testing methods had overlooked, demonstrating that novel attack vectors can penetrate defenses thought to be sound.

This elimination reflects the rigorous nature of NIST's PQC standardization effort, now in its critical final phase. The selection process deliberately subjects remaining candidates to intense scrutiny. Researchers worldwide contribute attacks and security analyses, with failed candidates providing valuable lessons for those continuing forward.

The HAWK defeat underscores a hard reality in cryptography: theoretical security and practical resilience remain distinct concepts. An algorithm can pass established evaluation frameworks yet fail against newly developed attack methods. This dynamic keeps cryptanalysts and designers in constant competition.

NIST expects to finalize post-quantum standards within the next year, selecting from algorithms that survive this gauntlet. Organizations already face pressure to transition away from vulnerable classical encryption as quantum computing threats become more concrete. The elimination of HAWK and similar candidates strengthens confidence in those that survive, having proven resistant to multiple attack paradigms.

The Mythos attack underscores why NIST conducts multiple rounds of evaluation rather than accepting the first apparently viable candidates. Each