The end of static security: AI breaks the cryptographic cycle
An AI system discovered a vulnerability in 60 hours that experts ignored for years, forcing the withdrawal of the post-quantum scheme HAWK.
October 1, 2026 · 4 min read
TL;DR: AI has reduced the discovery of cryptographic flaws that once took years to mere days. This invalidates long-term cybersecurity strategies, forcing companies to adopt continuous and automated audits.
The era of static security is over
For nearly half a century, cybersecurity has been governed by the principle of set and forget. Since the introduction of the RSA algorithm in 1977, global digital infrastructure has rested on cryptographic foundations that, while not invulnerable, exhibited predictable and slow degradation. However, the ecosystem has changed drastically. On July 28th, an artificial intelligence model managed to identify in just 60 hours a critical vulnerability in HAWK, a lattice-based post-quantum signature (PQC) scheme that had passed two years of rigorous reviews by human experts. This event is not a simple technical glitch; it is the definitive signal that the paradigm of static security has collapsed.
Historically, cryptography moved at a geological speed. RSA, for example, took nearly two decades to become the de facto standard for web security after its publication. This slowness allowed standardization bodies to deliberate for years and companies to plan migrations in five-year cycles. Security was a durable consumer product; what was bought today was considered adequate for the next decade. That certainty has vanished.
The collapse of discovery time
The importance of the HAWK case—which resulted in the immediate withdrawal of the algorithm from standardization processes—lies in the radical alteration of the economics of vulnerability discovery. Traditionally, finding a cryptographic weakness required a massive investment of specialized human talent, years of academic research, and computational capacity dedicated exclusively to theoretical attacks. AI has democratized and accelerated this process at a marginal cost near zero.
As noted by the EU-Startups analysis, when the time required to unearth a vulnerability falls from years to days, but the time required to apply patches or migrate systems in complex organizations remains in years, an unsustainable security gap opens up. This temporal mismatch is the new battlefield. While government and corporate organizations celebrated the acceleration of deadlines for the transition to post-quantum cryptography (such as U.S. Executive Order 14412, which set targets for 2030 and 2031), the reality is that those deadlines may already be obsolete. The arithmetic is uncomfortable: the lifespan of a cryptographic premise is now, plausibly, shorter than the duration of a standard migration project. We are facing a race where defense is not only slower, but is losing the advantage of predictability.
The new threat: incessant auditing
The risk transcends theoretical algorithms and moves to real-world implementation. Modern companies operate on a mountain of technical debt: expired certificates, weak cryptographic keys, legacy network configurations, and hardcoded credentials in code repositories. In the past, auditing every corner of an infrastructure was a prohibitive task due to its cost and complexity. Today, AI allows attackers to perform an incessant and automated audit of any organization's attack surface.
Unlike traditional attacks, which relied on human cunning to find an entry point, AI can perform a continuous scan of configurations, looking for deviations from best practices with surgical precision. Companies that rely on annual audits are operating in a timeframe that no longer exists. AI does not get tired, does not make fatigue-related errors, and, most importantly, can scale its attacks to thousands of organizations simultaneously. If a company has a legacy system that uses a weak cryptographic standard, AI will identify it before the IT team even has the next security update scheduled.
What should organizations do?
Faced with this new scenario of accelerated uncertainty, the strategy must shift toward dynamic resilience:
- Abandon complacency: Post-quantum migration plans designed for 2030 must be reviewed with a sense of urgency. Planning must be modular and agile, allowing for the replacement of cryptographic components without needing to rewrite the entire system architecture.
- Defensive automation: If attackers employ AI to audit, organizations are obligated to implement continuous and automated auditing systems (Continuous Security Monitoring). Vulnerability detection must be a real-time process, not a periodic event.
- Reduce the attack surface: Complexity is the greatest enemy of security in the age of AI. Fewer legacy systems mean fewer blind spots where AI can operate. Technological consolidation must stop being a choice of efficiency and become a survival priority.
- Cryptographic agility: It is imperative to adopt frameworks that allow for "cryptographic agility," that is, the ability to change algorithms or security parameters without altering software functionality.
In conclusion, the HAWK case is a reminder that security is no longer a state, but a continuous process of adaptation. Companies that fail to reduce their gap between threat discovery and response capability are destined to operate in an environment of permanent vulnerability.