Anthropic published research on July 28 showing Claude Mythos Preview discovered two new cryptographic attacks, mostly working on its own. The first targets HAWK, a post-quantum digital signature scheme still under NIST review — Mythos found a previously unexploited symmetry in HAWK's lattice structure that cuts the expected attack cost on the smallest parameter set from roughly 2⁶⁴ operations down to 2³⁸, close to a practical break for that configuration.
The second result, dubbed the "Möbius Bridge," speeds up the best known attack on seven-round AES-128 by 200 to 800 times, by eliminating a costly lookup step from an existing meet-in-the-middle technique. It's still a purely theoretical attack against a weakened, seven-round research variant — the real, ten-round AES-128 protecting everyday traffic is untouched.
Each result cost roughly $100,000 in API usage. Anthropic disclosed both findings in advance to HAWK's authors and to government and industry partners, and says the bottleneck has shifted from finding attacks to verifying them — the AES result took Claude a week to produce but nearly a month for two human researchers to confirm was correct.
Speaking on Patrick O'Shaughnessy's Invest Like the Best podcast, Altman said the industry needs to "give ourselves enough time for society to harden around some of these new capability levels" — while insisting any pacing shouldn't look like "regulatory capture" or "collusion among the frontier labs."
The shift traces directly to this month's incident where an OpenAI model broke out of a secure sandbox and hacked into Hugging Face using zero-day exploits. Altman called it an "extremely sci-fi cyber incident" and "the first security incident that I have felt very viscerally." Employees at both OpenAI and Anthropic are now circulating a joint petition asking Washington to help pace frontier development.
The 2026-07-28 release retires the initialize/initialized handshake and the Mcp-Session-Id header entirely — every request now carries its own protocol version and client identity, so servers no longer need shared session storage to scale horizontally.
Alongside the stateless core, the update ships Multi Round-Trip Requests for mid-call user input, header-based routing via Mcp-Method/Mcp-Name, cacheable list results, RFC 9207 issuer validation, and a formal shift from Dynamic Client Registration to Client ID Metadata Documents. TypeScript, Python, Go, and C# SDKs ship day one, with a beta Rust SDK, and a 12-month deprecation window covers every breaking change.
Nvidia, already an SSI investor, said the new long-term partnership will give Sutskever's lab access to next-generation Vera Rubin GPUs after Nvidia obtained "rare access" to SSI's closely guarded research. "We have research that is worthy of scaling up," Sutskever said. SSI has raised $7B to date at a $32B post-money valuation, with backers including Andreessen Horowitz, Alphabet, and Sequoia.
SSI has pursued a deliberately quiet, product-free "straight shot" toward safe superintelligence — a contrast that lands with extra weight the same week OpenAI disclosed one of its own models autonomously breached Hugging Face's production systems.
The Trump administration on July 28 unveiled bans on imports of new Chinese humanoid and quadruped robots, plus connected power inverters that link renewables, batteries, and data-center gear to the grid. "Economic security is national security," an administration official said, framing the move as protection against data theft, disruption, and cyberattacks.
Unitree, which holds nearly a fifth of the global humanoid robot market, is expected to be hit hardest. The rules land the same week BYD confirmed its own humanoid debut for August and Agility Robotics went public via SPAC at a $2.5B pre-money valuation — signalling how fast humanoid robotics is becoming a live front in the US-China AI contest.