AI heavyweight Anthropic said earlier this week that its Claude Mythos Preview model had discovered an attack that halves the effective key strength of HAWK, a proposed replacement for the digital signatures that protect online banking and web payments.
The work took about 60 hours and roughly $100,000 in computing costs, against an algorithm that had survived two years and two rounds of expert human review.
BIP-360, the proposal to give bitcoin quantum-resistant addresses, specifies three algorithms NIST has already standardized, and includes several deliberately so users have fallbacks if one is later broken by quantum or classical advances.
What changed is the speed of the classical side. BIP-361, the companion proposal that would freeze more than a third of bitcoin's supply, argues that the migration window is closing because cryptographic attacks are improving by up to 20-fold. Anthropic's results align with that trend, with a model behind it.Read in full https://www.coindesk.com/tech/2026/07/29/bitcoin-s-quantum-plan-assumes-some-algorithms-break-ai-just-weakened-one-in-60-hours
The conclusion does not follow from the premise, this is classic modern-day fearmongering. Just because some new candidate has had a flaw in it discovered, that does not mean that other things will have flaws in them too. Actually,
this case provides ONLY arguments for the side that says we need to take our time with this. If we had picked a signature algorithm already, we could have ended in a HAWK situation -- where a big portion of the Bitcoin network has migrated and it would now be vulnerable or already compromised. People who write these articles and people who interpret them as a sign for their favorite side are some of the most stupid people that exist, they are literally concluding the opposite of the correct conclusion.

Breaking digital signatures, it's ok but let's imagine that they will try doing this with weak signature first before attacking strong ones like Bitcoin private keys.
No, it is not "ok" and you don't know what is a weak signature and what isn't therefore mentioning generic terms from a point of inexperience about attackers is meaningless.
If things can be "doable" with quantum computers and their powerful computational power, they will try to break passwords to steal accounts, money, sensitive personal identity information, digital signatures of developers, applications from desktop to mobile, and more.
Things are not protected by the same types of cryptography, not every algorithm is built the same way. Just because some things can be broken easily in some way, that does not mean that something else can be broken in the same way. Furthermore, systems have different risk tradeoffs. Banks and whatever other stupid examples people bring will be long patched before there is a risk with them.
I believe that Bitcoin private keys will be like the very last ones will be attacked because finding an atom in the universe is not achievable with current technology.
Bitcoin keys and addresses.The size of Bitcoins private key space (2256) is an unfathomably large number. It is approximately 1077 in decimal. For comparison, the visible universe is estimated to contain 1080 atoms.
Stop shitposting in topics that you don't know anything about.
The size of the private key space has nothing to do with the issues that relate to quantum computers and ECDSA, and this example demonstrates that you have just joined here to write another shitpost and have absolutely zero knowledge on the topic. Since the attacker is not doing brute-forcing attacks, the private key space is completely meaningless. A targeted derivation of the corresponding private key from a known public key is not a brute force attack.