South Korea has certified a new hybrid post-quantum cryptography (PQC) encryption module at a time when AI has exposed weaknesses in one of the world's leading post-quantum encryption candidates. According to TechTimes, cybersecurity company ITCEN PNS received KCMVP (Korea Cryptographic Module Validation Program) certification for EdgeCrypto v4.2, a cryptographic library that combines traditional encryption with quantum-resistant algorithms. The milestone came just days after Anthropic's Claude Mythos Preview AI model discovered a critical mathematical flaw in the HAWK digital signature algorithm in approximately 60 hours, leading HAWK's developers to withdraw it from the U.S. National Institute of Standards and Technology (NIST) standardization process.
The HAWK vulnerability highlighted how AI is accelerating cryptographic research. Using semi-autonomous reasoning, the AI identified a previously unnoticed mathematical symmetry that significantly weakened HAWK's security, effectively reducing its security margin and eliminating its competitiveness as a future post-quantum standard. While the flaw does not affect NIST's finalized post-quantum standards—ML-KEM, ML-DSA, and SLH-DSA—the discovery reinforces concerns that even promising cryptographic algorithms can contain hidden weaknesses that advanced AI systems may uncover far more quickly than human researchers.
South Korea's newly certified EdgeCrypto v4.2 addresses this uncertainty through a hybrid encryption approach. Rather than relying solely on a new post-quantum algorithm, the software runs conventional public-key cryptography alongside NIST-standardized post-quantum algorithms. This means that if either the classical or post-quantum algorithm is compromised, the other continues to protect encrypted communications. The certification also enables the software to meet South Korea's mandatory security requirements for use in government agencies, defense systems, public administration, financial networks, telecommunications, and other critical infrastructure.
The incident underscores a broader shift in cybersecurity strategy. Instead of assuming that newly standardized algorithms will remain secure indefinitely, organizations are increasingly adopting crypto agility—the ability to replace or combine cryptographic algorithms as new threats emerge. As AI becomes more capable of analyzing complex mathematical structures, experts expect cryptographic systems to evolve more rapidly, making hybrid encryption, continuous security testing, and flexible migration strategies essential for protecting sensitive data in the quantum computing era.