Intro
On September 5, 2026, a proof appeared that had been ninety years in the making. It was the Navier-Stokes existence and smoothness problem, one of the seven Millennium Prize Problems. Human mathematicians had not solved it. An AI system did, according to a detailed report on HackerNoon. Not a single model, but roughly ten thousand agents running concurrently. They exchanged nearly 2.7 million messages and burned through compute at a cost OpenAI’s Chief Research Officer described as in the millions of dollars. The whole process took eighty-eight hours, followed by another seventeen to formalize the proof in the Lean verification system. OpenAI published the result on September 8, 2026.
The headline is not that AI is now smarter than human mathematicians. The headline is something quieter and far more consequential for anyone who manages a server, a website, or a database. When you can define what a correct answer looks like, and you can afford enough parallel search, problems that resisted a century of human attention can fall. In cryptography, the verifier is brutally simple: you either recover the key or you don’t. You either decrypt the message or the decryption function throws an error. There is no partial credit.
This is where AI agents cryptanalysis stops being a theoretical paper topic. The field has always rested on one critical assumption about its attackers: that they are human, scarce, and slow. They are limited by the specific tools and intuition their training gave them. The GPT-6 Astra result, and the class of problems it represents, suggests that assumption is now a liability. The attackers we need to plan for are not lone geniuses. They are armies of cheap, parallelizable agents that can be spun up for a specific task, like trying to factor a large number or find a shortcut in a lattice, and then discarded. Their cost is a function of electricity and silicon, not PhD salaries. The gap between what is “impossibly expensive” and what is “impossible” has always been where cryptographic risk lives. That gap just got narrower for anyone with a cloud budget.
Background: The Algorithms You Actually Depend On
Every cryptographic system in use today rests on a bet. The bet is this: solving a specific mathematical problem is cheap if you know the secret, and impossibly expensive if you do not. Not impossible. Impossibly expensive. Human civilization is built in the gap between those two words. The vast majority of what you run, from the padlock icon in your browser to the VPN tunnel protecting your server’s SSH, relies on computational security. This is a claim about your attacker’s budget, not the laws of physics. It says breaking the system would cost more than the value of the data or more than any attacker can reasonably spend. The other kind, information-theoretic security, means breaking the system is impossible regardless of computation, because the ciphertext simply does not contain enough information. Outside of one-time pads and some niche quantum key distribution, almost nothing you deploy has this.
Your current stack almost certainly leans on three classical algorithms. RSA starts by multiplying two enormous primes. Multiplying takes milliseconds. Pulling the primes back apart from the product takes longer than the age of the universe with every classical technique we know. Diffie–Hellman lets two parties agree on a shared secret over a public channel by having each raise a public base to a private number. An eavesdropper must recover the private exponent from the public result, solving the Discrete Logarithm Problem. Elliptic Curve Cryptography (ECC) runs the same discrete log bet on a more efficient mathematical surface. A 256-bit ECC key offers roughly the same classical security as a 3072-bit RSA key. The trap is that against a quantum attacker, the smaller key is a liability, it means fewer qubits are required. Migrating from RSA to ECC buys you nothing against quantum.
Here is a concrete analogy for a site owner. Think of RSA encryption like putting a message in a safe and locking it with a combination that’s the product of two giant prime numbers. Anyone can look at the safe (the public key), but only someone who can factor that huge number back into its two primes (the private key) can open it. For decades, we’ve assumed that factoring this particular number would take longer than the sun will burn. That assumption is the only thing standing between your data and an attacker. The “impossibly expensive” part of the bet is the entire foundation.
The quantum threat changes the math of that bet. Shor’s algorithm can factor large integers and solve discrete logarithms in polynomial time on a sufficiently large, error-corrected quantum computer. It turns an “impossibly expensive” classical problem into one that is merely “very hard engineering.” For this reason, NIST finalized its first set of post-quantum cryptography (PQC) standards in 2024. These are CRYSTALS-Kyber for key encapsulation (establishing a shared secret) and CRYSTALS-Dilithium for digital signatures. They are built on different mathematical problems, primarily lattice-based ones like the Learning With Errors (LWE) problem, which are believed to be resistant to both classical and quantum attacks. There is also SPHINCS+, a hash-based signature scheme that provides a conservative fallback. These are the algorithms you will be migrating to. The problem, as highlighted in the original analysis (opens in new tab), is that this migration is a massive undertaking, and the timeline for a relevant quantum computer may be shorter than the time it takes organizations to complete it.
What’s Happening Now: AI Agents in Cryptanalysis
The Navier-Stokes result matters for cryptography for a specific reason, and it is not the proof itself. It is that ten thousand agents, exchanging 2.7 million messages over 88 hours, solved a problem by parallel search where each candidate was checked cheaply by software. Lean verified every step mechanically. No human had to read each attempt. That is the model of attack that is new.
Cryptographic problems have a verifier that is even simpler than a proof assistant. You either decrypt the ciphertext or you do not. You either recover the private key or you do not. The check is a single function call, not a seventeen-hour formal verification. The original analysis (opens in new tab) makes this point directly: in cryptography there is no ambiguity about what a correct answer looks like, and that makes it an ideal target for exactly the kind of parallel search that just solved a Millennium Prize Problem.
What AI agents have actually done in cryptanalysis so far is quieter than the headline suggests. There is real work on AI-assisted lattice reduction, where neural networks prune the search space for BKZ-style attacks. There are agent systems that optimize side-channel analysis, guessing partial key bits from power traces or timing. There are heuristic search improvements for key recovery on reduced-round ciphers. None of it has broken a deployed system yet. But the trajectory is the same one the mathematics community just experienced: attack surfaces that were explored by a handful of human researchers are now being explored by thousands of parallel agents that never sleep.
Here is the analogy a site owner will recognise. A burglar used to try one lock pick at a time. Now imagine ten thousand hands, each trying a slightly different pick, and an automated system that records which ones show any give and immediately tries variations on those. The lock technology is unchanged. The number of hands, and the coordination between them, is what changed.
The compute cost is the one honest constraint left. The Navier-Stokes run cost millions of dollars. That is not something a random attacker on the internet can afford. But costs for AI inference have been falling for years, and agents scale horizontally in a way that human cryptanalysts never could. My expectation, and this is my read rather than a published conclusion, is that the first practical AI-agent-assisted break will not target RSA or ECC directly. It will target what agents are best at finding: weak randomness, reused nonces, and side channels in half-configured TLS stacks. The search is what gets cheaper. The sloppy implementation is what gets found.
What AI Agents Cryptanalysis Means in Practice: Q&A
Three questions keep coming up in the hosting forums I read, and the honest answers are shorter than most people expect.
Q: Should I replace my RSA keys with post-quantum algorithms right now?
A: If you are storing data that needs to stay confidential for more than five to seven years, start planning now. NIST finalized CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for signatures in 2024, and the migration guides are public. This is not a weekend project, especially if your stack touches TLS, VPNs, or hardware security modules. I have rotated keys across a dozen customer VPS boxes before, and even that simple job took coordination. Post-quantum migration touches every place a key is generated, stored, or exchanged. Start with inventory. Count your certificates, your SSH keys, your IPsec tunnels, your code-signing keys. That count is your exposure surface.
Q: What is the real risk timeline?
A: Cryptographically relevant quantum computers are still years out, possibly a decade. The AI agent risk is closer. You do not need a quantum computer to improve lattice attacks if you can throw ten thousand agents at the problem and afford the bill. The Navier-Stokes run cost millions, but inference costs fall fast, and the same coordination pattern applies to cryptanalysis. The combination of both, quantum hardware maturing while agent search gets cheaper, is what should change your planning horizon. The source writeup (opens in new tab) makes the same point: the old assumption that attackers are scarce and slow has expired.
Q: Is AES-256 still safe?
A: Symmetric ciphers take a much smaller hit from quantum algorithms. Grover’s search effectively halves the key strength, so AES-256 drops to roughly 128-bit classical security. That is still plenty for now. The asymmetric side, RSA, Diffie-Hellman, and ECC, is where the floor falls out. A quantum machine running Shor’s algorithm breaks those outright, and AI agents can accelerate the surrounding search without any quantum hardware at all.
What to Expect Next
NIST’s migration timeline is public. The deadlines are not hypothetical. Government agencies and their contractors have firm dates, and finance and healthcare usually follow close behind because they handle data that stays sensitive for decades. I expect the first forced migrations to be ugly in the places nobody prepared: legacy payment terminals and medical devices running chips that barely have room for the current TLS handshake.
Hybrid key exchange will carry most of us through the transition. The idea is to run a classical algorithm and a post-quantum algorithm in parallel, so an attacker has to break both to recover the session key. Cloudflare has been doing this in production TLS for a while, and the handshake works on ordinary browsers. It is not a permanent answer. It roughly doubles the size of the key exchange and it inherits the weakest link problem if an implementation gets sloppy. But as a stopgap it is the difference between migrating under pressure and migrating after a breach.
The cost problem is real, and it will hit small operators hardest. CRYSTALS-Kyber public keys are about four times the size of an RSA-2048 key, and CRYSTALS-Dilithium signatures run to a few kilobytes instead of a few hundred bytes. On a modern server that is noise. On a $15 VPS with a constrained CPU, or on an IoT device with 256 KB of RAM, it changes the math. I have customers running older cPanel boxes where the TLS handshake is already the slowest part of the connection. Doubling that work is not free, and the cheapest hardware will feel it first.
My expectation, and I want to be clear this is a guess rather than a forecast, is that AI agent capability grows faster than most organizations migrate. The Navier-Stokes result showed what coordinated parallel search can do when the verifier is cheap. Cryptographic verification is even cheaper: a decrypted message either makes sense or it does not. The source article (opens in new tab) makes the same argument about the old attacker assumptions expiring. Defensive migration is a slow, bureaucratic process involving inventory spreadsheets and change windows. Offensive research is a compute bill. Those two speeds do not match, and that gap is where the risk concentrates.
Closing: A Concrete Next Step for the Reader
The gap between offensive research speed and defensive migration speed does not close by reading more articles. It closes one server at a time, and it starts with a command you can run this afternoon.
Log into any machine you manage and run openssl list -public-key-algorithms. The output is a list of every public-key algorithm your OpenSSL build supports. On a default install you will see RSA, DSA, DH, and EC entries. Count how many of them your production systems actually use. Most people I walk through this find that their TLS stack, SSH keys, and VPN certificates run on RSA or ECC alone. That count is your exposure surface.
The number itself is not a reason to panic. It is the starting point for a migration conversation, because every one of those algorithms has a post-quantum counterpart in the NIST standards and none of them swap in with a one-line config change. If your SSH key is RSA-2048, moving to a post-quantum or hybrid option means regenerating keys, updating authorized_keys files, and touching every CI pipeline that connects to the box. That is not a weekend project. It is a budgeted project, and it starts with knowing the scope.
Think of it the way you would inventory a building before an insurance renewal. You do not need the replacement cost of every chair in the office. You need a list long enough that the policy actually covers the structure. This is the same exercise. The command gives you the list. The migration plan gives you the coverage.
The source article (opens in new tab) that started this thread argues that the old assumptions about attackers, that they are scarce and slow and tool-limited, have expired. I would add a mundane corollary from running servers for a living: your key inventory is probably older than that news. I have logged into boxes where the SSH host key was generated on the same day the OS was installed, and the OS was six years old. That key has no idea a Millennium Prize problem just fell to ten thousand AI agents.
Once you have the count, take two documents to your team. NIST’s migration guide (opens in new tab) lays out the algorithm transition timeline in plain language, and Cloudflare’s post-quantum TLS rollout writeup (opens in new tab) shows what the migration looks like when it is done at internet scale. You do not need to solve the whole problem this week. You need to start the conversation with a number in your hand instead of a vague sense of unease.