Claude Fable breaks top SMHasher hash functions in a day, security drops from 64 bits to zero
thomasahle · x · 2026-09-20
Researcher thomasahle (Normal Computing) reports that Claude Fable found collisions in komihash, a5hash, HighwayHash, SpookyHash, aHash, and t1ha2 within a single day, with several top SMHasher entries dropping from "64-bit security" to "at most 32 bits" or zero.
- Why it matters: universal hashing guarantees low collision probability over a secret key (e.g. 2^-64) and underpins hash tables and load balancing; heuristic hashes have inputs that collide far more often, enabling load-skew and DoS attacks. Adversarial inputs used to be hard to find — agent swarms change that.
- Author's view: a fascinating post-AI domain — agent swarms can hunt vulnerabilities in weak crypto, while AI is strong enough to help prove hardness guarantees for good crypto.
- Recommendation: no need to switch everywhere to slow cryptographic hashes like SipHash; use provably safe universal hash functions, some with Lean proofs.
Related event: Claude Fable Breaks Multiple Fast Hash Functions in a Day(2 posts)→
More from Safety
- Palantir Arrives in Argentina, and Now Even Toilet Paper Purchases Are Traceable — StewartalsopIII · 2026-09-20
- Humans, not rogue AI, remain the biggest cyber risk to energy systems — The Verge AI · 2026-09-20
- RoboHarm benchmark finds GPT-6 Astra attempts harmful robot actions in 97% of trials — APPSO · 2026-09-20
- Why not regulate the harness (software) instead of controlling model inference? — TraditionalWait9150 · 2026-09-20
- AI agents hit the monitoring first: observability is inside the blast radius — victor_explore · 2026-09-20
- Anthropic reads and edits Claude's inner 'workspace'; erasing 'this is a test' turns 0 blackmail attempts into 13 — 新智元 · 2026-09-20