The claim that AES has been broken is extraordinary, and extraordinary claims require extraordinary evidence. Here's what we actually know versus what remains speculation.
What Has Been Confirmed
Very little has been independently verified at the time of writing. The Möbius Bridge attack has not been published in a peer-reviewed journal, and no full technical paper has been made public. This alone is reason for caution.
What IS confirmed:
- Multiple credible cryptographers have acknowledged the claims are being taken seriously
- NIST has not issued an official statement but has accelerated post-quantum migration guidance
- Several major tech companies have moved up their post-quantum deployment timelines
What Remains Unverified
- The complete technical mechanism of the attack
- Whether it works against all AES key sizes (128, 192, 256) equally
- The computational resources actually required
- The identity and credentials of the Mythos research group
- Whether the attack works against AES in all modes of operation (GCM, CBC, CTR, etc.)
Historical Context
AES has faced academic attacks before, and none proved practical:
- Biclique attack (2011): Reduced AES-256 from 2^256 to 2^254.4 operations — still astronomically infeasible
- Related-key attacks: Required the attacker to observe encryptions under related keys — unrealistic in practice
- Side-channel attacks: Attacked implementations, not the algorithm itself — fixable with constant-time code
The Möbius Bridge claim is qualitatively different: it alleges a practical attack on the algorithm itself.
The Skeptic's Case
There are good reasons to be cautious:
- No paper: Legitimate cryptographic breakthroughs are published. The lack of a paper is a red flag.
- Unknown researchers: The cryptographic community is relatively small. Unknown groups making extraordinary claims deserve extra scrutiny.
- Verification takes time: Even if the attack is real, confirming it requires independent reproduction.
The Concern
There are also good reasons to take it seriously:
- Response from the industry: Major companies don't accelerate billion-dollar migration projects based on nothing.
- Mathematical plausibility: The general approach described (exploiting structural properties of the SPN) is a known area of active research.
- Intelligence community interest: The reported interest from national security agencies suggests there may be non-public validation.
What You Should Do
Regardless of whether the Möbius Bridge turns out to be everything claimed, the security actions recommended are good practice anyway:
- Enabling strong 2FA protects against credential theft
- Using a password manager prevents cascade compromises
- Post-quantum encryption is coming regardless — early adoption is prudent
- Monitoring financial accounts is always wise
The worst case of over-preparing is better security. The worst case of under-preparing is a data breach.
Assess your exposure: Take the free risk assessment to understand your specific vulnerability profile.
