We identify and experimentally validate a new weak key class for AES-128 and AES-256, arising from the unique additive subgroup of order 8 in GF (2⁸). Orbit-0 = 0x00, 0x14, 0x62, 0x76, 0x89, 0x9D, 0xEB, 0xFF is closed under XOR and arises from the Weyl group action G = Z₂ x Z₈5 x (Z₂) ² on GF (2⁸) (DOI: 10. 5281/zenodo. 20418781). Keys whose all 16 bytes belong to Orbit-0 form a weak key class of size 8¹6 = 2⁴8, exhaustible on a single RTX 4090 in ~8 hours. Experimental verification over 16. 7 million keys confirms zero decryption errors and negligible ciphertext bias (delta < 0. 001). The class includes the all-zero and all-one keys. We also report a previously undescribed AES KeySchedule property: non-uniform multiplicative order distribution, with order-84 bytes at 2. 7x random rate.
Yao-Kai Kao (2026) studied this question.