AI math breakthroughs push crypto to weigh a new security threat beyond quantum computing

AI math breakthroughs push crypto to weigh a new security threat beyond quantum computing

N
News Editor
2026-10-08 02:31:00
A warning from Ethereum Foundation researcher Justin Drake and a same-day release from OpenAI have sharpened a question the crypto industry has long framed around quantum computing: what if the break comes earlier, and from AI-driven mathematics instead? On Oct. 7, Drake urged the blockchain sector to prepare for “bunker mode,” arguing that rapid advances in AI math research could produce a classical algorithm capable of breaking ECDSA, the signature scheme used across Bitcoin and Ethereum, without waiting for a large-scale quantum computer. His post landed as OpenAI published 722 mathematical manuscripts spanning 372 problem families. The article ties that release to a broader 2026 timeline that includes work on the unit distance problem, 10 open problems in mathematics and theoretical computer science, a claimed counterexample to the Navier-Stokes equations, and more than 100 long-unsolved problems reportedly solved by an internal model trained only 24 days earlier. Vitalik Buterin responded hours later, cautioning users not to rush funds into new wallets while also saying there is a “good chance” AI-accelerated math could materially weaken lattice-based post-quantum cryptography within two years. The stakes are large: according to Glassnode research cited in the piece, about 6.04 million BTC, or 30.2% of issued supply, already have public keys exposed on-chain.

Rapid gains in AI mathematics are forcing the crypto industry to revisit a security question it has usually framed around quantum computing.

On Oct. 7, Ethereum Foundation core researcher Justin Drake posted a long thread on X that opened with a blunt line: “I call on the entire blockchain industry to calmly start preparing for ‘bunker mode.’”

That same day, OpenAI publicly released 722 mathematical manuscripts covering 372 families of problems, including answers to hundreds of long-unsolved questions. The article says an internal model that had been training for only 24 days had already produced breakthroughs across nearly every branch of mathematics. Two weeks earlier, it had also produced a counterexample for the Navier-Stokes equations, one of the seven Millennium Prize Problems.

Drake’s warning rests on that chain of evidence. If AI can solve problems in 24 days that human mathematicians could not crack over decades, he argued, the time needed to find a classical method for breaking the signature systems underneath cryptocurrencies may be much shorter than the industry assumed.

About 10 hours later, Vitalik Buterin responded on X. He first urged restraint, saying, “I do not recommend that anyone rush to move funds to a new wallet today.” He then added a more unsettling point: ECDSA may be breakable, and lattice-based cryptography, the post-quantum fallback many in the industry have counted on, has a “good chance” of being materially weakened within two years.

Why ECDSA sits at the center of crypto security

Drake’s argument centers on ECDSA, the Elliptic Curve Digital Signature Algorithm. Every Bitcoin and Ethereum transaction signature depends on it.

In that model, a private key generates a public key, and the public key is hashed into an address. The security of the broader crypto asset system depends on the one-way nature of that path. Reconstructing a private key from a public key is considered infeasible with current computing power.

For years, the industry’s security narrative has revolved around “Q-Day,” the point at which a sufficiently powerful quantum computer could use Shor’s algorithm to solve the discrete logarithm problem in polynomial time and reverse the one-way structure behind ECDSA. That moment has often been treated as a decade away, or longer.

Drake outlined a different threat model. In his view, no quantum computer is required. AI-driven mathematical superintelligence could discover a new classical algorithm that breaks elliptic curve cryptography on conventional hardware, much as the fast Fourier transform changed the complexity of multiplication from O(n²) to O(n log n).

The key point in his reasoning is that elliptic curves have rich mathematical structure. The richer the structure, the larger the mathematical attack surface. Hash functions are different by design: they aim to strip away exploitable structure and make outputs look like random noise. Drake framed that contrast with a pointed question: “Is a 64-byte ECDSA signature too good to be true?”

His worst-case estimate is that a large GPU cluster could recover private keys from exposed public keys in roughly a week. The article describes that figure as an engineering-scale estimate extrapolated from the pace of AI math progress.

A 2026 timeline of accelerating AI math results

The article backs Drake’s view with a fast-moving 2026 timeline.

In May 2026, OpenAI said an undisclosed model had refuted the unit distance conjecture proposed by mathematician Paul Erdős, a problem that had stood for nearly 80 years. What surprised mathematicians was not only the result but the route: the AI found a line of proof humans had not tried.

On Aug. 1, OpenAI released results from its Astra model on 10 open problems in mathematics and theoretical computer science. Each had been stalled for at least a decade. The set spanned high-dimensional sphere packing, coding theory, group theory, quantum complexity, and lattice cryptography. The work ran to 249 pages, and every proof was formally verified in Lean 4 so a machine could independently check correctness. The total cost, measured at API pricing, was about $2,000 for all 10 problems.

On Sept. 8, OpenAI announced that an internal model had produced a counterexample for the Navier-Stokes equations, one of the seven Millennium Prize Problems. A correct solution would carry a $1 million prize. The article notes that the result had not yet been independently verified, but the shock had already spread through the mathematics community.

On Sept. 21, OpenAI disclosed that an internal model that began training on Aug. 28 had solved more than 100 long-unsolved open problems in just 24 days, spanning nearly every branch of mathematics. Even OpenAI’s own mathematicians were surprised by the pace, according to the article. The company also set up an independent advisory group at the Institute for Advanced Study in Princeton, with members including Edward Witten and Timothy Gowers.

Then on Oct. 7, the same day Drake issued his warning, OpenAI formally released 722 manuscripts across 372 problem families. On average, the article says, each result cost about as much compute as three hours of ChatGPT Pro usage.

Placed side by side, the progression is stark: one conjecture in May, 10 hard problems in August, more than 100 open problems solved in 24 days in September, and results across 372 problem families in October. Drake’s conclusion was direct: “Mathematical superintelligence has arrived.”

The article also points beyond OpenAI. A research version of Anthropic’s Claude, not yet released, reportedly made major progress on the Riemann Hypothesis, another Millennium problem. Google DeepMind’s system has already reached gold-medal level in the International Mathematical Olympiad. The jump in AI math capability is presented not as a one-company anomaly but as a broader shift.

About 6.04 million BTC already have exposed public keys

If ECDSA is at risk, the next question is how much value is actually exposed.

According to Glassnode research cited in the article, about 6.04 million BTC, or 30.2% of issued supply, already have public keys exposed on-chain. The piece splits that exposure into two categories.

The first is “structural exposure,” affecting about 1.92 million BTC. In these cases, the vulnerability comes from the address type itself rather than user behavior. The largest share comes from Bitcoin’s early P2PK, or Pay-to-Public-Key, format, where the public key is written directly into the locking script and remains permanently visible on-chain.

Satoshi Nakamoto’s roughly 1.1 million BTC are said to be stored almost entirely in this format, spread across about 22,000 separate outputs. The article says those coins are not expected to move, the private keys may already be lost, and Satoshi may no longer be alive. That makes them both the most valuable honeypot on the blockchain and one of the least recoverable pools of assets.

The second category is “operational exposure,” affecting another roughly 4.12 million BTC. Those coins were originally protected by hashing, but public keys were later exposed on-chain through address reuse or specific custody operations. Of that total, about 1.66 million BTC belong to exchange balances, or roughly 40% of all operationally exposed assets.

The distinction matters. Operational exposure can be fixed by moving coins to fresh addresses. Structural exposure is permanent. Coins in P2PK addresses remain potential targets unless the holder moves them, and the article argues that Satoshi’s coins almost certainly will not be moved.

If ECDSA were broken, the attack path would be straightforward: scan the chain for exposed public keys, compute the corresponding private keys, sign transactions, and move the funds. The largest target would be Satoshi’s 1.1 million BTC, which the article values at more than $90 billion at current prices.

Buterin’s warning goes beyond ECDSA

For years, the standard answer to quantum risk in crypto has been a migration to post-quantum cryptography. The leading candidate has been lattice-based cryptography, whose security rests on the hardness of shortest vector problems in lattices and is widely viewed as resistant to quantum attacks.

NIST published federal standards based on lattice cryptography in 2024, including ML-DSA and ML-KEM. The Ethereum Foundation also formed a dedicated post-quantum security team in January this year.

But Buterin wrote on Oct. 7 that AI-accelerated mathematical research could deal a “material blow” to the practical security of lattice-based systems within the next two years. His wording, “good chance,” was stronger than a distant theoretical possibility.

His logic goes one layer deeper than Drake’s. If the next two years of AI-driven math progress compress what would otherwise have taken 50 years, then not only elliptic curves but also the assumptions behind lattice cryptography could come under pressure. As he put it: “If there are skeletons hiding behind both elliptic curves and lattices, humans may not be smart enough to find them, but robots soon will be.”

In other words, the industry’s Plan B for quantum computing may itself be vulnerable to AI mathematics.

Buterin said Ethereum’s roadmap has gradually shifted over the past year toward “pure hash-based cryptography,” including replacing BLS consensus signatures with leanXMSS and using STARK-based commitment schemes. These approaches rely on the security of hash functions, which are viewed as harder to attack because they lack rich exploitable structure.

He also stressed a practical point: “A botched wallet migration causing loss of funds is more real than a cryptographic attack that has not happened yet.” In crypto, user error still causes losses more often than cryptographic breaks do.

What “bunker mode” would look like

Drake’s proposed response is simple in principle: move assets to fresh addresses whose public keys have never appeared on-chain, meaning addresses that have never signed a transaction. If the public key remains hidden behind a hash, an attacker has no direct target.

He outlined three steps:

  • large institutions and experienced holders move first and set an example;
  • after each signed transaction, move the remaining funds again to a fresh address;
  • keep the process slow and controlled, with no panic-driven rush.

He specifically named Binance, Robinhood, Bitfinex, and Tether as institutions that should consider strengthening cold-wallet security practices. He also said a safe exit from bunker mode would require “post-AI cryptography,” meaning cryptographic systems that remain reliable even after AI becomes a primary engine of mathematical research.

The logic is internally consistent. The practical obstacles are just as clear.

Coordinating a migration across millions of users is not something the crypto industry has ever successfully done. The Ethereum DAO fork is cited as one of the largest examples of community coordination, and even that was a code change on a single chain. Drake is talking about a behavioral shift across the whole sector: Bitcoin, Ethereum, and every chain that depends on ECDSA.

For Bitcoin, the challenge is even more structural. Ethereum has a tradition of roadmap iteration pushed by a foundation. Bitcoin governance is far more conservative. The article says BIP-360, a proposal to introduce quantum-resistant address types, is under discussion, but every soft fork in Bitcoin’s history has taken years from proposal to activation. The harder problem is that ancient coins in P2PK addresses, including Satoshi’s, cannot be moved by anyone else.

Drake himself acknowledged the trade-off: “A rushed migration would cause more harm than the threat it is trying to prevent.”

The industry has long asked when quantum computers will arrive. In this discussion, the question shifts to something else: when will the next mathematical breakthrough land?

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.