AI math advances put crypto security under scrutiny as Drake and Buterin warn on ECDSA and post-quantum assumptions

AI math advances put crypto security under scrutiny as Drake and Buterin warn on ECDSA and post-quantum assumptions

N
News Editor
2026-10-08 02:34:09
Ethereum Foundation researcher Justin Drake warned on Oct. 7 that the blockchain industry should begin preparing for a "bunker mode" scenario after a rapid series of AI-driven math breakthroughs. His concern was tied to OpenAI’s release of 722 mathematical manuscripts spanning 372 problem families, alongside claims that an internal model trained for just 24 days had produced results across nearly every branch of mathematics. Drake argued that if AI can compress decades of mathematical progress into weeks, the time needed to discover a classical attack on elliptic-curve cryptography may be far shorter than the industry has assumed. Vitalik Buterin responded about 10 hours later, saying users should not rush to move funds into new wallets immediately. At the same time, he said ECDSA could be broken and that lattice-based cryptography, widely treated as crypto’s post-quantum fallback, has a "good chance" of being materially weakened within two years. The article also cited Glassnode research showing that about 6.04 million BTC, or 30.2% of issued supply, already have exposed public keys on-chain. Of that total, roughly 1.92 million BTC face structural exposure tied to address type, while another 4.12 million BTC face operational exposure linked to address reuse or custody practices.

Ethereum Foundation core researcher Justin Drake said on X on Oct. 7 that the blockchain industry should "calmly start preparing for bunker mode."

The post landed on the same day OpenAI publicly released 722 mathematical manuscripts covering 372 families of problems, including solutions to hundreds of long-unsolved questions. According to the article, an internal model that had been training for only 24 days had already produced breakthroughs across nearly every branch of mathematics, and two weeks earlier had also generated a counterexample for the Navier-Stokes equations.

Drake’s warning rests on a simple chain of reasoning: if AI can solve problems that human mathematicians failed to crack over decades in less than a month, then the time needed to discover a classical method for breaking the signature schemes that secure cryptocurrencies may be much shorter than previously thought.

About 10 hours later, Ethereum co-founder Vitalik Buterin replied on X. He said, "I do not recommend that anyone rush to move funds to a new wallet today." He then added a more unsettling point: ECDSA could be broken, and lattice-based cryptography, the post-quantum fallback many in the industry have pinned hopes on, has a "good chance" of being materially weakened within two years.

For years, crypto’s security debate has centered on one question: when will quantum computers be able to break cryptocurrency systems? Drake’s scenario does not require a quantum machine. He argues that AI-driven mathematical superintelligence could uncover a new classical algorithm and break elliptic-curve cryptography on conventional hardware.

Why ECDSA matters to crypto

ECDSA, or the Elliptic Curve Digital Signature Algorithm, sits at the core of transaction signing in Bitcoin and Ethereum. A private key generates a public key, and the public key is hashed into an address. The security of that one-way path underpins the broader crypto asset system. Reversing a public key back into a private key is generally treated as infeasible with current computing power.

The industry’s long-running security narrative has revolved around "Q-Day," the point at which a sufficiently powerful quantum computer uses Shor’s algorithm to solve the discrete logarithm problem in polynomial time, reversing the one-way path behind ECDSA and deriving private keys directly from public keys. That moment has widely been viewed as a decade away, or farther.

Drake outlined a different threat model. In his view, no quantum computer is needed if AI can discover a new classical algorithm, much as the Fast Fourier Transform reduced multiplication complexity from O(n²) to O(n log n). In that case, elliptic-curve cryptography could be broken on standard hardware.

His argument turns on mathematical structure. Elliptic curves have rich structure, and richer structure can create a larger mathematical attack surface. Hash functions are built with the opposite goal: strip away exploitable structure and make outputs resemble random noise. Drake framed the point with a sharp question: "Is a 64-byte ECDSA signature too good to be true?"

In his worst-case estimate, a large GPU cluster could recover private keys from exposed public keys in about a week. The article says that figure is an engineering-scale estimate extrapolated from the pace of AI math progress.

A 2026 timeline of accelerating AI math results

The article ties Drake’s view to a fast-moving timeline in 2026.

In May 2026, OpenAI said an undisclosed model had refuted the unit distance conjecture proposed by mathematician Paul Erdős, a problem that had stood for nearly 80 years. What surprised mathematicians, according to the article, was not only the result but the route: AI found a proof direction humans had not tried.

On Aug. 1, OpenAI released results from its Astra model on 10 open problems in mathematics and theoretical computer science. Each had been stalled for at least a decade, spanning high-dimensional sphere packing, coding theory, group theory, quantum complexity, and lattice cryptography. The work ran to 249 pages, and every proof was formally verified in Lean 4. At API pricing, the total compute cost for all 10 problems was about $2,000.

On Sept. 8, OpenAI said an internal model had produced a counterexample for the Navier-Stokes equations, one of the seven Millennium Prize Problems, whose correct solution carries a $1 million prize. The article notes that the result had not yet been independently verified.

On Sept. 21, OpenAI said an internal model that began training on Aug. 28 had solved more than 100 long-open mathematical problems in just 24 days, spanning nearly every branch of mathematics. The company also formed an independent advisory group at the Institute for Advanced Study in Princeton, with members including Edward Witten and Timothy Gowers.

Then on Oct. 7, OpenAI formally released 722 manuscripts covering 372 problem families. The average compute cost per result, the article said, was roughly equivalent to three hours of ChatGPT Pro usage.

Placed side by side, the sequence runs from one conjecture in May, to 10 major problems in August, to 100-plus open problems solved in 24 days in September, and then to results across 372 problem families in October. Drake summed it up in one line: "Mathematical superintelligence has arrived."

The article also pointed beyond OpenAI. It said an unreleased research version of Anthropic’s Claude had made major progress on the Riemann Hypothesis, while a Google DeepMind system had reached gold-medal level in the International Mathematical Olympiad.

About 6.04 million BTC already have exposed public keys

If the threat is real, the next question is how much value is actually exposed.

According to research cited from Glassnode, about 6.04 million BTC, or 30.2% of issued supply, already have public keys exposed on-chain. The article divides that exposure into two categories.

The first is structural exposure, affecting about 1.92 million BTC. This vulnerability comes from the address type itself rather than user behavior. The largest share comes from Bitcoin’s early P2PK, or Pay-to-Public-Key, format, where the public key is written directly into the locking script and remains permanently visible on-chain.

Satoshi Nakamoto’s roughly 1.1 million BTC are described as being stored almost entirely in these addresses, spread across about 22,000 separate outputs. The article says those coins are unlikely to move, the private keys may already be lost, and Satoshi may no longer be alive. That makes them both the most valuable honeypot on the blockchain and the least able to defend themselves.

The second category is operational exposure, affecting another 4.12 million BTC. These coins were originally protected by hashing, but their public keys were later exposed through address reuse or specific custody operations. Of that amount, about 1.66 million BTC belong to exchange-held balances, or roughly 40% of all operationally exposed assets.

The distinction matters. Operational exposure can be fixed by moving coins to fresh addresses. Structural exposure is permanent. Coins in P2PK addresses remain potential targets unless the holder moves them, and the article argues that Satoshi’s coins almost certainly will not be moved.

If ECDSA were broken, the attack path would be straightforward: scan the chain for exposed public keys, compute the matching private keys, sign transactions, and move the funds. The largest single target would be Satoshi’s 1.1 million BTC, which the article says are worth more than $90 billion at current prices.

Buterin’s warning reaches beyond ECDSA

For years, the standard answer to quantum risk and related cryptographic threats has been a shift to post-quantum cryptography. The leading candidate has been lattice-based cryptography, whose security relies on the hardness of shortest vector problems in lattices and is widely viewed as resistant to quantum attacks. NIST published federal standards based on lattice cryptography in 2024, including ML-DSA and ML-KEM. The Ethereum Foundation also set up a dedicated post-quantum security team in January this year.

But on Oct. 7, Buterin said on X that AI-accelerated mathematical research could deal a "material blow" to the practical security of lattice-based systems within the next two years. The wording he used was "good chance," which the article presents as stronger than a remote or purely theoretical possibility.

His logic goes a step deeper than Drake’s. If AI compresses the next 50 years of mathematical progress into the next two, then the assumptions behind both elliptic curves and lattice cryptography could come under pressure. As Buterin put it: "If there are skeletons hiding behind both elliptic curves and lattices, humans may not be smart enough to find them, but robots soon will be."

In that framing, the industry’s Plan B for quantum risk may itself be vulnerable to AI-driven math advances.

Buterin also pointed to a direction Ethereum has been moving toward over the past year: pure hash-based cryptography. The article mentions leanXMSS as a replacement for BLS consensus signatures and STARK-based commitment schemes. These approaches depend mainly on the security of hash functions.

He paired that with a practical warning: "Losses from a botched wallet migration are more real than losses from a cryptographic attack that has not happened yet."

What "bunker mode" would look like

Drake’s proposed response is simple in principle: move assets to fresh addresses whose public keys have never appeared on-chain, meaning addresses that have never signed a transaction. If the public key remains hidden behind a hash, an attacker has no direct target.

He suggested a three-step rollout:

  • Large institutions and experienced holders move first and set an example.
  • After each signed transaction, move the remaining funds again to a new address.
  • Keep the process slow and controlled, with no panic-driven rush.

He specifically named Binance, Robinhood, Bitfinex, and Tether as firms that should consider strengthening cold-wallet security practices. Drake also said that safely exiting bunker mode would require the maturation of "post-AI cryptography," meaning cryptographic systems that remain reliable even after AI becomes a primary engine of mathematical research.

The logic is internally consistent. The execution challenge is just as clear.

The article says the crypto industry has never successfully coordinated a migration of funds across millions of users. Ethereum’s DAO fork was one of the largest community coordination events to date, but that was still a code change on a single chain. Drake is talking about a behavior shift across Bitcoin, Ethereum, and every other chain that depends on ECDSA.

For Bitcoin, the challenge is even more structural. Ethereum has a tradition of roadmap iteration backed by a foundation. Bitcoin governance is far more conservative. The BIP-360 proposal, which would introduce quantum-resistant address types, is already under discussion, but Bitcoin soft forks have historically taken years from proposal to activation. The harder problem is that no one can act on behalf of the ancient coins sitting in P2PK addresses, including those attributed to Satoshi.

Drake acknowledged that risk directly: "The harm from a rushed migration would be greater than the threat it is trying to prevent."

The article closes on a shift in framing. The old question was when quantum computers would arrive. The new one may be when the next mathematical breakthrough lands.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.