Dragonfly partner proposes chain-level recovery mode against AI-driven wallet signature breaks

Dragonfly partner proposes chain-level recovery mode against AI-driven wallet signature breaks

N
News Editor
2026-10-08 16:43:04
Dragonfly managing partner Haseeb Qureshi has laid out what he calls a "cryptographic recovery mode" for major blockchains, arguing that networks should prepare an emergency path in case AI or an unexpected mathematical breakthrough breaks today’s wallet signature systems. Writing on X on Oct. 8 in a post titled "Against Crypto Doomerism," Qureshi pushed back on Ethereum Foundation researcher Justin Drake’s warning from a day earlier that ECDSA signatures could be broken within months and that large holders should move assets to fresh addresses that have never signed a transaction, a setup Drake described as "bunker mode." Qureshi argued that bunker mode only helps individuals while a chain-wide failure would still destroy asset value. His proposal calls for a minimal hash-based backup signature scheme to be added in a future protocol upgrade, with users binding existing addresses to backup keys. At first the setup would be voluntary, then mandatory after several months. He also suggested an emergency switch that validators could activate by vote if ECDSA were compromised, forcing addresses into recovery mode without another protocol upgrade. For addresses without a pre-bound backup key, Qureshi proposed zero-knowledge proofs for users who still control their seed phrases, and a proof-of-work hurdle tied to the amount of native assets held for others. He said crisis response may require faster decisions, broader validator powers, and coordination across wallets, exchanges, RPC providers, and asset issuers.

Dragonfly managing partner Haseeb Qureshi says major blockchains should add what he calls a "cryptographic recovery mode" so networks have a fallback if AI discovers a weakness in current wallet signature algorithms.

Qureshi published the proposal on X on Oct. 8 in a long post titled "Against Crypto Doomerism." It was a response to a warning from Ethereum Foundation researcher Justin Drake a day earlier. Drake said ECDSA signatures used by wallets could be broken within months and urged large holders to move assets to fresh addresses that have never signed a transaction, a setup he called "bunker mode."

Why Qureshi rejects bunker mode

Qureshi argued that moving funds to a new address may protect an individual holder, but it does not solve a network-wide failure. In his view, bunker mode only works while the assets remain untouched. If coins in other addresses are hacked and then dumped on the market, even protected holdings could become worthless.

He also backed Vitalik Buterin’s view that encouraging panic would push users into rushed migrations and mistakes, creating a larger risk than key theft itself.

The threat he is focused on

Qureshi said his concern is not AI accelerating quantum computing. What worries him is an unexpected mathematical breakthrough that would let ordinary computers compute discrete logarithms and break modern public-key cryptography.

He wrote that banks and internet encryption certificates could still recover in that scenario by re-verifying identities and switching to new standards. A blockchain, he said, would face a harder problem because anyone could derive someone else’s private key. "We would not know who owns what," he wrote.

How the recovery mode would work

His proposal has several parts. First, a future protocol upgrade would add a minimal hash-based signature mechanism. He described that system as "slow, expensive, and cumbersome," which is why it would not be used under normal conditions.

Users would bind their current addresses to a hash-based backup key. At the start this would be voluntary. After several months it would become mandatory, and transactions from addresses without a configured backup key would fail.

Second, the chain would pre-deploy an emergency switch. If AI really did uncover an ECDSA vulnerability, validators could activate the switch by vote. That would move all addresses into recovery mode without another protocol upgrade.

Qureshi acknowledged that the blockchain would become almost unusable in that state, but balances would remain safe and developers would gain time to build a new migration plan.

What happens to addresses without a backup key

For addresses that had not been pre-bound, Qureshi proposed a separate path. Users who still have their seed phrases could use zero-knowledge proofs to claim a new address.

Others would need to provide an ECDSA signature and solve a proof-of-work puzzle before moving funds. The puzzle difficulty would depend on the amount of native assets held by the address and would double each day, giving legitimate owners a chance to migrate before attackers. Validators could adjust both the difficulty and the growth rate depending on how the attack unfolds.

Speed over decentralization in a crisis

Qureshi said speed should take priority over decentralization during an emergency. If needed, decision rules could be loosened or validators could be given broader powers. Wallets, exchanges, RPC providers, and asset issuers would also need to act together.

He added that large investors have already asked him about the issue and that the market will watch which blockchains treat it seriously.

He also walked back an earlier Zcash view

Qureshi said he is retracting a position he took a few weeks ago, when he argued that Zcash should stop updating after completing a post-quantum migration. He stressed that he is not a cryptographer or a protocol designer and described the recovery mode as only a proposal with many missing details.

Even so, he said the most likely outcome is that nothing happens at all: "AI will conclude that the cryptography you invented is rock solid."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.