Vitalik says users should not rush to move funds to new wallets

Vitalik says users should not rush to move funds to new wallets

N
News Editor
2026-10-08 00:08:00
Ethereum co-founder Vitalik said users should not hastily move funds into new wallets, even as he urged the industry to take AI-driven advances in mathematical computation seriously. In his view, the risk is no longer limited to quantum computing. He pointed to ML-DSA, fully homomorphic encryption, and lattice-based cryptography as key areas where AI progress could create new pressure on existing security assumptions. Vitalik said this is another reason, beyond the quantum threat, why ECDSA security could break down faster than many expect, which helps explain the recent push for using fresh addresses. He also argued that the common assumption that elliptic-curve systems may fail while hash-based and lattice-based systems remain safe may not hold if AI makes major gains in mathematics over the next two years. He recommended preferring hash-based schemes where practical, being highly cautious with parameter sizes in lattice-based systems, keeping encrypted notes for privacy protocols offchain through third-party transmission mechanisms, and storing funds in addresses that have not yet been used for transactions when convenient. For multisig wallets, he said offchain coordination is better than onchain confirmation because signatures are not exposed on public networks, allowing the setup to degrade to a 1-of-1 model rather than leaving funds open to theft if ECDSA fails earlier than expected.

Ethereum co-founder Vitalik said users should not rush to move funds to new wallets, but they should take seriously the risk that AI-accelerated mathematical computation could pose to cryptography and reduce reliance on schemes that may be vulnerable not only to quantum attacks but also to AI-driven ones.

He identified ML-DSA, FHE (fully homomorphic encryption), and lattice-based cryptography as the new core risk areas. He said this is another reason, beyond the threat from quantum computing, why ECDSA security may collapse faster than expected, which in turn helps explain the recommendation to use new addresses.

Vitalik added that many people still believe that elliptic-curve algorithms will be broken while hash-based and lattice-based cryptographic algorithms remain safe. But in his view, progress in AI-driven mathematics over the next two years could materially weaken the practical security of lattice-based cryptography.

Recommendations from Vitalik

  • Prefer hash-based schemes over lattice-based ones where practical.
  • Be extremely careful with parameter sizes in any lattice-based scheme.
  • For privacy protocols, do not put encrypted notes onchain; send them offchain through third-party mechanisms instead.
  • If it is not operationally difficult, keeping funds in addresses that have not been used for any transaction is a good idea.

His view on multisig wallets

For multisig wallets, Vitalik said offchain confirmation is better than onchain confirmation. That way, signatures from signer wallets are not exposed on public networks. If advances in AI cause ECDSA to be broken earlier than expected, the multisig setup could at least degrade gracefully into a 1-of-1 model, meaning the party responsible for collecting signatures would control the funds, which he described as far better than a situation where the funds could simply be taken by anyone.

Earlier, Justin Drake said ECDSA could, in the worst case, be broken within months and advised large holders to move assets to new addresses.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.