Ethereum co-founder Vitalik Buterin said in an Oct. 8 post that AI-accelerated mathematical research could severely weaken the practical security of lattice-based cryptography within the next two years, affecting technologies including ML-DSA and fully homomorphic encryption, or FHE. He also said the shift could put ECDSA at risk sooner than many expect.
In the original post, Buterin wrote that AI could deliver the equivalent of 50 years of mathematical research progress in just two years.
The concern is mathematical breakthroughs, not quantum computing alone
Buterin framed the issue around AI-driven advances in mathematics rather than quantum computing itself.
He compared lattice cryptography with the historical path of RSA and ECDSA. RSA was once thought to be bounded by brute-force factoring at roughly 2^(n/2), he said, but over decades researchers developed the general number field sieve, or GNFS, cutting complexity to 2^O(n^(1/3)). As a result, RSA key sizes expanded from 64 bytes to about 400 bytes.
His argument is that lattice systems, like elliptic-curve cryptography, may also contain structural weaknesses that have not yet been found. The difference, in his telling, is that AI may uncover them faster than humans can. In that case, the threat would not come from brute force, but from a smarter mathematical route similar to what GNFS did for factoring.
Lean Ethereum has moved toward hash-based signatures
Buterin linked that view directly to the Lean Ethereum roadmap. Over the past year, he said, Lean Ethereum has been stepping away from lattice-based tools: it does not use ML-DSA, does not use Falcon, and does not put lattice-based commitments into zero-knowledge proofs. For signatures, it has shifted to purely hash-based approaches such as WOTS and SPHINCS-.
He wrote, “Where hash-based signatures are practical, pure hash is better than lattice crypto.”
Buterin added that hash functions could also fail in theory if P=NP, though he described that as highly unlikely. In his view, it is more plausible that a mathematical object was designed with no exploitable structure than that only a limited set of exploitable structures exists and a new one is still waiting to be discovered.
Public-key encryption remains the harder problem
While signatures already have a hash-based path, Buterin said public-key encryption is the real bottleneck.
He noted that mathematical results have long shown public-key encryption cannot be built from hash functions alone. It requires some structured trapdoor object, whether from group theory, including isogenies, lattice cryptography, code-based encryption, or a method that has not yet been imagined.
His practical advice was blunt: “If you want something to stay secure for a long time, increase key sizes by 10x.”
Under his assumption that AI could compress 50 years of mathematical progress into two years, lattice cryptography would not disappear, but it would need much larger parameters to preserve the same security level. At that point, he argued, pure hash-based systems could come out ahead on efficiency.
Keep funds in untouched addresses, but do not rush migrations
For asset security, Buterin said users should, where convenient, keep funds in addresses that have never initiated a transaction. If ECDSA is broken faster than expected, signatures that have already exposed a public key on-chain would become obvious targets, while never-used addresses would not yet have revealed their public keys.
At the same time, he warned against moving funds in haste. He said he has lost more money from botched migrations than from all hacks combined. In his view, operational errors during a migration can rival the long-term risk posed by future AI-assisted cryptanalysis.
For multisig wallets, he suggested using off-chain signature confirmation where possible. That keeps signers’ signatures off the public chain. If ECDSA were broken quickly by AI, a multisig setup would then “gracefully degrade” into a 1-of-1 controlled by the signature collector, which he described as far better than a situation where anyone could move the funds.
Europol issued a related warning 24 hours earlier
Twenty-four hours before Buterin’s post, Europol published a report saying crypto wallets are the main point of risk from quantum computing, because a sufficiently powerful quantum computer could derive private keys from public keys that have already been exposed.
According to the article, Europol’s assessment aligns with Buterin’s on a core point: the hashing functions used in blockchain linking and mining support remain broadly quantum-resistant, while signature systems, including ECDSA and lattice-based cryptography, are the weaker link.
The two warnings appeared in the same week, putting AI risk and quantum risk into the same cryptographic discussion. In Buterin’s framing, this is no longer only a distant theoretical issue. It could alter current security assumptions within two years.

