Ethereum researcher Justin Drake called on the community on October 7, 2026, to go into "bunker mode," calmly preparing defenses against the possibility that rapid progress in AI-driven mathematical research could threaten the digital signature technology behind crypto assets. Co-founder Vitalik Buterin agreed on October 8 (Japan time) that Ethereum needs to prepare for unknown mathematical attacks, but argued that wallets should not be migrated in haste. Neither statement reports a successful break of any cryptography; both are personal risk assessments based on recent research results. The near-term measure of keeping public keys hidden and the long-term measure of replacing signature schemes across the entire network address different risks and require different amounts of preparation time.
"Cryptography could be broken within months": the worry, and what AI math research has actually produced
Drake's concern is that ECDSA, the digital signature scheme used to authorize transactions and more, could lose its security without waiting for a quantum computer powerful enough to break today's public-key cryptography.
He warned that, in the worst case, the threat could emerge in "months rather than years." That is a harsh scenario he himself envisions, not a scientific forecast of when cryptography will be broken.
If a new algorithm were discovered that could derive a private key from a public key quickly on conventional computers, an attacker could impersonate the rightful owner and move funds. However, Drake's post offers no concrete description of such an attack method, nor any experimental results showing a private key extracted from a real wallet.
The trigger for the warning was the mathematics research results that OpenAI published on October 6.
OpenAI released on GitHub draft math papers and proof materials generated by an unreleased internal AI model. Some results come with materials that can be formally verified with the proof assistant Lean.
But being able to verify new mathematical results externally is an entirely separate matter from being able to break cryptography with a realistic amount of computation.
The initial listing groups 722 manuscripts into 372 research series. A series here is a unit that bundles a core result with supplementary arguments and alternative proofs. It therefore does not mean that 722 independent open problems were all solved.
OpenAI itself acknowledges that the verification status of the published results varies and that errors may be included.
Indeed, in the update history dated October 7, the day after publication, a sign error invalidated one proof, and three manuscripts, including ones that depended on that result, were withdrawn.
Another 14 were also revised, with proofs corrected or conditions of validity clarified.
Such corrections do not negate the value of all the published research. But the number of published papers cannot be treated as the number of results confirmed to be correct. Even for proofs formally verified in Lean, one must check which statements were proved and under what assumptions.
Assessing the impact on cryptography requires still deeper verification.
What attacks would work against the elliptic curves and key sizes actually used in Ethereum? How much computing power and time would they require? The computational cost of breaking real cryptography cannot be estimated from progress in mathematical research in general.
Post-quantum cryptography is not guaranteed to be safe from unknown mathematical attacks
Buterin's concern is not limited to today's ECDSA. He also pointed out that progress in AI-driven mathematical research could shake the security of "lattice-based cryptography," which is believed to withstand attacks by future quantum computers.
Lattice-based cryptography is a family of techniques that rely on the difficulty of mathematical problems involving high-dimensional lattices. It is used in the signature scheme ML-DSA and in fully homomorphic encryption (FHE), which allows computation on encrypted data without decrypting it.
Buterin predicted that AI-driven mathematical research over the next two years could substantially undermine the real-world security of lattice-based cryptography.
He illustrated this with the development of factoring algorithms related to RSA cryptography.
If mathematical research uncovers more efficient attack algorithms than before, the computation needed to break a key of a given size may fall. In that case, key sizes or problem sizes would have to grow to maintain the same level of security.
Buterin considers that if AI achieves "50 years of mathematical progress in two years," lattice-based cryptography could see major improvements in attacks comparable to those in factoring algorithms.
However, the "two years" is not a deadline derived from experiments, and the scale of "50 years" of progress is only an assumption.
He also mentioned a conservative option of increasing key sizes tenfold for public-key cryptography that needs long-term security. This is not, however, the result of calculating key lengths that could guarantee security for any particular scheme.
In the first place, the name "post-quantum cryptography" does not guarantee safety against every attack discovered in the future.
The U.S. National Institute of Standards and Technology (NIST) evaluated known classical attacks and quantum attacks, then standardized the lattice-based ML-DSA and the hash-based SLH-DSA on August 13, 2024.
SLH-DSA rests on a different mathematical mechanism from ML-DSA and is also positioned as an alternative in case a vulnerability is found in lattice-based signature schemes.
The idea of preparing multiple schemes built on different mechanisms, anticipating that future research could change the assumptions about a scheme's security, was already adopted at the standardization stage.
There are in fact cases where post-quantum candidates were broken by mathematical discovery, without any quantum computer.
Wouter Castryck and Thomas Decru of KU Leuven in Belgium published a new attack in 2022 on SIDH, a post-quantum candidate. The work was also accepted at EUROCRYPT 2023.
According to the paper's abstract, an implementation recovered the key for the SIKEp434 parameter set in about 10 minutes on a single CPU core.
However, SIDH is based on a different mathematical mechanism from lattice cryptography, and the attack exploited specific additional information exchanged during communication. It was also not an attack discovered by AI.
This case shows that if an unknown mathematical weakness is found, a scheme previously considered secure can lose its practical security. But it is not evidence that the same attack would work on ML-DSA or ECDSA.
What a new Ethereum address can and cannot hide
In a typical Ethereum personal account, the wallet address visible from the outside is not the same thing as the public key.
According to Ethereum's developer documentation, an address is generated by applying the Keccak-256 hash function to the public key and taking the last 20 bytes of the result.
As long as it is hard to work backward from the hash to the original public key, knowing an address alone does not let an attacker directly carry out an attack that targets the public key to recover the private key.
Drake's proposed near-term measure takes advantage of this mechanism.
First, holders with large amounts of crypto assets and sufficient knowledge and experience in key management would move funds, in a planned way, to new addresses whose public keys are not yet known. If they sign with that address, he recommends moving the remaining funds to another new address.
This measure extends the time before a public key becomes known; it does not make ECDSA itself more secure.
Also, a public key becomes known not only when a transaction is sent on the blockchain.
On Ethereum, a public key can be recovered from a signature and the message that was signed. So if you sign something with your wallet, such as a login to a service, the service that receives the signature can also learn the public key.
Even for an address that has never sent a transaction on the blockchain, the public key is not necessarily hidden if a signature has been disclosed through another route.
Similar caution applies to mechanisms where a third party carries out operations on your behalf.
For example, with a delegation authorization under EIP-7702, a signature created by the account owner can be included in a transaction and submitted by a different sender.
This authorization also uses a signature on the same elliptic curve as before and is verified by a mechanism that recovers the signer.
The fact that there is no history of sending from your address is therefore not enough to conclude that your public key is unknown to the outside.
For multisig setups, which require approval from multiple signers, Buterin proposed limiting exposure by collecting signatures off-chain rather than on the blockchain.
Even so, information goes to whoever collects the signatures, so that party has to be trusted. And signatures that have already been published in the past cannot be erased.
Moving funds to a new smart contract address would also not resolve the problem if the signer keys used for approval are already known.
What both men repeatedly stress is that these measures should not be rushed.
Buterin said that, in his experience, he has lost more funds to failed migrations than to hacks.
Even if preparation for future mathematical attacks is necessary, moving funds with inadequate preparation risks losing assets. The long-term risk to cryptography and the risk that comes with immediate migration work must be judged separately.
What changes if you switch to hash-based signatures?
Comparing the signature schemes NIST has standardized reveals the challenges of adopting schemes that do not depend on lattice cryptography.
Hash-based signature schemes use properties of well-studied hash functions and are designed to reduce reliance on algebraic structures that could lead to unknown attacks.
But different mathematical assumptions bring large differences in key and signature sizes.
For example, comparing ML-DSA-65 and SLH-DSA-SHA2-192s, both in NIST security category 3, SLH-DSA has the smaller public key but a far larger signature.
| Signature scheme / parameter set | Main mathematical assumption | NIST security category | Public key size | Signature size |
|---|---|---|---|---|
| ML-DSA-65 | Module lattices | 3 | 1,952 bytes | 3,309 bytes |
| SLH-DSA-SHA2-192s | Hash functions | 3 | 48 bytes | 16,224 bytes |
Sources: Table 2 of FIPS 204 (page 16 of the text) and Table 2 of FIPS 205 (page 43 of the text), both published August 13, 2024. Parameter sets in the same security category 3 were chosen, and the public key and single-signature sizes defined in the standards were compared. The "s" at the end of SLH-DSA denotes a setting that prioritizes smaller signatures.
NIST's security categories are a classification for comparing resistance to assumed attacks; they do not mean that different schemes are equally secure under all conditions.
Also, this table shows the data volume of keys and signatures. It does not compare processing speed or the gas costs required on Ethereum.
Smaller public keys reduce the storage burden, but larger signatures increase the bandwidth and storage needed when exchanging large numbers of signatures across the network.
Whether lattice-based or hash-based schemes are better therefore cannot be judged from key and signature sizes alone.
If, as Buterin fears, advances in future attack methods force lattice parameters to grow, such comparisons could change. But it cannot be concluded at this point that hash-based schemes are efficient for every use.
On Ethereum, the size of signatures used for consensus is especially important.
Ethereum validators currently use BLS signatures, which keep bandwidth down by aggregating many signatures into a small one.
The Ethereum post-quantum plan is researching replacing BLS signatures with the hash-based "leanXMSS." But hash-based signatures are large and cannot be aggregated directly the way BLS signatures can.
The response under development is a mechanism that uses a minimal virtual machine, leanVM, to prove compactly through SNARKs that many signatures were verified correctly.
The aim is to keep the amount of data processed across the whole network down even when the signatures themselves are large.
In other words, migrating to post-quantum cryptography is not just a matter of swapping one signature algorithm for another. Beyond generating and verifying signatures, the mechanisms for creating and aggregating proofs must also be built, and increases in bandwidth and storage must be contained.
Note that the SLH-DSA shown in the table and the leanXMSS that Ethereum is researching are different schemes, and the table's figures do not directly represent performance on Ethereum.
Can Ethereum become quantum-resistant by 2029?
The Ethereum Foundation's post-quantum team says in its official roadmap that it may be able to complete updates to the underlying L1 protocol by 2029.
The Ethereum Foundation's Protocol team also set a goal, in its development priorities published on September 7, 2026, of making the execution, consensus, and data layers quantum-resistant by December 2029.
However, this is not a completion date guaranteed to be met. Developing and verifying the necessary technology and building consensus across the network will continue to be required.
Also, even when the protocol-side updates are complete, not every user will have finished moving to the new signature scheme.
The Ethereum Foundation's post-quantum team also explains that migrating the entire execution layer, including user accounts, could take several more years.
If a mathematical attack of the kind Drake fears became practical sooner than expected, the time this migration needs would become a serious problem.
Meanwhile, the hash-based approach Buterin sees as desirable in the long run does not necessarily match the signature schemes Ethereum is currently considering adopting.
The official plan is to research hash-based signatures at the consensus layer, while for user accounts, it takes a staged approach using "account abstraction," which allows the signature verification method to be changed.
At the execution layer, multiple signature schemes, including Falcon, Dilithium, and SPHINCS+, are being evaluated as candidates.
The purpose is to be able to switch to another scheme if future research finds a weakness in a particular one.
Just because Buterin emphasizes hash-based cryptography does not mean lattice-based schemes have been uniformly ruled out on Ethereum.
There is another important difference in timing when migrating cryptography.
It is that digital signatures, which authorize the movement of funds, and encryption, which keeps information secret, are affected differently by future attacks.
Even if a technique for forging digital signatures emerged in the future, it would not automatically rewrite every transfer record already finalized in the past. The danger is that, if a private key is illicitly obtained, future transfers could be authorized without the owner's consent.
Encrypted data, by contrast, could have its past contents read if a way to decrypt it is later discovered.
This is why Buterin recommends handing off encrypted data used for privacy protection outside the chain rather than storing it on the blockchain: to reduce the risk of long-term information leakage.
Still, handling data off-chain does not guarantee safety. Leaks can occur from where the data is stored or shared, so the security of the chosen encryption scheme needs continued evaluation.
What should we use to judge the threat of AI-driven cryptanalysis?
What matters in this warning is not the prediction itself of "how many months until cryptography is broken."
Whether a new attack method would work against key sizes actually in use, how much computation time and cost such an attack would need, and whether wallets and clients can safely handle alternative signature schemes will be the factors for judgment going forward.
At this point, no evidence has been presented that the mathematics research OpenAI published has broken Ethereum's ECDSA. The acceleration of mathematical research should not be confused with crypto asset security having already been lost.
On the other hand, after a new attack method is discovered, it takes a long time to safely switch the cryptography of an entire network. Researching alternative technologies and preparing migration tools before a concrete threat is confirmed therefore makes sense.
What is needed now is not for crypto holders to rush to move their funds, but to put safe migration paths in place for future attacks.
Once the feasibility and computational cost of attacks become clear, and the security and compatibility of alternative signature schemes are sufficiently verified, Ethereum will find it easier to update its cryptography in response to new mathematical discoveries. How far that preparation can be advanced will shape long-term security.
