AI Crypto Threat: Bitcoin and Ethereum Wallets Could Face a New Risk
Is the math behind your wallet running out of time? Ethereum researcher Justin Drake says the industry should calmly plan for "bunker mode."
He warned that the cryptography protecting Bitcoin and Ethereum wallets could fail "in the worst case in months, not years."

Source: Justin Drake
Vitalik Buterin replied with a calmer view: take the risk seriously, but don't panic.
In this crypto news today update, we explain the AI crypto threat in plain words and show why AI Bitcoin security is suddenly a hot topic.
His concern is ECDSA, the digital signature that proves you own coins on Bitcoin and Ethereum.
Every wallet has a secret private key and a matching public key. When you sign a transaction, your public key becomes visible on the blockchain.
A powerful enough attack could then work backward and recover the private key, and whoever holds that key can move the money.
This is the heart of the ECDSA AI risk he describes. He asks the industry to brace for the possibility that ECDSA breaks before quantum computers arrive, a moment he calls "qday."
By "break," he means recovering a private key in about a week on available hardware, such as a large GPU cluster.

Source: CryptoRover on X
The wording matters: this is a worst-case possibility, not an announcement that anything has been cracked.

Source: Pete Rizzo
Bunker mode is a step-by-step plan, not a panic exit. His recommendations are:
Move the bulk of funds to fresh addresses that have never signed a transaction. Such an address shows only a hash of the public key, so the key itself stays hidden.
Large and sophisticated holders should go first.
After signing a transaction, move the remaining funds to another new address, possibly generated from the same seed phrase.
No new cryptography or new wallets are needed.
Don't rush and don't panic, because he says a rushed migration would do more harm than good.
Think of an unused address as a locked box whose key nobody has seen. Signing a transaction shows that key to the world, so a new box is safer.
A fresh wallet migration also carries real risks, so go slowly. Common-sense habits, which are not part of his post, include double-checking every address, sending a small test amount first, and keeping your seed phrase offline.
The AI crypto threat, as he describes it, rests on how fast artificial intelligence is now solving math problems.
He says OpenAI published 722 mathematical results and that "mathematical superintelligence is upon us."
He lists long-held ideas that recently fell, including the n log(n) bound for integer multiplication and the 3SUM conjecture. He calls May's disproof of the Erdős unit distance conjecture a "warning shot."
He singles out elliptic curves because they carry rich mathematical structure, with room for tricks like Schoof, Frobenius, and pairings.
Hashes, by contrast, are designed to have as little structure as possible. He also notes that a fast quantum algorithm can foreshadow a fast classical one, citing Ewin Tang.
A classical cousin of Shor's algorithm could therefore break elliptic curves and RSA together.
Finally, he claims cryptography is strikingly underrepresented among the 722 results. He also says he has seen the US government censor academic quantum cryptanalysis.
That is his personal claim, and the post offers no proof.
| Group | Suggestion |
| Large holders | Move the bulk of funds to never-used addresses. |
| Binance, Bitbank, Robinhood, Bitfinex, Tether | Harden cold storage; Project11's risk list tracks exposed BTC public keys |
| Wallets under 50 BTC | Partial cover from "Satoshi's shield," his roughly 20K exposed addresses holding 50 BTC each |
| Oracles and L2 security councils | Rotate ECDSA keys with every signed message and/or multisign with hash-based schemes like SPHINCS |
To leave bunker mode safely, he says the industry needs "post-AI cryptography."
His pick is hash-based cryptography from the SHA or BLAKE families, avoiding curves, lattices, and isogenies.
That is why the AI Ethereum threat matters for the network's plans. The Ethereum roadmap on strawmap.org already embraces hash-based cryptography with end-to-end formal verification, and he wants those timelines accelerated.
Buterin's reply on X agrees that the AI crypto threat deserves serious attention. He says he does not recommend anyone scramble to move funds today.

His main points:
New risk area: he sees ML-DSA, FHE, and lattice-based cryptography as the core new risk, even though many people assume lattices are safe.
Hidden shortcuts: factoring once looked like a 2^(n/2) problem. Decades of smarter methods, such as the number field sieve, made it far easier, which is why RSA keys need about 400 bytes instead of 64. Similar shortcuts could be hiding for curves and lattices.
Hash-only roadmap: Ethereum's lean roadmap has gone "hash-only" for a year, using hash-based signatures such as WOTS or SPHINCS.
Encryption problem: public-key encryption cannot be built from hashes alone, so he suggests multiplying lattice key sizes by 10.
Hashes stay as they are: he sees no reason yet to pad hash sizes.
Careful migrations: unused addresses are a good idea if easy, but he says he has lost more money in botched migrations than in all hacks combined.
Smarter multisig: confirming off-chain keeps signatures hidden, so a break would degrade a multisig to "1-of-1" instead of "anyone can take the money."
Privacy tools: protocols should avoid putting encrypted notes on-chain.
The AI crypto threat is a warning, not a confirmed attack. Drake and Buterin both back one low-effort step, keeping funds in unused addresses, and both warn that the biggest danger today may be mistakes during hurried transfers.
Stay calm, follow the primary posts linked above, and watch for updates from researchers and wallet teams.
This article is for information only and is not financial, legal, or investment advice. Crypto presales carry high risk, including total loss. Verify every detail with official sources before sending funds.