Ethereum Foundation researcher Justin Drake says AI-driven math breakthroughs could undermine ECDSA, the signature system behind Bitcoin and Ethereum, “in months not years,” potentially before quantum computers arrive.
In an Oct. 7 post on X, he urged large holders to prepare for “bunker mode” by moving funds to fresh addresses with unexposed public keys. No such attack has been demonstrated, and Vitalik Buterin says nobody should scramble yet.
Why exposed public keys matter
The immediate concern for crypto wallet holders is not that artificial intelligence can currently steal funds. Rather, it is what could happen if researchers discover a substantially faster method for solving the mathematical problem underpinning ECDSA.
A private key is used to authorize transactions, while its corresponding public key allows the blockchain to verify those signatures. On Ethereum, an account that has only received funds generally has not exposed its public key on-chain. Once that account signs a transaction, however, the public key can be recovered from the signature.
That distinction explains Drake’s recommendation. He wants holders to consider moving remaining assets from previously used addresses into fresh addresses whose public keys remain hidden behind a hash.
The proposal does not necessarily require a new wallet application, new seed phrase or new cryptographic standard. Funds can potentially be moved into another unused address generated from the same wallet infrastructure.
Bitcoin presents a more complicated picture because some address types can expose public-key information even before spending, while address reuse can also increase exposure.
Project Eleven’s Bitcoin Risq List illustrates the scale of the longer-term concern. Its Sept. 14 update identified more than 8.17 million BTC as being in addresses considered vulnerable to future quantum attacks. Inclusion on that list does not mean the funds can currently be stolen.
Vitalik backs caution but rejects panic
Ethereum co-founder Vitalik Buterin broadly agreed that AI-assisted advances in mathematics deserve serious attention, but he pushed back against the idea of an immediate mass migration.
“I don’t recommend anyone scramble to move their funds to new wallets today,” Buterin said in an Oct. 7 post, while arguing that the industry should reduce its exposure to cryptography that could become vulnerable to AI-accelerated mathematical discoveries.
Buterin’s warning goes beyond elliptic curves. He said there is a possibility that lattice-based cryptography could also suffer significant security reductions from rapid AI-driven mathematical progress over the next two years.
That matters because lattice systems are among the leading approaches being developed for post-quantum cryptography. NIST, for example, finalized FIPS 205 in 2024, standardizing SLH-DSA, a stateless hash-based digital signature algorithm based on SPHINCS+.
Buterin has therefore favored hash-based approaches in situations where they are practical, while warning that newer cryptographic assumptions should not automatically be considered permanently safe.
For individual holders, the message is more measured: unused addresses can provide an additional layer of protection against a future public-key attack, but rushing a migration could introduce operational mistakes.
That warning is particularly relevant for exchanges, custodians and large institutions, where a poorly executed transfer could create losses even without an attacker.
AI mathematics is raising the urgency
Drake’s warning came as AI research laboratories demonstrate increasingly sophisticated mathematical capabilities.
OpenAI published hundreds of mathematical research results on Oct. 6, releasing 722 manuscripts grouped into 372 result families after testing an internal frontier model against roughly 4,000 research problems. The publication includes supporting proof material, although the results remain subject to human scrutiny and verification.
The release did not demonstrate an attack against ECDSA, Bitcoin or Ethereum. That distinction is crucial.
Drake is instead concerned about what happens if increasingly capable AI systems discover mathematical shortcuts that human cryptographers have not found. A breakthrough of that kind could alter the security assumptions behind a crypto wallet without requiring a quantum computer.
His argument effectively changes the industry’s traditional timeline. For years, the biggest concern surrounding ECDSA has been “Q-Day” — the point at which a sufficiently powerful fault-tolerant quantum computer could use Shor’s algorithm to attack public-key cryptography.
Drake is now warning that AI-assisted mathematics could potentially create a different route to the same destination.
Ethereum is already preparing for the transition
Ethereum is not waiting for a confirmed crisis before working on cryptographic upgrades.
The Ethereum Foundation created a dedicated Post-Quantum Security team in January 2026. Its current work includes hash-based validator signatures, leanXMSS and leanVM, alongside interoperability testing involving multiple Ethereum client teams. Ethereum’s roadmap identifies account signatures, validator signatures, data-availability commitments and zero-knowledge proof systems as areas requiring post-quantum preparation.
The network is also considering EIP-8141, which would give accounts greater flexibility over transaction authentication and could eventually allow users to adopt alternative signature schemes without abandoning their accounts.
Ethereum’s roadmap currently places major post-quantum infrastructure milestones around 2029, although the project explicitly treats that as a planning target rather than a fixed deadline. It also states that no quantum computer today can break Ethereum’s cryptography and that users do not currently need to act solely because of the quantum threat.
That leaves the industry with a difficult balancing act. A crypto wallet migration involving millions of users cannot be safely improvised, yet waiting until a cryptographic break is confirmed could leave too little time to respond.
For now, Drake’s message is preparation rather than panic. Buterin’s response points in the same direction: strengthen cryptographic defenses, limit unnecessary exposure and give developers time to build safer alternatives.
The debate ultimately highlights a new security reality for the cryptocurrency industry. The threat to a crypto wallet may no longer be defined solely by faster computers. If AI begins producing mathematical breakthroughs at a pace far beyond human research, assumptions that have protected digital assets for decades could face an entirely different test.
For holders, exchanges and blockchain developers, the lesson is not that ECDSA has failed. It is that the window for preparing for the next generation of cryptographic threats may be opening much earlier than expected.