Ethereum Foundation researcher Justin Drake has warned that advances in artificial intelligence could break the elliptic-curve digital signature algorithm (ECDSA) used by Bitcoin and Ethereum wallets before quantum computers do. As of early October 2026, no practical attack has been demonstrated. Drake described a worst-case scenario in which private keys could be recovered from exposed public keys in about a week using available hardware such as large GPU clusters. The timeline could be “months not years.”
On October 7, Drake called on the blockchain industry to calmly prepare for “bunker mode.” His main recommendation is a controlled mass migration of assets to fresh addresses whose public keys remain hidden behind a hash. Addresses that have never signed a transaction keep the full public key unexposed. Vitalik Buterin responded by urging the industry to take AI-accelerated mathematics risks seriously while advising against any rushed movement of funds.
The Drivers of the Current Situation
The core concern is the mathematical structure of elliptic curves. Drake argued that rapid AI progress in mathematics, including OpenAI’s recent release of hundreds of machine-generated mathematical manuscripts, could uncover classical shortcuts that undermine ECDSA. He has long focused on quantum risks (Q-Day) but now sees artificial intelligence as a potentially nearer threat.
Once an address signs a transaction, its public key becomes visible on-chain. If an efficient method to derive the private key from that public key emerges, funds in previously used addresses would be vulnerable. Drake recommended that large and sophisticated holders move first. After any spend, remaining balances should shift to a new unused address from the same seed. He also urged institutions to harden cold storage and called for faster adoption of hash-based cryptography such as SPHINCS or SLH-DSA.
Ethereum already maintains a post-quantum research effort targeting more resilient infrastructure around 2029. Project Eleven tracks millions of Bitcoin addresses with already-exposed public keys. No working attack meeting Drake’s definition of a “break” has been published. The warning remains a precautionary risk assessment rather than evidence of an imminent failure.
A full transition to more robust signature schemes requires protocol changes and coordinated upgrades. Limited protective steps such as address rotation are available today without new software.
Impact and Broader Context
Questions about the long-term security of ECDSA under accelerating AI mathematics keep growing. Controlled migration to unused addresses offers a practical near-term hedge for holders. It also highlights the difference between quantum-focused roadmaps and emerging classical risks driven by AI.
The issue drives debate on cryptographic resilience across blockchains. It raises questions about the exposure of public keys, the security assumptions of elliptic curves versus hash-based schemes, the readiness of post-quantum migrations, risks of panic-driven transfers, and the role of institutional cold storage. Drake emphasized calm planning over haste. Buterin stressed that migration errors currently pose a more immediate danger than any demonstrated break.
The combination of AI mathematical advances and existing on-chain key exposure has shifted attention from distant quantum timelines to nearer-term classical risks. Further research results, formal security analyses, or concrete protocol upgrades will clarify the practical timeline and necessary defenses for crypto wallets.
This analysis uses statements from Justin Drake and Vitalik Buterin on X, reporting from Decrypt, CryptoSlate, and related coverage of OpenAI’s mathematical releases. The cryptographic risk assessment and recommended mitigations remain subject to ongoing research and community response.
