Ethereum Foundation researcher Justin Drake has urged crypto holders to prepare for a possible AI-assisted break of ECDSA, warning on Oct. 7 that a worst-case failure could arrive “in months not years” before quantum computers pose the expected threat.
Summary
- Justin Drake urged crypto holders to plan moves toward fresh addresses with unexposed public keys.
- Vitalik Buterin backed taking AI cryptography risks seriously but warned users against rushing wallet migrations.
- Ethereum already has a dedicated post-quantum team targeting core quantum-resistant infrastructure around 2029 for completion.
- NIST standardized hash-based SLH-DSA in 2024, providing an established post-quantum signature option for digital systems.
- Project Eleven tracks millions of Bitcoin addresses with exposed public keys that could face attacks.
Drake’s Oct. 7 post on X called for the blockchain industry to begin calmly planning for what he described as “bunker mode.” His proposal centers on gradually moving funds into fresh addresses whose public keys have not been exposed, with large holders and institutions taking the first steps. Drake repeatedly warned against panic and said a poorly managed migration could create its own risks.
The warning remains a risk scenario, not evidence that ECDSA has been broken. Drake defined his worst case as an attacker recovering a private key from a public key within roughly a week using available hardware such as a large GPU cluster. No working attack meeting that description has been published.
Why the Ethereum researcher wants fresh addresses
ECDSA is used to authorize transactions from standard Ethereum accounts and plays a central role in securing Bitcoin wallets. A private key creates a signature, while the corresponding public key lets the network verify that signature without revealing the private key.
Ethereum’s official post-quantum documentation explains that an ordinary Ethereum account which has only received funds and never sent a transaction has not exposed its public key onchain. Once the account signs a transaction, its public key can be recovered from the signature. A future method capable of deriving a private key from that public key could therefore threaten remaining funds.
Drake recommended that holders who use an address move any remaining assets into another unused address after signing. He said the process could use addresses generated from the same seed phrase, meaning his immediate proposal does not require a new wallet format or new cryptographic algorithm.
Bitcoin requires some extra distinction because not every unused address hides its public key. Project Eleven says address types including P2PK and Taproot can expose public-key information without prior spending, while address reuse exposes keys for several other address types. Its Bitcoin Risq List tracked more than 8.1 million BTC in addresses it classified as quantum-vulnerable in its Sept. 14 update.
Drake specifically pointed to the tracker while urging Binance, Bitbank, Robinhood, Bitfinex and Tether to examine their cold-storage setups. The tracker identifies addresses based on publicly visible key exposure; inclusion does not mean an attacker can currently derive their private keys.
Vitalik Buterin warns users not to rush
Ethereum co-founder Vitalik Buterin has responded to the warning by supporting more caution around AI-assisted mathematics without calling for an immediate movement of funds.
Buterin said he “[doesn’t] recommend anyone scramble” to move money into new wallets today. He argued that crypto developers should still take AI-driven advances in mathematics seriously and reduce dependence on cryptography that could prove weaker than expected.
His concern extends beyond elliptic curves. Buterin said the concrete security of lattice-based cryptography could face pressure from AI-assisted mathematical discoveries over the next two years, though he did not claim any lattice system has been broken. He favors hash-based designs where they can be used and recommends more conservative parameters for systems that rely on lattices.
For individual holders, Buterin said keeping funds in addresses that have never made a transaction can be useful when it is easy to do safely. He warned that mistakes during rushed migrations can themselves cause losses, reinforcing Drake’s call for a controlled process instead of an emergency move.
OpenAI math release did not break ECDSA
Drake tied the timing of his warning to rapid progress in AI-assisted mathematics, including OpenAI’s Oct. 6 publication of mathematical research produced by an internal frontier model.
OpenAI’s official announcement said the work covers a range of mathematical results and includes supporting proof material. The public repository currently contains 722 manuscripts across 372 result families, produced after the model was tested on roughly 4,000 research problems.
OpenAI did not announce an attack against ECDSA, RSA or cryptocurrency wallets. Its repository states that the results are at different stages of verification, that not every manuscript has a Lean formalization and that some unformalized results “could have issues.”
Drake interpreted the speed of recent mathematical advances much more aggressively, writing that “mathematical superintelligence is upon us.” He questioned whether new classical algorithms assisted by AI could find shortcuts against elliptic-curve systems before quantum computers become capable of running Shor’s algorithm at the scale needed to attack them. His timing remains a personal risk assessment rather than a demonstrated cryptographic break.
Ethereum’s current documentation takes a less urgent position on the established quantum threat. It states that no quantum computer today can break Ethereum’s cryptography and says current users do not need to take action solely because of quantum computing.
Ethereum is already preparing to replace vulnerable keys
Ethereum began preparing for post-quantum threats before Drake’s latest AI warning. The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026 and has been testing hash-based validator signatures, new proof systems and post-quantum interoperability across multiple client teams.
The network’s current plan includes leanXMSS, a hash-based signature design intended eventually to replace quantum-vulnerable validator signatures. Ethereum is pairing that work with leanVM, which is intended to aggregate much larger post-quantum signatures efficiently. The roadmap targets core post-quantum infrastructure around 2029, though Ethereum describes the date as a planning target that can change.
At the wallet level, EIP-8141 is intended to give accounts more freedom over how transactions are authenticated. Ethereum’s roadmap lists the proposal for the Hegotá upgrade, currently placed in 2027, which could eventually let an account adopt a quantum-resistant signature method without moving all assets into a different address format.
As crypto.news previously reported in its analysis of Ethereum’s quantum-resistance roadmap, the network is working on replacing vulnerable ECDSA and BLS signatures while reducing its reliance on cryptographic assumptions threatened by quantum computing. More recently, crypto.news reported that EIP-8141 could allow Ethereum accounts to rotate authentication methods without requiring the user to abandon the account itself.
Hash-based signatures already have an established standard outside Ethereum. The U.S. National Institute of Standards and Technology finalized FIPS 205 in 2024, creating SLH-DSA from SPHINCS+, a hash-based digital signature scheme designed for post-quantum security.
Institutional wallet providers have begun testing separate approaches. In related coverage, crypto.news reported that BitGo tested post-quantum MPC wallet signing with Silence Laboratories, while Coinbase is designing post-quantum custody infrastructure that can adapt to whichever signature methods major blockchains eventually adopt.
Drake is scheduled to address institutional participants on Nov. 12 in London at the Ethereum Institutional Forum. The official agenda lists a 10 a.m. session titled “Post-Quantum Ethereum,” followed by a technical roadmap discussion and live Ethereum Q&A.
Powered by WPeMatico