0x7af6fefb7af6…7af6fefe
Buterin Warns AI Could Weaken Crypto Signatures, Urges No Panic
Buterin said AI-accelerated math could erode ECDSA and lattice defenses within two years but warned migration errors pose a bigger risk than any demonstrated break.
Outputs
Buterin warned on Oct. 7 that AI-driven math advances could weaken existing crypto signatures and some post-quantum defenses
OpenAI published machine-generated mathematical proofs formalized in Lean on Oct. 6, reporting no blockchain attack
NIST standardized ML-DSA as a post-quantum signature algorithm in 2024; Buterin flagged lattice cryptography as at risk over the next two years
Ethereum's lean roadmap has shifted toward hash-only systems, avoiding ML-DSA and Falcon signatures
Buterin said key sizes could need to grow by as much as ten if AI sharply improves cryptanalysis
Ethereum co-founder Vitalik Buterin warned on Oct. 7 that AI-driven advances in mathematics could weaken both existing cryptocurrency signatures and some post-quantum defenses, while advising holders against rushing funds into new wallets.
Writing on X, Buterin said: "I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously."
His comments came two days after OpenAI published new mathematical results generated by an internal frontier model, including machine-generated proofs formalized in Lean. OpenAI reported no attack on blockchain cryptography, and neither Buterin nor Ethereum researcher Justin Drake claimed evidence that ECDSA has been practically broken.
Why the debate intensified now
Drake had earlier called for the industry to prepare for "bunker mode," including moving assets toward fresh addresses whose public keys have never been exposed on-chain. He raised the possibility that AI could accelerate mathematical attacks on the elliptic-curve cryptography securing Bitcoin and Ethereum.
Buterin extended the concern further. He singled out lattice-based cryptography, including ML-DSA — which NIST standardized in 2024 as a post-quantum digital-signature algorithm under FIPS 204 — as an area where AI-driven mathematical discovery could erode assumed security margins over the next two years.
He compared the risk to the history of integer factorization. The general number field sieve dramatically reduced the computational work required to attack RSA compared with naive methods, forcing systems to adopt much larger keys. AI could compress decades of similar mathematical progress into a far shorter window, he argued.
"If AI will bring us 50 years of math in 2 years," Buterin wrote, those advances could include breakthroughs that substantially improve attacks on lattice cryptography.
What does Ethereum's roadmap change?
The concern helps explain a growing developer preference for hash-based designs. Buterin said Ethereum's "lean" roadmap has shifted toward hash-only systems over the past year, avoiding lattice-based signatures such as ML-DSA and Falcon and reducing reliance on lattice-based commitments inside zero-knowledge proofs.
Hash-based signature systems, including WOTS and SPHINCS, play a larger role in that direction because they depend less on mathematical structure that could yield unexpected shortcuts. Elliptic curves rely on group operations and other exploitable relationships; lattice systems depend on families of difficult problems whose practical resistance could change if attackers find more efficient methods.
The approach has limits. Public-key encryption used in secure messaging, anonymous communications and websites cannot generally be built from hashes alone, because those applications require a trapdoor allowing authorized users to decrypt. Buterin suggested such systems may eventually need substantially larger parameters — key sizes multiplied by as much as ten could become reasonable if AI sharply improves cryptanalysis.
The consequences would extend beyond blockchains. Secure messaging, VPNs, Tor, encrypted web traffic and privacy protocols could face similar trade-offs between performance and wider security margins.
Should users migrate funds now?
For holders, the immediate precautions are narrower. Users who can keep funds in addresses that have never signed a transaction gain additional protection, because their public keys remain hidden behind address hashes until the first spend.
Multisig operators could reduce exposure by gathering signatures off-chain and rotating signer keys after operations, limiting how long an exposed key remains useful if ECDSA security deteriorates.
Buterin nonetheless warned against treating these steps as an emergency migration order. He said he has personally lost more money through failed migrations than through hacks.
That framing leaves wallet providers, custodians and protocol developers with a harder task than simple key rotation: they must prepare for faster-moving cryptographic risk while avoiding upgrade paths that introduce operational failures of their own. With Ethereum's lean roadmap already de-emphasizing lattice-based constructions and OpenAI's math results now public, the two-year window Buterin cited is likely to shape cryptographic procurement and protocol design decisions well before any quantum deadline arrives.
via x.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles