0x3814f0133814…3814f010

ConfirmedSecurity691 vB101 sat/vB3 min decode

Ethereum's Drake Warns AI Could Break Wallet Crypto 'in Months'

Ethereum researcher Justin Drake urged large holders to move funds to fresh addresses, warning AI could break wallet signature math "in months, not years" — years before the network's 2029 quantum deadline.

Outputs

  1. Justin Drake warned AI could break bitcoin and ether wallet signatures 'in months, not years' in the worst case.

  2. OpenAI released 722 mathematical manuscripts on Tuesday from an unreleased model tested on about 4,000 research problems.

  3. The Bitcoin Red Team used AI to sweep 390 projects in ~27 hours, logging nearly 5,000 flaws, 85 rated critical.

  4. A July 30 Coldcard firmware exploit drained at least 1,367 BTC; Coinkite suspected AI helped find the flaw.

  5. The Ethereum Foundation targets December 2029 for quantum-resistant cryptography.

Ethereum researcher Justin Drake has called on the blockchain industry to begin planning for "bunker mode," warning that artificial intelligence could break the signature mathematics protecting bitcoin and ether wallets in the worst case "in months, not years" — well before quantum computers arrive.

"Today I call upon the blockchain industry to calmly start planning for 'bunker mode,'" Drake wrote on X on Wednesday, urging large holders to gradually shift funds to fresh addresses whose public keys have never appeared onchain.

No practical attack on Bitcoin or Ethereum wallet keys has been demonstrated, and none appeared in the research reviewed. But Drake's concern is specific: AI may find a shortcut that lets an attacker recover a private key from its public key on ordinary computers, eliminating the need for the quantum machines the industry has spent years preparing against.

Why the exposure is broad

The threat model is structural, not hypothetical. Millions of bitcoin sit in addresses with public keys already visible onchain. On Ethereum, any account that has ever sent a transaction has exposed its key — and the stablecoins and tokenized funds issued on the network rely on that same signature system.

Drake said elliptic curves, the math behind bitcoin and ether signatures, follow tidy patterns a powerful enough AI could learn to exploit. Hash functions, by contrast, are built to scramble information with minimal pattern.

What triggered the warning?

The catalyst was OpenAI's release on Tuesday of 722 mathematical manuscripts produced by an unreleased model tested on roughly 4,000 research problems. Some findings carry computer-checkable proofs; others remain unverified and could contain errors, the company said.

The manuscripts came from the model OpenAI said last month had solved the Navier–Stokes problem, one of seven Millennium Prize challenges. Each result used, on average, computing power equal to roughly three hours of ChatGPT Pro reasoning. Within a day, an outside researcher reran the computer check on one result — a new limit on how fast computers can multiply large matrices, a question open since 1969 — and found it held.

AI attacks are already costing money

The theoretical risk sits atop a growing record of real AI-assisted exploits:

  • Last December, Anthropic researchers showed frontier models could write working exploits against simulated copies of real DeFi contracts.
  • In late July, the volunteer Bitcoin Red Team used AI models to sweep 390 Bitcoin software projects in about 27 hours, logging nearly 5,000 possible flaws, 85 rated critical.
  • On July 30, an attacker began draining Coldcard hardware wallets through a five-year-old firmware bug, taking at least 1,367 BTC; maker Coinkite said it suspected AI helped find the flaw.
  • Days later, BTCPay Server confirmed thefts from merchants' Lightning nodes through a flaw first surfaced in an AI-assisted audit, and on Aug. 27 Core Lightning's developers issued an emergency warning after AI-generated bug reports turned up real vulnerabilities.

What did Buterin say?

Ethereum co-founder Vitalik Buterin agreed the risk extends beyond today's wallets to some quantum-resistant replacements. Lattice-based cryptography underpins a digital-signature standard approved by the U.S. National Institute of Standards and Technology, and Buterin said it may not hold.

"There is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math," Buterin wrote on X. "If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a 'naive factoring -> GNFS' level of improvement to our ability to break lattices."

Ethereum's proposed long-term rebuild increasingly favors hash-based signatures, which Buterin sees as offering fewer openings for unexpected shortcuts — though he acknowledged they too could face attacks.

He backed reducing public-key exposure where practical but told holders not to rush. "I personally have lost more money in botched migrations than I have lost in all hacks combined," he wrote.

The timing gap is the core operational problem: the Ethereum Foundation has set December 2029 as its target for quantum-resistant cryptography, while Drake's worst case puts a classical break years ahead of that deadline.

via CoinDesk (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles