0x016d70b7016d…016d70b4
Ethereum's Justin Drake Says AI May Break ECDSA Before Quantum Computers
Ethereum Foundation researcher Justin Drake says AI could break ECDSA before quantum computers, urging a controlled migration to addresses with hidden public keys.
Outputs
Justin Drake warned ECDSA could break 'in the worst case in months not years' due to AI-driven math advances.
Drake cited 722 mathematical results published by OpenAI on Tuesday as a sign cryptographic assumptions are weakening.
Roughly 20,000 exposed Satoshi-era addresses holding 50 BTC each would likely be attacked first, he said.
In March, Drake put the odds of Q-Day by 2032 at 10% or more.
The Ethereum Foundation formed a dedicated post-quantum team earlier this year.
Ethereum Foundation researcher Justin Drake has called on the blockchain industry to begin planning for "bunker mode," warning that artificial intelligence could break ECDSA — the signature scheme securing Bitcoin and Ethereum — before quantum computers do, "in the worst case in months not years."
In a post on X on Wednesday, Drake recommended "a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash." The proposal does not require new cryptography or wallets: funds would move to addresses that have never signed a transaction, keeping their public keys shielded.
"Today I call upon the blockchain industry to calmly begin planning for 'bunker mode,'" Drake wrote. He urged holders not to panic or rush.
Why does exposed ECDSA put wallets at risk?
ECDSA is the signature scheme Bitcoin and Ethereum use to prove a transaction was authorized by the correct private key. When a wallet signs its first transaction, its public key becomes visible on-chain. If the scheme were broken, an attacker could derive the private key from that exposed public key and drain the wallet.
By "break," Drake specified recovering a private key in about a week on available hardware, such as a large GPU cluster. He said it is now reasonable to prepare for ECDSA breaking before Q-Day — the point at which quantum computers can crack today's encryption.
What is driving the accelerated timeline?
Drake pointed to a burst of AI-driven mathematical progress, including 722 results OpenAI published on Tuesday, as evidence that long-held cryptographic assumptions are weakening. "Elliptic curves feel especially vulnerable to superintelligence," he wrote, arguing their rich mathematical structure leaves room for clever attacks that hash functions are designed to resist.
That asymmetry underpins his recommendation: hash-based addresses, which never expose their public keys, remain safe even if elliptic-curve signatures fall.
Which custodians did Drake single out?
Drake urged major custodial firms to harden their cold storage, naming:
- Binance
- Bitbank
- Robinhood
- Bitfinex
- Tether
He also noted a partial mitigation for small holders. Wallets holding less than 50 BTC benefit from what he called "Satoshi's shield": roughly 20,000 exposed addresses tied to Bitcoin's creator, each holding 50 BTC, which attackers would likely target first.
How does this fit Ethereum's roadmap?
The warning escalates a debate that has run through 2026. In March, after a Google paper suggested quantum computers could break crypto's cryptography sooner than expected, Drake put the odds of Q-Day by 2032 at 10% or more.
The Ethereum Foundation formed a dedicated post-quantum team earlier this year, and co-founder Vitalik Buterin has already laid out plans to move the network toward quantum-resistant cryptography.
Drake said Ethereum's shift to hash-based cryptography should now be accelerated. "I'll be pushing for maximum defensive acceleration," he wrote.
The immediate operational question for exchanges, custodians and large holders is sequencing: whether a staged migration to unexposed addresses can be completed before AI-assisted cryptanalysis — or a quantum breakthrough — forces it as an emergency measure rather than a planned one.
via x.com (Original)