0x5c3154345c31…5c315437
Ethereum's Justin Drake Urges 'Bunker Mode' After OpenAI Math Push
Justin Drake urges 'bunker mode': move assets to addresses with unexposed public keys, warning AI could compress an ECDSA break to months, not years.
Outputs
Justin Drake called for 'bunker mode' on Oct. 7, urging migration to addresses with never-exposed public keys.
OpenAI published new frontier-model mathematical results on Oct. 6, including Lean-formalized proofs.
Drake's worst case: an effective ECDSA break 'in months, not years' — a conjecture, not a demonstrated attack.
Ethereum's core post-quantum infrastructure is targeted for roughly 2029; its research retreat runs Oct. 9–12.
Drake named Binance, Bitbank, Robinhood, Bitfinex and Tether as custodians that should harden cold storage.
Ethereum researcher Justin Drake has called on the crypto industry to adopt what he terms "bunker mode," a controlled migration of assets into fresh addresses whose public keys have never been exposed on-chain. His warning, issued Oct. 7 on X, followed OpenAI's Oct. 6 release of a broad collection of new mathematical results generated by an internal frontier model.
Drake said large and sophisticated holders should consider moving most of their assets to addresses that have never signed a transaction. Once such an address sends funds, he recommended sweeping any remaining balance into another fresh address.
OpenAI said it tested its model across thousands of problems, published many resulting proofs with computer-checkable Lean formalizations, and spent roughly three hours of ChatGPT Pro reasoning on the average result. The announcement does not report a practical attack on ECDSA or RSA.
How urgent is the threat, really?
Drake's most aggressive claim concerns timing. "In the worst case," he said, an effective break of the Elliptic Curve Digital Signature Algorithm could arrive "in months, not years." That figure is a worst-case conjecture, not a demonstrated capability.
The underlying concern is concrete. Standard Ethereum externally owned accounts use ECDSA on the secp256k1 curve. Once an account sends a transaction, its public key can be reconstructed from on-chain data. An attacker capable of efficiently deriving the corresponding private key could take control of the assets.
Addresses whose public keys remain unexposed carry an additional layer of protection: only the address, a hash of the public key, is visible, according to Ethereum's documentation. The industry has traditionally framed this exposure as a future quantum-computing risk, and Ethereum's post-quantum roadmap currently targets core infrastructure for roughly 2029, subject to change.
Drake is challenging the assumption that quantum computers will arrive first. He pointed to recent surprises in mathematics and argued that sufficiently capable AI could uncover a classical algorithm that dramatically reduces the difficulty of recovering private keys — removing the need to wait for large fault-tolerant quantum machines. He cited the precedent of quantum algorithms occasionally inspiring faster classical approaches and said researchers should stay open to a classical counterpart to Shor's algorithm, which would threaten both elliptic-curve cryptography and RSA. Whether such an algorithm exists remains unknown.
Europol added separate urgency to the file. The agency warned that quantum computing could eventually undermine the cryptography protecting cryptocurrency wallets and urged the industry to begin preparing before the threat becomes practical, noting that uncertainty over timing should not delay migration because upgrading systems and coordinating defenses could itself take years.
What would 'bunker mode' change operationally?
Drake's proposed interim defense requires no new blockchain infrastructure:
- Move funds to address types that keep public keys hidden behind hashes.
- Avoid unnecessary outgoing transactions from those addresses.
- Note the exception: Bitcoin Taproot outputs expose a public key from the outset, and Taproot's Schnorr signatures still rely on secp256k1.
He urged large custodians to lead the transition, naming Binance, Bitbank, Robinhood, Bitfinex and Tether as firms positioned to harden cold-storage practices. For critical infrastructure, he suggested more aggressive precautions: oracles and layer-2 security councils could rotate ECDSA keys after signing messages, or combine existing signatures with hash-based systems such as SPHINCS.
Drake framed these measures as an interim defense, not a permanent fix. His preferred long-term approach relies heavily on hash-based cryptography, which offers less algebraic structure for future AI systems to exploit than elliptic curves, lattices or isogenies. Ethereum's roadmap already moves partly in that direction, with hash-based validator signatures and mechanisms that let individual accounts adopt different signature schemes without forcing a network-wide migration.
Drake cautioned against a rushed migration, warning that hurried transfers could create more risk than they remove. He said Ethereum's existing timelines should now be revisited as AI changes the assumptions underlying them. Ethereum's second annual post-quantum research retreat runs Oct. 9–12, and Drake plans to address institutional participants in London next month as he pushes for faster defensive preparations — a schedule that could pressure custodians to begin key-hygiene reforms well before the 2029 post-quantum target.
via x.com (Original)