0x34f36b0034f3…34f36afd
Ethereum's Justin Drake Warns AI Could Break Wallet Crypto 'in Months'
Ethereum researcher Justin Drake says AI could break ECDSA wallet security "in months, not years" and urges a controlled migration of assets to fresh addresses.

Outputs
Justin Drake warned on Wednesday that AI could break ECDSA 'in months not years,' before quantum computers arrive.
OpenAI released hundreds of new mathematical findings on Tuesday across algebra, logic and theoretical computer science.
OpenAI said last month that 10,000 parallel AI agents solved the Navier-Stokes equation in 88 hours.
Drake recommends large holders migrate first to fresh addresses and sweep balances after each signed transaction.
Ethereum core researcher Justin Drake has urged crypto users to prepare for "bunker mode," warning that advances in artificial intelligence could break the elliptic curve digital signature algorithm securing most wallets within months rather than years.
In an X post on Wednesday, Drake said recent AI-driven mathematical breakthroughs — particularly those released by OpenAI — suggest machine systems may eventually defeat ECDSA, the signature scheme that protects private keys across major blockchains including Ethereum and Bitcoin.
"It is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years," Drake wrote, referring to "qday" as the arrival of quantum computers capable of breaking current cryptography. His warning reframes a threat timeline long associated with quantum computing into a nearer-term AI risk.
What triggered the warning?
Drake's assessment follows two recent OpenAI releases. On Tuesday, the lab published hundreds of new mathematical findings spanning algebra, theoretical computer science and mathematical logic. Last month, OpenAI said it deployed 10,000 autonomous AI agents working in parallel to solve the Navier-Stokes equation — one of the most famous unsolved problems in mathematics and physics — in 88 hours.
"Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen," Drake said.
He argued that elliptic curves are structurally more exposed than other cryptographic primitives. "Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimize algebraic structure)," he wrote.
The concern is operational rather than theoretical. Attackers who can derive private keys from exposed public keys could drain wallets at scale. Most address formats keep the public key hidden behind a cryptographic hash until a transaction is signed — which reveals it.
What does 'bunker mode' mean in practice?
Drake's recommendation is a staged migration to fresh addresses.
- Large and sophisticated holders should move funds to new addresses first.
- Any remaining balance should be shifted to a new address after signing a transaction, since signing exposes the public key.
- Migration should be gradual; a rushed transition concentrates operational risk.
"My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses," Drake said, while cautioning that "a rushed migration would do more harm than good."
The logic: funds parked at a fresh, unsigned address keep the public key concealed behind its hash, shrinking the attack surface for any adversary that needs the public key to attempt key recovery.
Business and protocol consequences
For custodians, exchanges and treasury operations, the guidance implies reviewing address hygiene policies — sweeping residual balances after each outgoing transaction and avoiding address reuse at institutional scale. For protocol teams, it sharpens the case for post-quantum and hash-based signature migration roadmaps that Ethereum researchers have debated for years.
A mass, uncoordinated migration would also stress mempools and fee markets if holders moved simultaneously, one reason Drake framed the process as controlled and sequenced rather than immediate.
No ECDSA break has been demonstrated. Drake's position is a risk-management posture based on accelerating AI capability, not a confirmed exploit — but it comes from a researcher central to Ethereum's roadmap, which gives it weight beyond typical security commentary.
The industry now faces a rolling assessment window: whether AI systems replicate or extend the curve-specific techniques Drake flagged, and whether wallet providers and custodians operationalize address-hygiene guidance before any demonstrated key-recovery attack forces a disorderly response.
via x.com (Original)