Ethereum researcher Justin Drake's AI cryptography warning divides industry
Ethereum Foundation researcher Justin Drake urged the crypto community to prepare for "bunker mode" over concerns that AI could break wallet cryptography within months, sparking sharp pushback from industry experts as Bitcoin slipped below $83,000.

Justin Drake, an Ethereum Foundation researcher, urged the cryptocurrency industry to begin planning for "bunker mode" following OpenAI's release of 722 mathematical results. Drake warned that rapid advances in artificial intelligence could uncover classical mathematical shortcuts that recover private keys from exposed ECDSA public keys in "months not years," potentially threatening wallet signatures before quantum computers do. He recommended an orderly migration of holdings to fresh addresses whose public keys remain hidden behind a hash.[2][3][4][9][10]
Drake emphasized that current cryptography has not failed and cautioned against panic, warning that rushed migrations could cause more harm than good. Under his proposal, users—beginning with large custodians including Binance, Robinhood, Bitbank, Bitfinex, and Tether—should avoid address reuse and sweep remaining funds into fresh addresses after every transaction. However, OpenAI's published work did not demonstrate any practical attack on ECDSA or RSA, leaving Drake's timeline as a worst-case conjecture.[3][4][9][10]
The warning provoked fierce pushback across the sector. Coinbase cryptography lead Yehuda Lindell called the post "a really bad take" and said there is no evidence pointing to a break of elliptic-curve cryptography, while Ledger chief technology officer Charles Guillemet labeled the months-long timeline "FUD" and warned that user mistakes during transfers carry greater operational risks. Ethereum co-founder Vitalik Buterin advised users not to scramble, noting he had lost more money to botched migrations than hacks, though he agreed that avoiding address reuse is prudent. Amid the unfolding community debate, Bitcoin slipped below $83,000 on Oct. 8.[1][6][8][10][11]
Key facts
- Ethereum Foundation researcher Justin Drake urged the crypto industry to plan for "bunker mode" by migrating assets to fresh addresses that have never signed a transaction.
- Drake warned that AI-accelerated mathematics could theoretically allow private key recovery from ECDSA public keys in "months not years," arriving ahead of quantum computers.
- Drake stated that present-day cryptography has not been broken and warned that a disorderly, rushed migration could cause more harm than good.
- OpenAI's published drop of 722 mathematical results contained no reported practical attacks on ECDSA or RSA cryptography.
- Coinbase cryptography lead Yehuda Lindell and Ledger CTO Charles Guillemet criticized the warning, with Lindell noting there is no evidence pointing to a break in elliptic curve cryptography.
- Vitalik Buterin recommended against scrambling to move funds, warning he has lost more money in botched migrations than hacks, while still calling unexposed addresses a good practice.
- Bitcoin fell below $83,000 on October 8, 2026, as the community debated Drake's warning.
Sources · 10 sources
- KO
kook@KookCapitalLLCPost on X ·
justin drake told the whole industry to start planning a mass migration of everyones coins to fresh addresses bunker mode..... vitalik came out and said dont scramble to move your funds and that he personally lost more money in botched migrations than in all hacks combined mert said absolutely dont take justins advice the biggest threat to your coins is still you lmao
Open source - BT
Bull Theory@BullTheoryioPost on X ·
🚨 ETHEREUM RESEARCHER JUST WARNED THAT AI COULD HACK BITCOIN AND ETHEREUM WALLETS SOON This is not the first time a warning like this has spread fear across crypto. In March, Google Quantum AI published a paper estimating that breaking the cryptography behind Bitcoin and Ethereum would need fewer than 500,000 physical qubits, about 20x fewer than earlier estimates. Google's Willow chip has 105 qubits today, and the paper says no quantum computer can run the attack yet. Justin Drake of the Ethereum Foundation co authored the paper. He puts at least 10% odds on a quantum computer recovering a private key by 2032. That warning was about quantum computers. The new warning, from yesterday, is about AI. On Oct 6, OpenAI published 722 math papers from a model it has not released. On Oct 7, Drake posted that AI math could break ECDSA, the signature method behind Bitcoin and Ethereum, in the worst case within months. HERE'S WHAT HE'S WARNING: Every wallet has a private key and a public key. The private key lets you spend. An address is a hash of the public key. The public key stays hidden until you spend from the address, and after that it is visible on the blockchain permanently. If someone could calculate the private key from a public key, they could move the coins. Nobody knows a way to do that in practical time today. Drake defines a break as recovering a private key in about 1 week on a large GPU cluster. His comparison is RSA, an older system. Researchers found faster ways to factor numbers over decades, and RSA keys had to grow from 64 bytes to about 400 bytes. He asks whether elliptic curves have a similar shortcut that has not been found, and whether AI will find it. The evidence shows less than the fear suggests. No weakness in ECDSA has been shown by anyone. Drake asks whether ECDSA is "too good to be true." None of OpenAI's reported papers are about cryptography. They cover pure math and physics problems, such as number theory and models of magnetism. OpenAI says many proofs are computer checked but not all, some may contain errors, and no outside group has reviewed them yet. The RSA comparison is not an exact match. The RSA shortcuts took decades of work by many researchers, and elliptic curves have been studied since the mid 1980s with no practical attack published on the curve Bitcoin uses. AI could speed this up, but that speed up is an assumption. Coinbase's head of cryptography, Yehuda Lindell, says there is "no evidence whatsoever" that elliptic curves are close to failing. This is not something to panic about today. It is a risk to plan for. Using a break would also be hard to do at scale. The quantum attack needs hardware that is about 4,700x larger than Willow's 105 qubits. Drake's AI scenario takes about 1 week of a large GPU cluster to recover a single key, so an attacker could only go after a few wallets at a time. And Only part of the supply is exposed. A March paper by Ark Invest and Unchained estimated 34.6% of Bitcoin supply, about 6.9M BTC, has a visible public key: - 5M BTC in reused addresses. - 1.7M BTC in old P2PK addresses. - 200K BTC in Taproot addresses. The other 65.4% has its public key hidden. Holders keep it hidden by not reusing addresses. Hash functions are not the target. Bitcoin mining and address hashing use them, and both Drake and Vitalik treat them as the most secure part of the system. If you hold crypto, here is what you should do: 1. Use a new address for every receive. Most modern wallets can do this automatically. 2. Check whether your coins sit in an address that has already sent a transaction. Its public key is visible, so move those coins to a new address. 3. Taproot addresses show the public key from the start, so a fresh Taproot address gives no protection from this risk. 4. Ethereum works the same way. Once an account sends a transaction, its public key is visible. Large holders can use multisig wallets with confirmations collected offchain. That keeps signatures private, and if ECDSA breaks, the wallet falls back to being controlled by whoever collects the signatures, instead of anyone being able to take the money. Two problems are still open. The first is the 1.7M BTC in old P2PK addresses, which are assumed to be lost. A draft proposal called BIP-361, written by Jameson Lopp and five co-authors in April, would handle them in phases: 1. 3 years after activation, no new BTC can be sent to old-style addresses. 2. 5 years after activation, old-style signatures are invalidated and coins left in vulnerable addresses are frozen. 3. Later, a zero knowledge proof method would let owners who missed the deadline recover frozen funds if they still have their seed phrase. It has no activation date. Critics call it confiscation and Metaplanet's Phil Geiger said, "We have to steal people's money to prevent their money from being stolen." The second is encryption. Hashes cannot replace public key encryption, which secures websites, messaging apps and VPNs, so the issue goes beyond crypto. Vitalik also warns that lattice based cryptography, the main option for quantum safe encryption, could lose security from AI math as well. So far, no one has shown that AI can break ECDSA, and no quantum computer can run the attack today. What exists today is a known weak spot. About 6.9M BTC has a visible public key, and holders can reduce that exposure by moving coins to fresh addresses.
Open source - PR
ProtosArticle ·
Initiate ‘bunker mode’ to protect crypto from AI, says Justin Drake Senior Ethereum Foundation researcher Justin Drake, who has spent months warning about the supposedly imminent cybersecurity threat of quantum computing, has escalated his rhetoric with a prediction that AI will “break” elliptic curve cryptography within “months.” Warning the threat could arrive even faster than quantum computers, he’s calling for a mass migration of most crypto assets into new wallets suited for deep cold storage. He wants the whole industry, starting with the largest entities, to hide their money from an impending AI breakthrough that he views as essentially inevitable. He’s implored everyone to create and store most digital tokens in new “bunker” wallets that have never signed a transaction. These more private wallets with less information revealed on public ledgers will, in Drake’s view, help digital asset owners stay safe during the first wave of attacks. The post is, in essence, a description of a well-known best practice by BTC holders: never re-using addresses. Satoshi Nakamoto even wrote in October 2008: “A new key pair should be used for each transaction to keep them from being linked to a common owner.” Explaining this concept as though it was novel, Drake thanked Satoshi’s large and highly public wallets that will ostensibly shield smaller investors from the first wave of attacks. Make no mistake, however, Drake believes the AI is coming for everyone soon. I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.… — vitalik.eth (@VitalikButerin) October 7, 2026 Crypto should enter bunkers and cower from the AI With yesterday’s viral X post, Drake asked the industry to commence “bunker mode,” a mass migration to fresh addresses, in a post that drew millions of views. He implores the largest entities and their billionaire operators to get their assets into bunkers first. Drake even named four of the largest custodians by name: Changpeng Zhao’s Binance, Vlad Tenev’s Robinhood, Babak Zanjani’s Bitbank, and Giancarlo Devasini’s Bitfinex and Tether. Four companies with billionaire leadership will guide the industry to safety. A wallet that has never transacted, such as a “bunker” BTC wallet in Drake’s view, exposes only a hash of its public key on-chain. This privacy contrasts with a wallet which has transacted and published its raw public key within its transaction signatures. Because only the hash of a “bunker” wallet is publicly accessible, a quantum attacker who can break Bitcoin’s Elliptic Curve Digital Signature Algorithm must first hack the public key hash and then hack its associated private key to steal any BTC. This extra step of requiring the AI- or quantum-powered hacker to reverse engineer the public key hash first, before reversing the private key, might protect bunkered savers from the first wave of attacks, Drake predicts. A rational AI or quantum hacker might decide to start with the easiest targets: wallets with exposed public keys, such as Satoshi’s wallets. Bitcoin’s quantum deadline just moved up Read more: Cloudflare’s 2029 quantum sprint raises Bitcoin alarm bells Crypto bunker life In Drake’s worldview of bunker life, never-transacting wallets function like deep cold storage, never transacting except in the event of emergency. Any transaction must immediately accompany a full sweep of funds into another, new, never-transacted wallet — ideally within the same block of transactions. He admits plainly, “Exiting bunker mode safely will require post-AI cryptography” that doesn’t currently exist in consensus for blockchains like Bitcoin. In March, Drake co-authored Google Quantum AI’s well-publicized paper suggesting that breaking the Elliptic Curve Digital Signature Algorithm (ECDSA) could occur within 1,200 logical qubits, a 20-fold reduction in the prior understanding of physical hardware requirements for that quantum breakthrough. In June, Drake forecasted Q-day, i.e. the day quantum computers crack major forms of modern cryptography, at “10% by 2030” and “50% by 2032.” Drake’s new fear is non-quantum AI computers. On Tuesday, OpenAI published a trove of AI-generated mathematical results. He interprets the batch as a sign that mathematical superintelligence has arrived. He warned, “In my opinion it is now reasonable to brace for the possibility that ECDSA breaks before Qday, in the worst case in months not years.” Got a tip? Send us an email securely via Protos Leaks . For more informed news and investigations, follow us on X , Bluesky , and Google News , or subscribe to our YouTube channel. The post Initiate ‘bunker mode’ to protect crypto from AI, says Justin Drake appeared first on Protos .
Open source - CR
CryptoSlateArticle ·
OpenAI math breakthroughs raise ‘bunker mode’ alarm from Bitcoin researcher Justin Drake OpenAI’s latest advances in mathematics have prompted a leading Ethereum researcher to warn that crypto’s core wallet security could face an unexpected AI threat . On Oct. 7, Ethereum researcher Justin Drake urged the blockchain industry to prepare for what he described as “bunker mode,” including a controlled migration of digital assets into fresh addresses whose public keys have never been exposed. Drake said large and sophisticated holders should consider moving most of their assets to addresses that have never signed transactions. Once those addresses are used to send funds, he recommended transferring any remaining balance into another fresh address. His warning followed OpenAI’s Oct. 6 release of a broad collection of new mathematical results produced by an internal frontier model. The company said it tested the model across thousands of problems, published many of the resulting proofs with computer-checkable Lean formalizations and spent the equivalent of about three hours of ChatGPT Pro reasoning on the average result. Drake argued that the accelerating pace of AI-driven mathematical discovery should force the crypto industry to reconsider assumptions about how long elliptic-curve cryptography will remain secure. “In the worst case,” he said, an effective break of the Elliptic Curve Digital Signature Algorithm, or ECDSA, could arrive “in months, not years.” OpenAI’s announcement does not report a practical attack on ECDSA or RSA. Drake’s months timeline is a worst-case conjecture, not a demonstrated capability. Drake warns AI could shorten crypto’s security timetable Bitcoin and Ethereum rely heavily on elliptic-curve cryptography to establish ownership and authorize transactions. Standard Ethereum externally owned accounts use ECDSA on the secp256k1 curve. Once an account sends a transaction, its public key can be reconstructed from information placed onchain. Someone capable of efficiently deriving the corresponding private key could then take control of the assets. Standard Ethereum accounts whose public keys remain unexposed have an additional layer of protection: only the address, a hash of the public key, is visible, Ethereum’s documentation says. The industry has traditionally treated that problem primarily as a future quantum-computing risk. Ethereum has already established a dedicated post-quantum security effort, with work underway on hash-based signatures, account abstraction and replacements for other cryptographic systems vulnerable to sufficiently powerful quantum computers. Core post-quantum infrastructure is currently targeted for roughly 2029, although the roadmap remains subject to change. Drake is challenging the assumption that quantum computing will necessarily be the first technology capable of breaking those systems. He pointed to recent surprises in mathematics and argued that sufficiently capable AI could uncover a classical algorithm that dramatically reduces the difficulty of recovering private keys. That would change the industry's timetable because it would remove the need to wait for large fault-tolerant quantum computers. Drake cited the precedent of quantum algorithms occasionally inspiring faster classical approaches and said researchers should remain open to a classical counterpart to Shor’s algorithm, which would threaten both elliptic-curve cryptography and RSA. Whether such an algorithm exists remains unknown. Europol separately added urgency to the broader issue, warning that quantum computing could eventually undermine cryptography protecting cryptocurrency wallets and urging the industry to begin preparing before the threat becomes practical. The agency said uncertainty over timing should not delay migration because upgrading systems and coordinating defenses could itself take years. Crypto holders could start moving before cryptography changes Drake’s proposed response does not require waiting for new blockchain infrastructure. Drake proposed moving funds to addresses that keep public keys hidden behind hashes and avoiding unnecessary outgoing transactions. That protection depends on the address type: Bitcoin Taproot outputs expose a public key from the outset. Taproot also uses Schnorr signatures rather than ECDSA, although both rely on the secp256k1 curve. Drake urged large custodians to lead that transition, specifically naming Binance , Bitbank, Robinhood , Bitfinex and Tether as firms with an opportunity to harden cold-storage practices . He also recommended more aggressive precautions for critical blockchain infrastructure. Oracles and layer-2 security councils, for example, could rotate ECDSA keys after signing messages or combine existing signatures with hash-based systems such as SPHINCS. Those measures would amount to an interim defense rather than a permanent solution. Drake said his preferred long-term approach would rely heavily on hash-based cryptography, which has less algebraic structure for future AI systems to exploit than elliptic curves, lattices or isogenies. Ethereum is already moving partly in that direction. Its post-quantum roadmap includes hash-based validator signatures and mechanisms designed to let individual accounts eventually adopt different signature schemes without requiring the entire network to migrate at once. Drake cautioned against a rushed migration, warning that hurried transfers could create more risk than they remove. But he said Ethereum’s existing timelines should now be revisited as AI changes the assumptions underlying them. Ethereum’s second annual post-quantum research retreat is scheduled for Oct. 9 to Oct. 12, while Drake said he plans to address institutional participants in London next month as he pushes for faster defensive preparations. The post OpenAI math breakthroughs raise ‘bunker mode’ alarm from Bitcoin researcher Justin Drake appeared first on CryptoSlate .
Open source - TM
That Martini Guy ₿@MartiniGuyYTPost on X ·
Ethereum researcher Justin Drake is warning the crypto industry to prepare for “bunker mode.” He believes advances in AI could accelerate mathematical breakthroughs that eventually threaten ECDSA, the cryptography securing major blockchains. His worst-case scenario? Private keys becoming recoverable in “months, not years.” Drake says there is no reason to panic, but large holders and institutions should start gradually moving funds to fresh addresses with unexposed public keys. Nothing has been broken today. But if AI-driven mathematical breakthroughs move faster than expected, the cryptographic assumptions protecting billions in crypto could face a completely new threat. The industry may need to prepare before that threat becomes reality.
Open source - CO
CoindeskArticle ·
Bitcoin slips below $83,000 as Ethereum researcher's 'bunker mode' call divides crypto Justin Drake's call to prepare for an AI break of wallet cryptography drew a mixed response as bitcoin slipped below $83,000.
Open source - CO
CoindeskArticle ·
Bitcoin and ether holders urged to enter ‘bunker mode’ against possible AI attacks Ethereum researchers warned AI could break the signatures guarding bitcoin, ether and the tokens built on them "in months, not years" in the worst case, well before quantum computers arrive.
Open source - LS
Laura Shin@laurashinPost on X ·
Justin Drake's "bunker mode" proposal has split crypto experts. Haseeb Qureshi called it a "very sober call," while Yehuda Lindell and Ledger's Charles Guillemet pushed back. https://t.co/AoJMzKkpnU
Open source - TB
The Block@TheBlockCoPost on X ·
THE BLOCK: Ethereum Foundation researcher Justin Drake is urging the crypto industry to begin planning for "bunker mode," recommending a controlled migration of assets to fresh addresses that have never signed a transaction, keeping their public keys hidden behind a hash. Drake said it is now reasonable to prepare for the possibility that AI could enable fast recovery of private keys from ECDSA public keys, potentially within "months not years." "Don't rush," Drake said, warning that a disorderly migration could cause more harm than good.
Open source - UN
UnchainedArticle ·
Ethereum Researcher’s ‘Bunker Mode’ Call Sparks Debate Over Whether AI Math Threatens Crypto Keys Ethereum Foundation researcher Justin Drake called on Oct. 7 for the blockchain industry to “calmly begin planning” for “bunker mode,” a controlled shift of holdings to new addresses whose public keys stay hidden behind a hash. He tied the call to OpenAI’s release of 722 mathematical results the day before, writing that it is “reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years.” ECDSA is the signature scheme most Bitcoin and Ethereum accounts use. Drake did not claim a break has occurred. He stressed “Don’t rush,” and suggested that large holders consider shifting most of their holdings to addresses that have not yet signed a transaction. Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . Critics Push Back Yehuda Lindell , who leads cryptography at Coinbase, called the post “a really bad take” and said there is “no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.” Ledger CTO Charles Guillemet wrote that assuming ECDSA could fall to a classical attack within months as the working scenario “still looks like FUD.” He called avoiding address reuse “reasonable for large holders,” but said a mass migration could create “operational mistakes that lose funds with higher probability than the scenario being mitigated.” Dankrad Feist argued that if exposed public keys become exploitable and white-hat hackers do not secure everyone’s assets first, “your coins are going to zero,” and bunker mode “is not going to help you.” Helius’s Mert Mumtaz wrote in a post “absolutely do not take justin’s advice btw” and called Drake’s post “an unnecessarily performative post” in the same message. Dragonfly’s Haseeb Qureshi backed the warning, calling it “a very sober call,” saying the risk is conventional mathematics overturning “unproven cryptographic hardness assumptions.” Buterin Counsels Caution Vitalik Buterin wrote in a post that he does not recommend anyone “scramble to move their funds to new wallets today,” though the risks from AI-accelerated math should be taken seriously. He added that ECDSA “might fall even faster than expected,” and that keeping funds in addresses that have not made a transaction “is a good idea” if it is easy. He cautioned: “I personally have lost more money in botched migrations than I have lost in all hacks combined.” He named lattice-based schemes such as ML-DSA as a core new area of risk. Jacob Creech argued Solana users do not need bunker mode because its keys derive from a hashed seed that is never exposed onchain. Drake wrote that the Ethereum roadmap’s timelines “must now be revisited and accelerated” in light of what he called mathematical superintelligence. Related Listen: The Chopping Block: Ethereum’s Identity Crisis, Apostates Speak Out, and Is ETH the Microsoft of Crypto? The post Ethereum Researcher’s ‘Bunker Mode’ Call Sparks Debate Over Whether AI Math Threatens Crypto Keys appeared first on Unchained .
Open source - CR
Crypto Rover@cryptoroverPost on X ·
BREAKING: If you own crypto, this is SCARY. Ethereum researcher Justin Drake warns that new AI models could break the cryptography securing Bitcoin and Ethereum within MONTHS. His advice: Move your crypto to fresh, unused wallets. https://t.co/42fNLLSOQy
Open source

