Experts in the cryptocurrency sector should begin preparing for what Justin Drake, a researcher at the Ethereum Foundation, refers to as "bunker mode," as the ECDSA digital signature algorithm could be compromised even before sufficiently powerful quantum computers become available.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don’t rush. While I believe there is cause for action a rushed migration would do more harm than good. Don’t panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May’s unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday’s OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I’ve witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11’s "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I’ll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi’s shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I’ll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026
Drake noted that ECDSA is utilized for authorizing transactions in Bitcoin and Ethereum networks. When he speaks of a potential breach, he refers to the ability to swiftly recover a private key from the public one, potentially achievable on a large GPU cluster in as little as a week.
He also indicated that this scenario could materialize in "months rather than years," emphasizing that this is a possible risk rather than an established fact.
New Addresses as a Defense
The public key becomes visible on the blockchain once the owner signs their first transaction, remaining hidden behind a hash prior to that point.
Consequently, Drake advised cryptocurrency holders, particularly those who are large and technically savvy, to keep the majority of their assets in new addresses that have not yet initiated transactions. He recommended that after each transaction, any remaining balance should be moved to a different wallet.
He framed this advice as a personal suggestion and urged against panic, warning that hasty migrations could be more detrimental than beneficial.
Drake also encouraged major platforms like Binance, Bitbank, Robinhood, Bitfinex, and Tether to consider enhancing the security of their cold storage.
Risks Beyond Quantum Computers
Drake tied his warning to the rapid advancements in AI within mathematics, citing the recent publication by OpenAI of 722 papers produced by an unreleased internal model.
He suggested that this indicates the emergence of a "mathematical superintelligence." OpenAI has cautioned that the results are at various stages of vetting, and some may contain inaccuracies.
Drake posited that novel mathematical techniques could potentially break cryptography based on elliptic curves and RSA on conventional computers, without the need for quantum technology. He attributed the vulnerability of these systems to their intricate mathematical structures, which can be exploited in attacks. He deemed hash functions more reliable due to their lower structural complexity.
To safely exit "bunker mode," the expert concluded that cryptography resilient to AI attacks will be necessary.
Buterin's Viewpoint
Ethereum co-founder Vitalik Buterin advised against succumbing to panic but also emphasized the importance of not underestimating the risks associated with AI.
I don’t recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it’s also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover — but bots soon will be? This is a major part of the reason why for the past year ethereum’s lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
— vitalik.eth (@VitalikButerin) October 7, 2026
"I do not recommend anyone rush to transfer their funds to new wallets today," he wrote.
Buterin supported the idea of keeping funds in addresses that have not yet been used for transactions, but only if it is not cumbersome. He also cautioned against the risks associated with migration.
"Personally, I have lost more money due to botched migrations than I have lost in all hacks combined," the programmer noted.
For multi-signature wallets, Buterin suggested that confirmations be gathered off-chain. This way, the signatures of the signer wallets remain private, ensuring that if ECDSA is compromised sooner than anticipated, the wallet effectively reverts to a scheme where the control remains with the individual collecting the signatures—much safer than a situation where anyone could access the funds.
Moreover, the Ethereum co-founder called for a serious approach to the threats posed by AI-accelerated mathematics to cryptography. He indicated that there is a need to reduce reliance not only on algorithms vulnerable to quantum computers but also on those potentially susceptible to AI.
He identified lattice-based cryptography as a significant new area of concern, currently viewed as a primary defense against quantum attacks. Notably, the standardized NIST digital signature algorithm ML-DSA and FHE are based on this approach.
Buterin speculated that AI could advance mathematical knowledge by 50 years over the next two years, significantly undermining the practical resilience of such schemes. In this scenario, while lattices may remain in use, they would require significantly larger parameters to ensure the same level of security. For long-term protection, he recommended increasing key sizes tenfold.
Where feasible, the Ethereum co-founder favored exclusively hash-based constructions. This preference has driven Lean Ethereum's development over the past year, where all signatures are hash-based.
It is worth noting that in March, the Ethereum Foundation unveiled a roadmap to secure the network against quantum computers, aiming for completion by 2029. In June, Nicolas Consigny, head of the Kohaku project at EF, proposed a post-quantum account protection scheme SPHINCS- that does not require a hard fork.
Follow ForkLog on social media Telegram (main channel) Facebook X