Home Crypto Ethereum researcher warns AI could crack crypto wallets

Ethereum researcher warns AI could crack crypto wallets

0
12
Ethereum researcher warns AI could crack crypto wallets
Ethereum researcher warns AI could crack crypto wallets

Ethereum Foundation researcher Justin Drake has warned crypto users to prepare for a possible future attack on ECDSA, saying an extreme scenario could arrive “in months not years” rather than waiting for quantum computers.

Drake made the warning on Oct. 7 and urged the crypto industry to calmly prepare for what he called “bunker mode.”

His main suggestion is for users and institutions to gradually move funds to fresh addresses whose public keys have not been exposed. He said large holders and institutions should begin preparing first, rather than waiting for a potential crisis.

Drake’s warning is still only a risk scenario. There is currently no published attack showing that ECDSA has been broken using AI.

He described his worst-case situation as an attacker being able to recover a private key from a public key in roughly one week using large amounts of computing power, such as a major GPU cluster. No working attack that meets those conditions has been demonstrated.

ECDSA is an important part of how standard Ethereum accounts and many Bitcoin wallets authorize transactions. A private key is used to sign a transaction, while the public key allows the network to verify that signature.

The concern is greater for addresses whose public keys have already been exposed. On Ethereum, an account that has only received funds and has never sent a transaction generally has not revealed its public key onchain.

Once the account sends a transaction, its public key can be recovered from the signature. If a future technology could derive the private key from that public key, funds remaining in the address could become vulnerable.

Drake suggested that users who have already used an address could move their remaining funds to another unused address. This does not necessarily require a new seed phrase or a completely new wallet because fresh addresses can be generated from the same seed phrase.

Bitcoin requires some additional caution because certain address types can expose public-key information even without a previous transaction. Reusing Bitcoin addresses can also expose keys that would otherwise remain hidden.

crossorigin="anonymous">

Project Eleven has been tracking Bitcoin addresses that it considers vulnerable to future quantum attacks. Its September update identified more than 8.1 million BTC in addresses with publicly exposed key information.

Drake has urged major companies, including Binance, Bitbank, Robinhood, Bitfinex and Tether, to review their cold-storage arrangements. Being included in the tracker does not mean those wallets can currently be hacked.

Ethereum co-founder Vitalik Buterin agreed that AI-driven advances in mathematics deserve serious attention, but he warned users not to rush into wallet migrations.

Buterin said he does not recommend that people immediately move their funds into new wallets. He argued that the industry should prepare for unexpected advances in cryptography while avoiding rushed actions that could create new security risks.

His concerns also extend beyond elliptic-curve cryptography. Buterin has warned that AI-assisted mathematical breakthroughs could eventually put pressure on lattice-based cryptography as well, although there is currently no evidence that modern lattice systems have been broken.

Buterin has suggested favoring hash-based cryptography where practical because of its more conservative security assumptions.

The latest discussion was partly triggered by recent progress in AI-assisted mathematics. OpenAI published mathematical research on Oct. 6 produced with help from an internal frontier model.

However, OpenAI did not announce any attack against ECDSA, RSA or cryptocurrency wallets. Its published research includes results at different stages of verification, and some results have not yet been formally checked.

Drake has interpreted the rapid progress in AI mathematics as a reason to prepare earlier than the crypto industry might otherwise expect. His “months not years” warning remains his personal assessment of a worst-case risk, not evidence that ECDSA is currently failing.

The established quantum threat is also different from the AI scenario.

Ethereum’s own documentation says no quantum computer currently exists that can break the network’s cryptography. It does not currently require users to take action simply because of the future possibility of quantum computing.

At the same time, Ethereum is already working on longer-term defenses.

The Ethereum Foundation created a dedicated Post-Quantum Security team in January 2026. Developers are working on hash-based validator signatures, new proof systems and other technologies designed to protect Ethereum against future quantum attacks.

One of the projects under development is leanXMSS, a hash-based signature system intended to eventually replace quantum-vulnerable validator signatures. Ethereum is also working on leanVM to make it easier to process large post-quantum signatures.

The current roadmap targets major post-quantum infrastructure around 2029, although that is a planning target and could change.

Ethereum is also working on account-level changes. EIP-8141 could give accounts more flexibility over how transactions are authenticated, potentially allowing users to change their signature method without abandoning the account.

Hash-based signatures already have an established post-quantum standard. The U.S. National Institute of Standards and Technology finalized FIPS 205 in 2024, standardizing SLH-DSA, a hash-based digital signature system designed for post-quantum security.

Crypto companies are also beginning to prepare. BitGo has tested post-quantum MPC wallet signing, while Coinbase has been working on custody infrastructure that can adapt to future changes in blockchain signature technology.

For now, there is no evidence that AI has broken ECDSA or that crypto wallets are facing an immediate attack.

Drake’s warning is mainly about preparation. His message is that the industry should start planning for unexpected advances in AI and cryptography before a serious security problem appears, while Buterin’s response emphasizes that any migration should be carefully planned rather than driven by panic.