{"id":24175,"date":"2026-10-08T09:05:12","date_gmt":"2026-10-08T09:05:12","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/10\/08\/ethereum-researcher-warns-ai-could-crack-crypto-wallets\/"},"modified":"2026-10-08T09:05:12","modified_gmt":"2026-10-08T09:05:12","slug":"ethereum-researcher-warns-ai-could-crack-crypto-wallets","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/10\/08\/ethereum-researcher-warns-ai-could-crack-crypto-wallets\/","title":{"rendered":"Ethereum researcher warns AI could crack crypto wallets"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2026\/07\/Ethereum1.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">Ethereum Foundation researcher Justin Drake has urged crypto holders to prepare for a possible AI-assisted break of ECDSA, warning on Oct. 7 that a worst-case failure could arrive \u201cin months not years\u201d before quantum computers pose the expected threat.<\/p>\n<div id=\"cn-block-summary-block_a1965cfc36f9004cca7ab4fd054102b5\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Justin Drake urged crypto holders to plan moves toward fresh addresses with unexposed public keys.<\/li>\n<li>Vitalik Buterin backed taking AI cryptography risks seriously but warned users against rushing wallet migrations.<\/li>\n<li>Ethereum already has a dedicated post-quantum team targeting core quantum-resistant infrastructure around 2029 for completion.<\/li>\n<li>NIST standardized hash-based SLH-DSA in 2024, providing an established post-quantum signature option for digital systems.<\/li>\n<li>Project Eleven tracks millions of Bitcoin addresses with exposed public keys that could face attacks.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Drake\u2019s Oct. 7 <a href=\"https:\/\/x.com\/drakefjustin\/status\/2107837081313505768\" target=\"_blank\">post on X<\/a> called for the blockchain industry to begin calmly planning for what he described as \u201cbunker mode.\u201d His proposal centers on gradually moving funds into fresh addresses whose public keys have not been exposed, with large holders and institutions taking the first steps. Drake repeatedly warned against panic and said a poorly managed migration could create its own risks.<\/p>\n<p>The warning remains a risk scenario, not evidence that ECDSA has been broken. Drake defined his worst case as an attacker recovering a private key from a public key within roughly a week using available hardware such as a large GPU cluster. No working attack meeting that description has been published.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Why the Ethereum researcher wants fresh addresses<\/strong><\/h2>\n<p>ECDSA is used to authorize transactions from standard Ethereum accounts and plays a central role in securing Bitcoin wallets. A private key creates a signature, while the corresponding public key lets the network verify that signature without revealing the private key.<\/p>\n<p>Ethereum\u2019s official post-quantum documentation <a href=\"https:\/\/ethereum.org\/roadmap\/security\/quantum-resistance\/\" target=\"_blank\">explains<\/a> that an ordinary Ethereum account which has only received funds and never sent a transaction has not exposed its public key onchain. Once the account signs a transaction, its public key can be recovered from the signature. A future method capable of deriving a private key from that public key could therefore threaten remaining funds.<\/p>\n<p>Drake recommended that holders who use an address move any remaining assets into another unused address after signing. He said the process could use addresses generated from the same seed phrase, meaning his immediate proposal does not require a new wallet format or new cryptographic algorithm.\u00a0<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Today I call upon the blockchain industry to calmly begin planning for &#8220;bunker mode&#8221;. My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.<\/p>\n<p>Holders, starting with large\u2026<\/p>\n<p>\u2014 Justin Drake (@drakefjustin) <a href=\"https:\/\/x.com\/drakefjustin\/status\/2107837081313505768?ref_src=twsrc%5Etfw\">October 7, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Bitcoin requires some extra distinction because not every unused address hides its public key. Project Eleven says address types including P2PK and Taproot can expose public-key information without prior spending, while address reuse exposes keys for several other address types. Its Bitcoin Risq List tracked more than 8.1 million BTC in addresses it classified as quantum-vulnerable in its Sept. 14 update.<\/p>\n<p>Drake specifically pointed to the tracker while urging Binance, Bitbank, Robinhood, Bitfinex and Tether to examine their cold-storage setups. The tracker identifies addresses based on publicly visible key exposure; inclusion does not mean an attacker can currently derive their private keys.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Vitalik Buterin warns users not to rush<\/strong><\/h2>\n<p>Ethereum co-founder Vitalik Buterin has responded to the warning by supporting more caution around AI-assisted mathematics without calling for an immediate movement of funds.<\/p>\n<p>Buterin said he \u201c[doesn\u2019t] recommend anyone scramble\u201d to move money into new wallets today. He argued that crypto developers should still take AI-driven advances in mathematics seriously and reduce dependence on cryptography that could prove weaker than expected.<\/p>\n<p>His concern extends beyond elliptic curves. Buterin said the concrete security of lattice-based cryptography could face pressure from AI-assisted mathematical discoveries over the next two years, though he did not claim any lattice system has been broken. He favors hash-based designs where they can be used and recommends more conservative parameters for systems that rely on lattices.<\/p>\n<p>For individual holders, Buterin said keeping funds in addresses that have never made a transaction can be useful when it is easy to do safely. He warned that mistakes during rushed migrations can themselves cause losses, reinforcing Drake\u2019s call for a controlled process instead of an emergency move.<\/p>\n<h2 class=\"wp-block-heading\"><strong>OpenAI math release did not break ECDSA<\/strong><\/h2>\n<p>Drake tied the timing of his warning to rapid progress in AI-assisted mathematics, including OpenAI\u2019s Oct. 6 publication of mathematical research produced by an internal frontier model.<\/p>\n<p>OpenAI\u2019s <a href=\"https:\/\/openai.com\/index\/sharing-ai-progress-in-mathematics\/?utm_source=chatgpt.com\" target=\"_blank\">official announcement<\/a> said the work covers a range of mathematical results and includes supporting proof material. The public repository currently contains 722 manuscripts across 372 result families, produced after the model was tested on roughly 4,000 research problems.<\/p>\n<p>OpenAI did not announce an attack against ECDSA, RSA or cryptocurrency wallets. Its repository states that the results are at different stages of verification, that not every manuscript has a Lean formalization and that some unformalized results \u201ccould have issues.\u201d<\/p>\n<p>Drake interpreted the speed of recent mathematical advances much more aggressively, writing that \u201cmathematical superintelligence is upon us.\u201d He questioned whether new classical algorithms assisted by AI could find shortcuts against elliptic-curve systems before quantum computers become capable of running Shor\u2019s algorithm at the scale needed to attack them. His timing remains a personal risk assessment rather than a demonstrated cryptographic break.<\/p>\n<p>Ethereum\u2019s current documentation takes a less urgent position on the established quantum threat. It states that no quantum computer today can break Ethereum\u2019s cryptography and says current users do not need to take action solely because of quantum computing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Ethereum is already preparing to replace vulnerable keys<\/strong><\/h2>\n<p>Ethereum began preparing for post-quantum threats before Drake\u2019s latest AI warning. The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026 and has been testing hash-based validator signatures, new proof systems and post-quantum interoperability across multiple client teams.<\/p>\n<p>The network\u2019s current plan includes leanXMSS, a hash-based signature design intended eventually to replace quantum-vulnerable validator signatures. Ethereum is pairing that work with leanVM, which is intended to aggregate much larger post-quantum signatures efficiently. The roadmap targets core post-quantum infrastructure around 2029, though Ethereum describes the date as a planning target that can change.<\/p>\n<p>At the wallet level, EIP-8141 is intended to give accounts more freedom over how transactions are authenticated. Ethereum\u2019s roadmap lists the proposal for the Hegot\u00e1 upgrade, currently placed in 2027, which could eventually let an account adopt a quantum-resistant signature method without moving all assets into a different address format.<\/p>\n<p>As crypto.news previously reported in its <a href=\"https:\/\/crypto.news\/vitalik-buterin-to-make-ethereum-quantum-resistant\/?utm_source=chatgpt.com\" target=\"_blank\">analysis of Ethereum\u2019s quantum-resistance roadmap<\/a>, the network is working on replacing vulnerable ECDSA and BLS signatures while reducing its reliance on cryptographic assumptions threatened by quantum computing. More recently, crypto.news reported that <a href=\"https:\/\/crypto.news\/ethereum-eip-8141-could-remove-need-for-users-to-hold-eth-for-gas\/?utm_source=chatgpt.com\" target=\"_blank\">EIP-8141 could allow Ethereum accounts to rotate authentication methods<\/a> without requiring the user to abandon the account itself.<\/p>\n<p>Hash-based signatures already have an established standard outside Ethereum. The U.S. National Institute of Standards and Technology finalized FIPS 205 in 2024, creating SLH-DSA from SPHINCS+, a hash-based digital signature scheme designed for post-quantum security.<\/p>\n<p>Institutional wallet providers have begun testing separate approaches. In related coverage, crypto.news reported that <a href=\"https:\/\/crypto.news\/bitgo-tests-quantum-safe-mpc-wallet-signing-with-silence-labs\/?utm_source=chatgpt.com\" target=\"_blank\">BitGo tested post-quantum MPC wallet signing<\/a> with Silence Laboratories, while <a href=\"https:\/\/crypto.news\/coinbase-plans-post-quantum-bitcoin-custody\/?utm_source=chatgpt.com\" target=\"_blank\">Coinbase is designing post-quantum custody infrastructure<\/a> that can adapt to whichever signature methods major blockchains eventually adopt.<\/p>\n<p>Drake is scheduled to address institutional participants on Nov. 12 in London at the Ethereum Institutional Forum. The official agenda lists a 10 a.m. session titled \u201cPost-Quantum Ethereum,\u201d followed by a technical roadmap discussion and live Ethereum Q&amp;A.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/researcher-warns-ai-could-crack-crypto-wallets\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ethereum Foundation researcher Justin Drake has urged crypto holders to prepare for a possible AI-assisted break of ECDSA, warning on Oct. 7 that a worst-case failure could arrive \u201cin months not years\u201d before quantum computers pose the expected threat. Summary Justin Drake urged crypto holders to plan moves toward fresh addresses with unexposed public keys. [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":24115,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-24175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/24175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=24175"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/24175\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/24115"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=24175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=24175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=24175"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=24175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}