Justin Drake, a researcher at the Ethereum Foundation, posted on 7 October asking the industry to begin what he called "bunker mode", a controlled migration of coins to addresses whose public keys have never appeared on a blockchain. Artificial intelligence may find a mathematical shortcut that breaks the signatures protecting bitcoin and ether, he argued, and in the worst case the break would arrive "in months not years".
Signatures are what prove a transaction came from the owner of the coins. Bitcoin and Ethereum both rely on ECDSA, short for the elliptic curve digital signature algorithm, and the scheme's security rests on a single assumption. Anyone can see the public key, but nobody is supposed to be able to work backwards from it to the private key the owner holds.
Drake set a threshold for what a break would look like in practice: "fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster)". No such result has been demonstrated or published, a point carried in most accounts of his post.
Where The Shortcut Would Come From
Drake raised the possibility of an ordinary, non-quantum algorithm with effects comparable to Shor's algorithm, the quantum method that would break elliptic-curve cryptography. It is "now reasonable to brace for the possibility that ECDSA breaks before Q-Day", he wrote, using the industry's name for the day a quantum machine becomes capable of breaking it. No quantum computer features in the threat he describes.
OpenAI's release on 6 October of machine-generated mathematics is what he pointed to as evidence, 722 manuscripts from an unreleased model, most carrying proofs written out in Lean, a language that lets a computer check each step. "Recent days have been humbling for human mathematical intuition," he wrote. "Long-held, unquestioned hypotheses have fallen." AI, in his account, is the thing that finds the shortcut rather than the thing that attacks.
Elliptic curves worry him because they are rich in mathematical structure, and he named several well-known techniques from that mathematics as the kind of machinery an attacker might turn to its advantage. Hash functions, the one-way scramblers used to turn data into a fixed-length fingerprint, are "designed to minimize algebraic structure", which is why his longer-term proposal moves Ethereum towards signatures built on hashes instead.
Coinbase's Cryptographer Pushes Back
Yehuda Lindell, who heads cryptography at Coinbase and teaches at Bar-Ilan University in Israel, answered the next day. "To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography," he wrote, calling the post "the very definition of FUD", the industry's shorthand for fear spread without proof.
"It cannot be proven wrong but there's also no evidence whatsoever of it being true," Lindell added, which puts his objection on what can be tested rather than on timing. Making such statements without evidence, he wrote, "is the opposite of responsible behavior".
Adam Back, the cryptographer who runs Blockstream, replied with a single word, "fud-burger", and Alpen Labs engineer Jose Storopoli wrote that "extraordinary claims demand extraordinary evidence". Haseeb Qureshi of the investment firm Dragonfly took the other side, calling the post "a very sober call" while drawing a distinction of his own: "The risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions."
Ethereum co-founder Vitalik Buterin landed between the two camps on the same day. "I don't recommend anyone scramble to move their funds to new wallets today," he wrote, while also saying that "we should take the risks to cryptography from AI-accelerated math seriously". He added that he has "lost more money in botched migrations than I have lost in all hacks combined".
Lattice-based cryptography, which builds its security on the difficulty of finding short paths through a vast grid of points, could itself "take serious hits from the next two years of AI math", Buterin wrote, pushing the problem outwards rather than containing it. Two of the three post-quantum standards the US National Institute of Standards and Technology finalised in 2024 are built on lattices, which leaves the hash-based third as the one his reasoning favours.
6.26M Bitcoin Sit Exposed
Glassnode co-founder Rafael Schultze-Kraft gave the amount of bitcoin sitting behind a visible public key as 6.26M on 8 October, which is 31.2% of the coins in circulation. The research firm counted 6.04M in May and 222,000 more exposed coins since, against only 64,000 coins of new issuance in the same stretch.
A public key stays hidden behind a scrambled fingerprint inside most modern bitcoin addresses, and it becomes visible on the blockchain the first time coins are spent from that address. Once visible it stays visible, so the arithmetic assumption is the only thing left between those coins and anyone who breaks it.
Glassnode published the first version of this count in May, months before the AI argument surfaced, and built it for the quantum threat instead. Its method separates coins whose script reveals the key by design, including the earliest address format Bitcoin used and the modern Taproot format, from coins exposed because the owner spent from an address and left funds behind.
Exchange balances made up 1.79M of the October figure, measured as the share of each firm's own bitcoin that sits behind a visible key. Robinhood came out at 100%, Revolut at 99% and Binance at 83%, while the bitcoin held by the US, UK and El Salvador governments showed no exposure at all.
Bitcoin's Own Migration Plan
Developers have had a post-quantum plan on the table since 2024, and the timetable inside it runs to years rather than months. Hunter Beast, Ethan Heilman and Isabel Foxen Duke drafted Bitcoin Improvement Proposal 360, known as BIP-360, which would create an output type that never exposes a public key while coins sit still. It remains a draft, and Beast has estimated that a full migration would take seven years from the day the community agrees to one.
Jameson Lopp and five co-authors went further in a second proposal, BIP-361, published on GitHub in April 2026. It would bar new coins from being sent to vulnerable address formats after roughly three years, then have nodes reject old-style signatures after about five years, freezing whatever has not moved by then.
More than 6M bitcoin could be caught that way, including the roughly 1.7M in early addresses widely attributed to Satoshi Nakamoto. For those, the proposal concedes that no proof of ownership can be constructed, because the coins predate the wallet standard such a proof would rely on.
Operators shutting down older 2G and 3G mobile networks have run into the same mechanism from the other end, with devices going dark because nobody moved them to a newer network in time. A frozen bitcoin would differ in one respect: it stays visible on the ledger while being impossible to spend.
Bitcoin traded near $82,000 on 8 October, down from about $86,600 the previous day, and the analysts quoted that day pointed instead to $487M of outflows from spot bitcoin funds, rising US bond yields and hawkish Federal Reserve minutes. None of the coverage tied the fall to the warning.
The Timelines Do Not Line Up
Nobody has demonstrated a working attack on bitcoin or ether keys, and no cryptanalytic result pointing to one has been published. Drake attached no probability to his estimate and framed it as a worst case, and his practical proposal needs no new cryptography at all, only addresses that have never signed anything.
NIST's transition guidance deprecates today's elliptic-curve cryptography after 2030 and disallows it after 2035, Ethereum's post-quantum work points to 2029, and a 2025 survey of 26 specialists put the chance of a capable quantum machine inside ten years at 28% to 49%. Drake's worst case of months sits well short of all of them.