Ethereum

Ethereum Researcher Warns A.I. Could Break Blockchain Encryption Before Quantum Computers

Ethereum coin lying on a computer mainboard
An Ethereum coin on a computer mainboard. © Kanchanara / Unsplash

Set Trending Topics as a preferred source on Google.

For years, quantum computers were seen as the biggest threat to Bitcoin and Ethereum. Now they may have competition from artificial intelligence: Justin Drake, a researcher at the Ethereum Foundation, called on the crypto industry on Wednesday on X to “calmly begin planning for ‘bunker mode.’” His concern: In the worst case, the signature schemes that Bitcoin and Ethereum rely on could be broken “in months not years,” and by A.I.-driven mathematics.

What Alarmed the Ethereum Researcher

At the center is ECDSA, the elliptic-curve signature scheme that Bitcoin and Ethereum use to prove that a transaction was authorized by the right private key. As soon as a wallet signs a transaction, its public key becomes visible on the blockchain. If ECDSA were broken, attackers could work backward from that public key to the private key and drain the wallet. By “break,” Mr. Drake means recovering a private key in about a week on available hardware such as a large GPU cluster.

Mr. Drake pointed to the flood of A.I. results in mathematics. OpenAI just released hundreds of new math results from an unreleased model. For Mr. Drake, that is a sign that long-held assumptions are falling. “Elliptic curves feel especially vulnerable to superintelligence,” he wrote. Their rich mathematical structure leaves room for clever attacks that hash functions are specifically designed to resist, he argued.

What Bunker Mode Means

Mr. Drake is proposing a controlled, mass migration: Funds should gradually be moved to fresh addresses that have never signed a transaction. With such addresses, the public key is still hidden behind a hash and therefore protected for now. There is no need to panic or rush, Mr. Drake stressed, since the move requires neither new cryptography nor new wallets.

He specifically called on large custodians: Binance, Bitbank, Robinhood, Bitfinex and Tether should harden their cold storage. Smaller Bitcoin holders with less than 50 BTC also enjoy some protection from what Mr. Drake calls “Satoshi’s shield.” That refers to roughly 20,000 addresses with exposed keys that are attributed to Bitcoin’s creator, Satoshi Nakamoto, each holding 50 BTC. They would likely be the first targets of an attack.

For Ethereum itself, Mr. Drake wants to accelerate the planned shift to hash-based cryptography. “I’ll be pushing for maximum defensive acceleration,” he wrote. The Ethereum Foundation set up a dedicated post-quantum team earlier this year, and quantum-safe infrastructure is currently planned for around 2029. Next-generation cryptography also plays a central role in Vitalik Buterin’s vision for Ethereum through 2030.

Buterin Urges Calm

The Ethereum co-founder takes the warning seriously but is pumping the brakes on the pace. The risk from A.I.-accelerated math deserves more attention, he said, but users should not scramble to move their funds to new wallets today. Drawing on his own experience, Mr. Buterin warned against rushed moves: Botched migrations have cost him more money than all hacks combined. In the long run, he favors hash-based signature schemes such as WOTS and SPHINCS and wants to avoid lattice-based schemes where alternatives exist, because he considers them potentially vulnerable to A.I. as well.

Others think the warning is overblown. Yehuda Lindell, head of cryptography at Coinbase, sees “no evidence whatsoever” that the assumptions behind elliptic-curve cryptography are close to failing, and said A.I.’s mathematical achievements are no evidence against ECDSA. Samson Mow, chief executive of the Bitcoin company Jan3, told his followers there was no need to panic just because “an Ethereum researcher is saying silly things.” OpenAI has not presented a practical attack on ECDSA either, and Mr. Drake’s time frame is a worst-case scenario.

Google Puts Q-Day at 2029

Until now, the debate has mainly revolved around so-called Q-Day: the moment when a quantum computer becomes powerful enough to break today’s common public-key encryption, including RSA and elliptic-curve cryptography. Shor’s algorithm makes that possible by solving, on a sufficiently large quantum computer, exactly the mathematical problems that classical computers cannot.

For a long time, Q-Day was considered a problem for the 2030s. In the spring, however, Google announced that it would move its authentication services to quantum-safe cryptography by 2029, because hardware, error correction and resource estimates are advancing faster than expected. Mr. Drake then put the odds of Q-Day by 2032 at 10 percent or more. What is new about his latest warning is that A.I. could overtake the problem before a quantum computer is even ready.

Where Bitcoin Stands in the Debate

For Bitcoin, the discussion is further along than the implementation. According to an analysis by Glassnode, about 6 million bitcoin, or roughly 30 percent of the supply, sit in addresses whose public keys are already visible. The asset manager CoinShares concluded in February, by contrast, that only about 10,000 BTC in larger wallets would be a realistic near-term target. The exposed holdings also include Taproot addresses, which reveal their public keys immediately.

Two proposals dominate the debate. BIP-360 was added as a draft to the official repository of Bitcoin Improvement Proposals in February. It introduces a new address type called Pay-to-Merkle-Root (P2MR) that removes Taproot’s quantum-vulnerable spending path. It has not been activated, which would require a soft fork with broad consensus across the network. BIP-361, put forward in April by the Bitcoin developer Jameson Lopp and others, goes further: Three years after activation, bitcoin could no longer be sent to vulnerable addresses, and after five years, legacy ECDSA and Schnorr signatures would become invalid. Coins not migrated by then would effectively be frozen, according to CoinDesk, and a later recovery via zero-knowledge proof is still at the research stage.

That is exactly what divides the community. Critics see freezing coins as a break with Bitcoin’s core principle that whoever holds the private key controls the coins, and call it confiscation. The authors see the proposal as purely defensive: In an emergency, the alternative to frozen coins would be stolen ones. Adam Back, chief executive of Blockstream, considers the quantum threat decades away anyway and has floated hash-based signatures as a long-term option. Whether Mr. Drake’s A.I. scenario will push Bitcoin developers to move faster remains to be seen.

Rank My Startup: Erobere die Liga der Top Founder!
Advertisement
Advertisement

Specials from our Partners

Top Posts from our Network

Deep Dives

© Wiener Börse

IPO Spotlight

powered by Wiener Börse

Europe's Top Unicorn Investments 2023

The full list of companies that reached a valuation of € 1B+ this year
© Behnam Norouzi on Unsplash

Crypto Investment Tracker 2022

The biggest deals in the industry, ranked by Trending Topics
ThisisEngineering RAEng on Unsplash

Technology explained

Powered by PwC
© addendum

Inside the Blockchain

Die revolutionäre Technologie von Experten erklärt

Trending Topics Tech Talk

Der Podcast mit smarten Köpfen für smarte Köpfe
© Shannon Rowies on Unsplash

We ❤️ Founders

Die spannendsten Persönlichkeiten der Startup-Szene
Tokio bei Nacht und Regen. © Unsplash

🤖Big in Japan🤖

Startups - Robots - Entrepreneurs - Tech - Trends

Continue Reading

Newsletter

Founders Dispatch

Zwei Mal pro Woche kostenlos in die Inbox: die wichtigsten Startups, Deals und Tech-Entwicklungen aus Europa, handgeschrieben von der Redaktion.

Jederzeit abbestellbar. Mehr über den Newsletter