Bitcoin researcher Justin Drake has urged the blockchain industry to prepare for AI-assisted attacks on the mathematics behind Bitcoin and Ether. His warning concerns a possible breakthrough in recovering private signing keys, with a worst-case horizon of months rather than years.

Ethereum co-founder Vitalik Buterin’s response takes that possibility seriously while challenging the idea that preparing for quantum computers alone is enough. He argues that AI-driven mathematical advances could threaten other cryptographic designs too, with consequences for secure messaging, privacy tools and the wider internet. Neither researcher presented a working attack.

Drake’s October 7 post called for calmly planning “bunker mode”: a controlled shift toward addresses whose public keys remain concealed behind hashes, where the address design allows it. He focused on ECDSA, the elliptic-curve digital signature algorithm, and defined the scenario explicitly:

“IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).”

That is a forecast, not an announcement that AI has broken ECDSA. The feared advance is an efficient mathematical shortcut on existing hardware, distinct from waiting for a sufficiently powerful quantum computer. The suggested week is an example of attack speed, not a measured result.

What an AI-assisted attack would require

An AI agent can repeatedly study a problem, use tools to run experiments and assess the results. As previously reported by Apex, AI extends beyond chatbots. An agent’s ability to investigate mathematics, however, does not establish that it can solve the particular problems securing cryptocurrencies.

A candidate breakthrough would need independent reproduction and testing against real cryptographic parameters. Recovering a private key from its public counterpart would let an attacker produce valid-looking signatures for that key. It would not automatically defeat every blockchain rule or give the attacker control of the entire network.

An explanatory flowchart: an AI agent loops through tools and experiments, proposes a mathematical shortcut, and needs independently verified practical key recovery before signature forgery is demonstrated. Lattice risk, hash-based signatures and public-key encryption are distinguished.
Chart: The Apex Index. AI-assisted research and the proposed cryptographic attack pathway, not a demonstrated exploit or measured forecast. Original agent documentation and both researchers’ posts checked independently twice; reviewed October 8, 2026 UTC.

The distinction between signatures and hashing is central. Elliptic-curve signatures rely on structured mathematical problems. Hash functions are designed to resist exploitable structure. The warning is that AI might uncover shortcuts humans have missed; it is not proof that such shortcuts exist.

Buterin’s response goes beyond wallet moves

In his response, posted October 7, Buterin opened with a warning against panic:

“I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.”

His central concern is lattice-based cryptography, including ML-DSA signatures and fully homomorphic encryption, which allows computation on encrypted data. Being designed to resist known quantum attacks does not guarantee protection against new classical algorithms discovered with AI assistance.

As previously reported by Apex, a Bitcoin private key authorizes spending. Any change to the assumptions protecting that key therefore matters to ordinary holders as well as institutions.

The co-founder points to the history of integer factoring: mathematical advances made that problem substantially easier than naive methods suggested. His question is whether similarly powerful shortcuts remain undiscovered in elliptic curves or lattices. He expects lattice schemes might need much larger security parameters, potentially changing their efficiency relative to hash-based alternatives. These are his expectations, not demonstrated breaks or established replacement requirements.

For signatures and proofs, he favours hash-based designs wherever suitable. His argument is that reducing dependence on structured mathematics leaves fewer opportunities for an unexpected mathematical shortcut. He cites WOTS and SPHINCS-family signatures in Ethereum’s lean research roadmap as examples of that approach. He does not claim hashes are unbreakable.

Encryption is a harder problem. He explains:

“For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption.”

Unlike signatures, public-key encryption cannot simply replace every mathematical assumption with hashing. His response therefore urges more conservative parameters for structured primitives and cautions against permanently recording encrypted private notes on public blockchains. Data retained indefinitely could become readable if its encryption is defeated later; moving encrypted notes offchain reduces that permanent public exposure, without guaranteeing secrecy.

He also favours collecting multisignature confirmations offchain to limit public exposure of individual signers’ signatures. In his failure scenario, the signature collector remains a trusted party. That changes the trust assumptions; it does not repair broken cryptography.

What blockchains protect and what remains exposed

Bitcoin uses ECDSA for many transactions and Schnorr signatures for Taproot; both depend on elliptic-curve mathematics. Ethereum’s ordinary accounts use ECDSA, while its consensus layer uses different signatures. Transaction authorization, block commitments and consensus are separate security functions.

An explanatory diagram of a wallet signing with a private key, nodes checking signatures and state, blocks committing to data and earlier history, and consensus selecting the accepted chain. Bitcoin proof of work and Ethereum proof of stake are distinguished.
Chart: The Apex Index. How signatures, hash commitments and consensus perform different security jobs. Shared roles are schematic; Bitcoin and Ethereum implementations differ. Original protocol documentation checked twice; reviewed October 8, 2026 UTC.

Fresh addresses are also not a universal shield. Taproot outputs expose an output public key. Signing a transaction or message can disclose a key that an unused address had concealed. Wallet design and transaction history matter; migration mistakes can themselves destroy funds.

Ethereum’s published roadmap, checked on October 8, describes ongoing hash-based signature research and post-quantum infrastructure targets around 2029. Those are planning targets, not an agreed emergency deadline. The debate now is whether AI-driven mathematics requires faster preparations and how to test those changes without turning a hypothetical attack into an immediate loss through rushed migration.