Weather     Live Markets

AI’s Shadow Over Crypto: How One Post Shook Ethereum’s Faith in Math

Ether Slides as AI Math Fears Rattle Crypto’s Security Foundation

Ether fell 3.9% over the 24 hours to Thursday afternoon, changing hands at $2,471, while Bitcoin slipped a comparatively modest 2.0% to $81,664, according to CoinGecko. The selloff was not triggered by a hack, a regulatory crackdown, or a macroeconomic shock. It was the aftershock of a single essay. Justin Drake, a researcher at the Ethereum Foundation, published a long-form post on Oct. 6 arguing that advances in AI-assisted mathematics could soon undermine the cryptographic foundations of blockchain technology — potentially exposing funds on networks that rely on standard elliptic curve signatures. His recommendation: move assets to “bunker” addresses that have never signed a transaction, and pressure the industry to accelerate its post-quantum migration plans. The response was immediate and polarized. Within two days, the post had drawn rebuttals and endorsements from leading cryptographers, exchange security chiefs, and rival blockchain founders, while Ethereum’s price fell to its lowest level of the week. What makes the episode remarkable is not just the caliber of the back-and-forth, but the fact that both camps agree on the underlying trend: AI is getting better at mathematics at a pace that few experts anticipated. The disagreement is about whether that progress constitutes a near-term threat to the specific mathematical problems that keep crypto assets secure — or whether it is, as one prominent computer scientist put it, “the very definition of FUD.” Drake’s post did not emerge from a vacuum. It landed in a market already wrestling with large language models that can now produce formal proofs, and against a backdrop of quantum computing research that has made steady, if incremental, progress. But while quantum threats have been discussed for years in abstract terms, Drake’s argument was concrete: the same AI models accelerating drug discovery and chip design are also getting dangerously close to the kind of mathematical reasoning that could one day find cracks in the hardened problems that secure digital signatures. Whether that day comes in two years or twenty, the episode has forced the crypto industry to confront a question it has long preferred to defer. For a sector that prides itself on mathematical certainty, the uncertainty itself was enough to move markets.

Coinbase’s Lindell Calls It ‘The Very Definition of FUD’

Yehuda Lindell, a computer science professor at Bar-Ilan University on leave and the chief technology officer at Coinbase, opened his response by admitting he had planned to stay silent. “I wasn’t going to comment since this is a really bad take IMO, but since it’s taken off I feel the need to,” he wrote. “To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.” Lindell, one of the most widely cited researchers in applied cryptography, drew a sharp distinction between what AI can do in formal theorem proving and what it would take to break a cryptographic assumption. “The fact that AI can prove theorems that have been hard does not indicate in any way that problems assumed to be hard are not,” he argued. Proving theorems that are hard for humans is a fundamentally different activity from overturning the conjectured difficulty of problems that the entire internet relies on. “Our assumptions on hard problems are not based merely on human fallibility but on a belief that inherent hardness exists,” he wrote. He also rejected Drake’s claim that elliptic curves are more exposed than hash functions — a claim that has gained traction in some corners of crypto Twitter. “There’s also zero evidence that elliptic curve hardness is more vulnerable than hash function hardness,” Lindell wrote. “In fact historically hash functions have been more broken than elliptic curves.” His conclusion was blunt: “Making such statements without any evidence is the opposite of responsible behavior. It is the very definition of FUD — it cannot be proven wrong but there’s also no evidence whatsoever of it being true.” Pressed on Thursday about Coinbase’s own preparations, Lindell acknowledged that the exchange is “indeed getting ready to support hash-based signatures for the potential quantum era,” but reiterated that there is no basis for the claim that AI will break elliptic curves faster than hashes — “and there are actually very good reasons to say the opposite.” Two days before Drake’s post, Lindell had flagged a cryptanalytic result of a different kind: researchers at UC San Diego and INRIA Nancy had forged 1024-bit RSA signatures using roughly 1,380 CPU core-years of precomputation and access to a signing oracle. The attack, he noted, does not recover the key — and the authors are human.

Buterin Redirects the Threat: Lattices, Not Elliptic Curves

Vitalik Buterin split the difference Wednesday evening, accepting the threat model while rejecting the urgency — and redirecting the target. “I don’t recommend anyone scramble to move their funds to new wallets today,” the Ethereum co-founder wrote. “But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.” His warning lands on the schemes the industry has been migrating toward. “The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices,” he wrote, naming the Module-Lattice-Based Digital Signature Algorithm standardized by the National Institute of Standards and Technology, fully homomorphic encryption, and the lattice problems both rest on. “So far most people have been in the mode of thinking ‘elliptic curves broken, hashes safe, lattices safe.’ But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.” Buterin framed the risk through the history of factoring, where decades of human work cut the cost of attacking RSA. “What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover — but bots soon will be?” He tied the concern to Ethereum’s “lean” roadmap, which has been hash-only for the past year — no lattices, no ML-DSA, no Falcon, and no lattice-based commitments inside zero-knowledge proofs. Signatures in lean Ethereum use WOTS or SPHINCS+. On Drake’s actual recommendation, Buterin endorsed it with a caveat drawn from his own record. “If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.” He followed up Thursday morning with a correction on multisig wallets, writing that the ideal rule is for each signer to change their key after each operation.

‘We Might Lose Public Key Cryptography’: Experts Split

The wider security community split along predictably doctrinal lines. Dankrad Feist, a researcher at Tempo and formerly at the Ethereum Foundation, attacked the remedy rather than the premise. “If elliptic curves are broken so that any exposed public key leads to compromise, and it’s not by white hat hackers who save everyone’s assets first, your coins are going to zero,” he wrote. “Having them in bunker mode is not going to help you. They are still worth zero.” The post drew 154,000 views. Charles Guillemet, Ledger’s chief technology officer, made the same point about scope. A working private-key recovery attack on secp256k1, the curve Bitcoin and Ethereum use, “would not stay confined to Bitcoin and Ethereum,” he wrote. “It would compromise TLS, code signing, most banking systems, and a large fraction of deployed public-key infrastructure at once.” Matthew Green, who teaches cryptography at Johns Hopkins University, took the other side. “I think we might lose public key cryptography,” he posted Wednesday evening. The seven-word post has 1.4 million views and 4,500 likes. In a thread Thursday afternoon he set out what he meant. Losing public-key encryption “does not mean cryptography or encryption is impossible,” he wrote. “It does mean that we imminently see new cryptanalytic results that substantially improve our ability to attack standardized schemes.” Green’s argument turns on who has been doing the analysis. The underlying problems “have been extensively analyzed by humans. We felt good that the best known attacks were the best attacks. But we’re learning that human mathematical analysis isn’t the gold standard,” he wrote. He addressed the absence of cryptanalysis in OpenAI’s release directly: “If you think the frontier labs aren’t paying cryptanalysts to work on these results with their internal models, you’re very wrong.” Lindell replied that improvements on factoring are likely but bounded: “For EC, nothing has been found over generic algs for 30 years so no I don’t think AI will change that.” Haseeb Qureshi, managing partner at Dragonfly, backed Drake within two hours of the original post. “Doomerism has now hit cryptography,” he wrote. “Unfortunately, on reflection, I think this is a very sober call.”

Solana, NEAR, and Bitcoin Seize the Moment

Two rival chains used the thread to position their own cryptography. Jacob Creech, vice president of technology at the Solana Foundation, wrote that “unlike many networks, Solana users don’t need to go into ‘bunker mode.'” Solana uses Ed25519, where each signing key is derived by hashing a secret seed that never appears onchain. Breaking the curve would expose the derived key but not the seed, he wrote, and a one-time network upgrade would let owners prove knowledge of the seed with a hash-based proof and move to a new signature scheme. Anza has published a proof of concept. Illia Polosukhin, NEAR’s co-founder, called the framing itself the problem. “Doomerism approach is never a helpful framing, even if it starts with ‘calmly’ and with best intentions,” he wrote Thursday. “Going ‘bunker mode’ is not practical nor a safe approach given how complex it is in operations.” His alternative is key rotation at the account level. NEAR accounts can add, remove and rotate keys, and the chain “already supports post-quantum ML-DSA,” he wrote, with hash-based cryptography planned. That is the scheme Buterin named as the new risk area a day earlier. Polosukhin’s conclusion: “Upgrading cryptography should be a routine operation, not a crisis response.” Bitcoin developers read the recommendation as a description of practice they already follow. “Only an Ethereum developer would think that not reusing addresses is ‘Bunker mode,'” wrote Juan Galt, a reporter at Bitcoin Magazine. Adam Back, the Blockstream chief executive who invented hashcash, replied with “fud-burger.” He elaborated Thursday on the account model behind the advice: Ethereum users “store their entire transaction history with an architecture of static reused address, and to top it off they get a .eth address with their handle to self-dox.” Bitcoin’s Taproot addresses use Schnorr signatures and keep public keys hidden until a spend, a point Drake made in the original post.

What Actually Set Off the Firestorm

The debate traces back to a single publication. Drake posted a day after OpenAI released a set of new mathematical results produced by an unreleased internal model, with Lean formalizations of many of the proofs, on Oct. 6. The company says the average result used roughly three hours of ChatGPT Pro-equivalent compute. None of the published results concern cryptanalysis — a fact that both sides have wielded with equal confidence. Drake cited three recent results as evidence that mathematical intuition is failing: the fall of the n log(n) bound for integer multiplication, the 3SUM conjecture, and May’s disproof of the Erdős unit distance conjecture, which he called “our warning shot.” His skeptics counter that these are advances in pure mathematics, not in the computational hardness of cryptographic primitives. Drake has not posted publicly since, and had not replied to any of the critics as of Thursday afternoon New York time. He framed the recommendation as personal rather than institutional, and said he will address institutions at a live Q&A in London next month. The Ethereum Foundation set out a post-quantum key registry as the first concrete migration step earlier this year, and launched a post-quantum research hub before that. Drake’s post asked for those timelines to be “revisited and accelerated.” Whether the industry heeds that call will depend on which of these experts the market chooses to believe. For now, the price action suggests traders are not yet panicking — but the debate itself has already shifted the terms of conversation. A year ago, “quantum” was the doomsday word. Today, the fear has a new name: artificial intelligence. What is clear is that the conversation has moved from theoretical caution to active contingency planning. Even the sharpest critics of Drake’s post concede that the industry should be preparing for a world in which cryptographic assumptions fail. The only real argument is over how fast that world is approaching.

Share.
Leave A Reply

Exit mobile version