Key Highlights:
- Crypto industry leaders, cryptographers, and blockchain developers are engaged in an intense debate over whether rapid advances in artificial intelligence could break public-key cryptography and elliptic curves.
- Vitalik Buterin advised caution without panic, highlighting lattice-based cryptography as a potential risk area under AI-accelerated mathematics, while Yehuda Lindell characterized elliptic curve break claims as unsupported FUD.
- Market prices dropped alongside the discourse, with Ether falling 3.9% to $2,471 and Bitcoin dipping 2.0% to $81,664 over a 24-hour window.
Cryptographers Clash Over AI Math and Hardness Assumptions
A contentious debate has erupted across the cryptocurrency sector regarding whether advancements in artificial intelligence pose an existential threat to foundational cryptography. The discussion was catalyzed after an Ethereum researcher suggested that users consider protective measures such as moving funds into unused addresses to prevent public-key exposure. The suggestion followed an October 6 release by OpenAI showcasing advanced mathematical proofs generated by an unreleased internal model using the Lean formalization language. Against the backdrop of the discourse, CoinGecko data showed Ether declining 3.9% over 24 hours to Thursday afternoon to trade at $2,471, while Bitcoin fell 2.0% to $81,664.
Yehuda Lindell, a professor of computer science on leave from Bar-Ilan University and chief cryptographer at Coinbase, forcefully pushed back against warnings that elliptic curve cryptography (ECC) faces an imminent collapse. Lindell dismissed the speculation, stating: I wasn’t going to comment since this is a really bad take IMO, but since it’s taken off I feel the need to. To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.
Lindell clarified that mathematical theorem-proving does not equate to subverting computational hardness, adding, The fact that AI can prove theorems that have been hard does not indicate in any way that problems assumed to be hard are not. Our assumptions on hard problems are not based merely on human fallibility but on a belief that inherent hardness exists.
Lindell also challenged assertions regarding the relative strength of hash functions versus curves: There’s also zero evidence that elliptic curve hardness is more vulnerable than hash function hardness. In fact historically hash functions have been more broken than elliptic curves. So this is also based on conjecture rather than any evidence.
He concluded that Making such statements without any evidence is the opposite of responsible behavior. It is the very definition of FUD â it cannot be proven wrong but there’s also no evidence whatsoever of it being true.
Asked about Coinbase’s roadmap, Lindell stated that the exchange is indeed getting ready to support hash-based signatures for the potential quantum era. But there is no basis to say that AI will break ECC more than hashes, and there are actually very good reasons to say the opposite.
Buterin and Green Evaluate the Theoretical Threat Landscape
Ethereum co-founder Vitalik Buterin offered a nuanced viewpoint, cautioning against rushed actions while identifying future areas of technical concern. I don’t recommend anyone scramble to move their funds to new wallets today,
Buterin wrote. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
Rather than focusing purely on traditional curves, Buterin raised flags over emerging post-quantum algorithms: The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices,
referencing the Module-Lattice-Based Digital Signature Algorithm standardized by the National Institute of Standards and Technology (NIST), fully homomorphic encryption, and underlying lattice mathematics. So far most people have been in the mode of thinking âelliptic curves broken, hashes safe, lattices safeâ. But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
Buterin drew historical parallels to RSA factoring optimizations, asking, What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover â but bots soon will be?
He noted that Ethereum’s lean roadmap has adopted a hash-only profileâomitting lattices, ML-DSA, Falcon, and lattice-based commitments in zero-knowledge proofs in favor of Winternitz One-Time Signatures (WOTS) or SPHINCS+. While acknowledging the utility of avoiding address reuse, Buterin cautioned: If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.
He later clarified that for multisignature setups, signers ideally rotate keys following each operation.
Taking a more pessimistic stance, Johns Hopkins University cryptography professor Matthew Green declared, I think we might lose public key cryptography.
Elaborating on the claim, Green clarified that this outcome does not mean cryptography or encryption is impossible,
but rather It does mean that we imminently see new cryptanalytic results that substantially improve our ability to attack standardized schemes
âpotentially dropping a 128-bit security level to 96 or 108 bits. Green warned against underestimating automated cryptanalysis: have been extensively analyzed by humans. We felt good that the best known attacks were the best attacks. But we’re learning that human mathematical analysis isn’t the gold standard,
noting that frontier AI labs may already deploy internal models on cryptanalytic work. He summarized, I can’t see the future. Nobody can. But so far, betting against models and in favor of human intelligence being the limit has not worked well for any of us. I think it’s an especially poor choice now, being made by normally-cautious security pros.
Dragonfly managing partner Haseeb Qureshi supported the note of caution, stating, Doomerism has now hit cryptography. Unfortunately, on reflection, I think this is a very sober call. No reason to be taking unnecessary risk with all of the rapid progress happening in mathematics. The risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions.
Global Infrastructure Implications and Layer-1 Responses
Multiple industry experts pointed out that any sudden, catastrophic crack in elliptic curves would extend far beyond crypto assets. Former Ethereum Foundation researcher Dankrad Feist, now at Tempo, highlighted that proactive isolation would be irrelevant under total mathematical compromise: If elliptic curves are broken so that any exposed public key leads to compromise, and it’s not by white hat hackers who save everyone’s assets first, your coins are going to zero. Having them in bunker mode is not going to help you. They are still worth zero.
Ledger Chief Technology Officer Charles Guillemet noted that cracking secp256k1 would not stay confined to Bitcoin and Ethereum,
warning that It would compromise TLS, code signing, most banking systems, and a large fraction of deployed public-key infrastructure at once.
Alternative blockchain ecosystems responded by showcasing their own technical architectures. Jacob Creech, vice president of technology at the Solana Foundation, explained that unlike many networks, Solana users don’t need to go into âbunker mode.â
Because Solana utilizes Ed25519 with signing keys generated by hashing secret seeds kept off-chain, Creech noted that breaking the curve would not expose seeds, allowing for a planned network transition to alternate signature schemes via hash-based proofs. NEAR co-founder Illia Polosukhin argued against reactionary measures: Doomerism approach is never a helpful framing, even if it starts with âcalmlyâ and with best intentions. Going âbunker modeâ is not practical nor a safe approach given how complex it is in operations.
Polosukhin pointed out that NEAR allows native account key rotation and already supports post-quantum ML-DSA,
concluding that Upgrading cryptography should be a routine operation, not a crisis response.
Bitcoin developers viewed the bunker recommendation as a reminder of account model differences. Juan Galt, a reporter at Bitcoin Magazine, commented that Only an Ethereum developer would think that not reusing addresses is âBunker mode,â
while Blockstream CEO Adam Back labeled the panic a fud-burger,
observing that Ethereum users store their entire transaction history with an architecture of static reused address, and to top it off they get a .eth address with their handle to self-dox.
Bitcoin’s Taproot architecture, relying on Schnorr signatures, avoids exposing public keys until a transaction spend occurs.
Why This Matters
The controversy underscores a pivotal shift in cybersecurity and blockchain engineering: the convergence of automated artificial intelligence and mathematical cryptanalysis. While the industry has historically focused on the multi-year threat timeline posed by quantum hardware, the prospect that large-scale AI reasoning engines could independently accelerate mathematical theorem discovery and uncover flaws in hardness assumptions challenges long-held security parameters.
The debate highlights critical vulnerabilities across global digital infrastructure. Elliptic curve algorithms secure not only digital assets like Bitcoin and Ethereum, but also web security standards like Transport Layer Security (TLS), global banking communication, and software verification systems. As institutions and foundation teams weigh post-quantum roadmapsâincluding hash-based schemes versus lattice-based cryptographyâthe discussion will shape future upgrades, key management standards, and the urgency of migration strategies across Web3 and traditional finance alike.
Frequently Asked Questions
Did OpenAI’s latest mathematics update break elliptic curve cryptography?
No. While OpenAI published new mathematical findings formalized via Lean on October 6, none of the published proofs involved cryptanalysis or broke elliptic curve cryptography. The controversy emerged over whether future iterations of advanced AI models could eventually uncover vulnerabilities in cryptographic hardness assumptions.
What is “bunker mode” in the context of wallet security?
The phrase refers to keeping digital assets exclusively in addresses that have never broadcast an outgoing transaction, thereby avoiding the public exposure of the associated public key onchain. While Bitcoin natively encourages non-reused addresses, account-based blockchains like Ethereum typically reuse addresses across multiple transactions.
Why is Vitalik Buterin concerned about lattice-based cryptography?
Vitalik Buterin noted that while the industry has viewed lattice schemes (such as ML-DSA) as secure post-quantum replacements for elliptic curves, AI-accelerated mathematical reasoning could potentially find unexpected weaknesses in lattice security assumptions within the next few years, leading Ethereum’s lean roadmap to prioritize hash-based signatures instead.




