Ethereum researcher Justin Drake warns AI could break crypto signatures before quantum
In brief
- Justin Drake urged the blockchain industry in a Wednesday X post to calmly plan for 'bunker mode'.
- ECDSA, used by Bitcoin and Ethereum, might be cracked by AI before quantum computers, Drake said.
- Drake recommended a controlled mass migration to fresh addresses that have never signed a transaction.
- Drake urged Binance, Bitbank, Robinhood, Bitfinex and Tether to harden their cold storage.
- Ethereum's roadmap toward hash-based cryptography should now be accelerated, Drake said.
Why ECDSA is the worry
The concern is ECDSA, the signature scheme Bitcoin and Ethereum use to prove a transaction was authorized by the correct private key. When a wallet signs a transaction, its public key becomes visible on-chain. If ECDSA were broken, an attacker could derive the private key from that public key and drain the wallet.
Drake said it's now reasonable to prepare for ECDSA breaking before Q-Day, "in the worst case in months not years." That's his warning, not a consensus view. By "break," he meant recovering a private key in about a week on available hardware (a large GPU cluster, for example).
Why now? Drake pointed to a burst of AI-driven math, including 722 results OpenAI published Tuesday, as a sign that long-held assumptions were falling. He argued that the rich mathematical structure of elliptic curves leaves room for clever attacks that hash functions are designed to resist.
Fresh addresses, no panic
My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Drake stressed that holders shouldn't rush or panic. Moving assets doesn't require new cryptography or new wallets, he noted, and he urged Binance, Bitbank, Robinhood, Bitfinex and Tether to harden their cold storage.
Smaller Bitcoin holders have some cover, according to Drake. He said wallets holding less than 50 BTC enjoy partial protection from what he called "Satoshi's shield": roughly 20,000 exposed addresses tied to Bitcoin's creator, each holding 50 BTC, which he said would likely be targeted first.
Ethereum's post-quantum roadmap
This isn't Drake's first warning on the subject. In March, after a Google paper suggested quantum computers could break crypto's cryptography sooner than expected, he put the odds of Q-Day by 2032 at 10% or more. The Ethereum Foundation formed a dedicated post-quantum team earlier this year, and co-founder Vitalik Buterin has laid out plans to move the network toward quantum-resistant cryptography.
Drake now says Ethereum's roadmap toward hash-based cryptography should be accelerated.
Frequently asked questions
Why are wallets that have signed a transaction more exposed?
When a wallet signs a transaction, its public key becomes visible on-chain. If ECDSA, the signature scheme Bitcoin and Ethereum use, were broken, an attacker could derive the private key from that public key and drain the wallet. Fresh addresses that have never signed keep their public keys hidden behind a hash.
What does Justin Drake mean by ECDSA 'breaking'?
Drake defined a break as recovering a private key in about a week on available hardware such as a large GPU cluster. He said it's now reasonable to prepare for that before Q-Day, 'in the worst case in months not years,' a view he presented as his own warning.
What is 'Satoshi's shield'?
It's Drake's term for the partial cover he says wallets holding less than 50 BTC enjoy. He pointed to roughly 20,000 exposed addresses tied to Bitcoin's creator, each holding 50 BTC, which he said would likely be targeted first.


