Vitalik Buterin urges calm as AI-driven math raises crypto signature concerns

Editorial illustration: Vitalik Buterin holds up an open hand behind a dark leather wallet protected by a transparent dome, with a glowing lattice of connected crystal nodes extending toward it.

In brief

  • Buterin warned AI-driven math could weaken existing signatures and some post-quantum defenses.
  • Holders should reduce exposure where practical but avoid rushing into new wallets, Buterin advised.
  • No evidence shows ECDSA has been practically broken, according to CryptoSlate's reporting.
  • Ethereum's 'lean' roadmap has shifted toward hash-only signature systems, Buterin said.

Drake's 'bunker mode' and OpenAI's math results

Buterin's comments followed Ethereum researcher Justin Drake's call for the industry to prepare for a "bunker mode," which includes moving assets to fresh addresses whose public keys have never been exposed onchain. Drake raised the possibility that AI could speed up mathematical attacks on the elliptic-curve cryptography that Bitcoin and Ethereum use.

The debate comes a day after OpenAI published new mathematical results from an internal frontier model on Oct. 6, including machine-generated proofs formalized in Lean, as reported by CryptoSlate. OpenAI didn't report any attack on blockchain cryptography.

Neither Buterin nor Drake pointed to evidence that ECDSA has been practically broken.

Why lattice schemes are in focus

Buterin singled out lattice-based cryptography (including ML-DSA) as an area where AI-driven mathematical discovery could erode assumed security margins over the next two years. That's a pointed warning. NIST standardized ML-DSA in 2024 as a post-quantum digital-signature algorithm, and lattice-based systems are among the leading technologies designed to replace cryptography that sufficiently powerful quantum machines could break.

His reference point is the history of integer factorization, where improvements such as the general number field sieve sharply cut the work needed to attack RSA. Buterin said AI could compress decades of similar progress into a much shorter period, potentially turning up comparable advances against elliptic curves or lattice problems.

“I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously.”

Ethereum leans on hashes

According to Buterin, Ethereum's "lean" roadmap has moved toward hash-only systems over the past year, avoiding lattice-based signatures such as ML-DSA and Falcon. Hash-based schemes like WOTS and SPHINCS play a bigger role in that direction because they depend less on mathematical structures that could give attackers unexpected shortcuts.

Hashes don't solve everything, though. Public-key encryption (used in secure messaging, anonymous communications and websites) can't generally be built from hashes alone, and Buterin suggested systems that rely on those structures may eventually need substantially larger security parameters.

Frequently asked questions

Has AI broken Bitcoin or Ethereum cryptography?

No. CryptoSlate reported that OpenAI's Oct. 6 math results didn't include any attack on blockchain cryptography. Neither Vitalik Buterin nor Justin Drake pointed to evidence that ECDSA has been practically broken.

Should crypto holders move funds to new wallets now?

Buterin advised holders to reduce exposure where practical but cautioned against rushing funds into new wallets. He argued that migration mistakes pose a more immediate danger than any demonstrated cryptographic break.

Why is Buterin concerned about lattice-based cryptography like ML-DSA?

Buterin said AI-driven mathematical discovery could erode the assumed security margins of lattice-based schemes, including ML-DSA, over the next two years. NIST standardized ML-DSA in 2024 as a post-quantum signature algorithm. He compared the risk to how the general number field sieve sharply cut the work needed to attack RSA.

How is Ethereum's roadmap responding to these risks?

Buterin said Ethereum's 'lean' roadmap has moved toward hash-only systems over the past year, avoiding lattice-based signatures such as ML-DSA and Falcon. Hash-based schemes like WOTS and SPHINCS depend less on mathematical structures that could give attackers unexpected shortcuts.