OpenAI’s release of hundreds of AI-generated mathematical results has prompted Ethereum Foundation researcher Justin Drake to raise an unusual security question for cryptocurrency users: whether cryptographic assumptions that have held for decades could be weakened by AI-assisted mathematical discovery before quantum computers become practical.
Drake urged parts of the industry to consider a precautionary “bunker mode” focused on reducing unnecessary public-key exposure. His concern centers on the Elliptic Curve Digital Signature Algorithm, or ECDSA, the signature system used by Bitcoin, Ethereum and many other networks to authorize transactions.
There is no known practical AI-derived attack on ECDSA, and neither Drake nor Ethereum co-founder Vitalik Buterin argued that users should make panicked transfers. Their discussion instead frames AI mathematics as a new variable in long-term cryptographic risk planning, especially for wallets and services with publicly exposed keys and large balances.
OpenAI said on October 7 that it had released a collection of AI-produced mathematics results that was later organized on GitHub into 722 manuscripts across 372 result families. The material spans number theory, geometry, combinatorics and theoretical computer science. According to OpenAI, its evaluation involved roughly 4,000 questions, with each result using computing resources equivalent to about three hours of ChatGPT Pro “thinking.”
Drake outlines a months-to-years threat scenario
Drake said the speed of AI-led mathematical work could eventually reveal shortcuts in problems that underpin modern cryptography. In his worst-case scenario, a new class of methods could allow a large GPU cluster to derive an ECDSA private key from exposed public information in roughly a week.
That hypothetical timeline is measured in months to years rather than the decades usually associated with cryptographic threats from fault-tolerant quantum computers. It depends on an undiscovered mathematical or algorithmic breakthrough, rather than an incremental improvement in conventional computing power.
ECDSA security relies on the difficulty of solving the elliptic-curve discrete logarithm problem. A user creates a private key, derives a public key from it, and uses the private key to generate a signature authorizing a transaction. An attacker who could efficiently reverse that relationship could potentially control funds associated with the exposed public key.
The practical implications vary among blockchains and wallet formats. On Ethereum, a transaction signature allows observers to recover the sender’s public key. On Bitcoin, many older output types reveal a public key when funds are spent. Funds that remain at an address whose public key has never been exposed offer an additional layer of protection under the threat model Drake described, because an attacker would first need to overcome the hash function used in the address construction.
Drake recommended gradually moving assets to fresh addresses that have never signed an outgoing transaction. The objective is to leave funds in addresses where only hashed public-key information is visible on-chain. He cautioned against rapid, industry-wide movement, since wallet mistakes, lost backups and incorrect destination addresses can produce immediate and irreversible losses.
High-value signers face a different problem
The proposal is more complicated for exchanges, custodians, bridges, oracle networks, Layer 2 security committees and other entities that must sign transactions repeatedly. These systems cannot permanently avoid public-key exposure while continuing normal operations.
For those users, Drake suggested stronger cold-storage procedures, periodic rotation of ECDSA public keys and, where technically practical, multisignature systems using hash-based signature schemes. Hash-based signatures derive their security mainly from the preimage resistance and collision resistance of cryptographic hash functions, rather than from the algebraic structure of elliptic curves or lattices.
That distinction is central to the discussion. Cryptographers have long treated diverse mathematical assumptions as a way to reduce single points of failure. AI systems capable of identifying previously hidden patterns could test that diversification in a new way, particularly if a model develops useful methods for recognizing structure in hard mathematical problems.
Drake referred to OpenAI’s earlier mathematical disclosures, including a May release involving a counterexample connected to the Erdős unit distance conjecture, an August update on open problems and a September statement about an internal model’s work on the Navier–Stokes Millennium Prize problem. Those releases do not establish a link to cryptanalysis, but they illustrate the type of faster mathematical exploration that Drake believes security engineers should consider in their contingency planning.
He also mentioned an “implicit Satoshi shield” around certain Bitcoin holdings, referring to 20,000 addresses holding 50 BTC each whose public keys are already exposed. The observation appears intended to show that any hypothetical attacker capable of breaking ECDSA would face many visible and valuable targets, potentially complicating assumptions about which coins might be targeted first.
Buterin backs precautions but rejects a rush
Buterin agreed that users can keep funds in fresh addresses that have not signed transactions, as long as the process remains simple and manageable. He argued against hurried migrations based only on AI mathematics headlines, saying that the operational risks of moving keys and funds may exceed the immediate cryptographic risk.
His caution places ordinary wallet hygiene ahead of dramatic emergency measures. A holder who moves funds carelessly, uses a compromised device, exposes a seed phrase or sends assets to an incompatible address faces a known danger today. An AI-assisted ECDSA break remains speculative.
Buterin also expanded the concern beyond elliptic curves. He said faster mathematical discovery could affect other cryptographic systems, including the lattice-based assumptions behind ML-DSA and some forms of fully homomorphic encryption, or FHE. Lattice cryptography is a leading category of post-quantum cryptography, but it too relies on hardness assumptions that could change if researchers discover previously unknown structure.
For lattice-based systems, Buterin suggested that increasing parameters and key sizes by a factor of 10 could be the simplest way to widen safety margins. Larger parameters generally increase computational and storage costs, creating a trade-off that protocols and wallet providers would need to manage carefully.
Design choices can limit public-key exposure
Buterin’s operational suggestions extend to privacy systems and multisignature wallets. He recommended keeping privacy-protocol credentials or “notes” off-chain through third-party communication channels where feasible, rather than publishing them permanently to a blockchain.
For multisignature arrangements, he suggested completing signing confirmation off-chain. That approach could delay public-key exposure and, in an ECDSA failure scenario, allow a wallet to degrade into a collector-managed single-signing flow rather than immediately enabling unrestricted withdrawals by anyone able to exploit exposed keys.
Neither Drake nor Buterin presented an imminent attack as established fact. Their exchange instead points toward a more practical standard for wallet and protocol design: minimize permanent cryptographic exposure where doing so is cheap, reversible and does not create larger operational hazards.
The debate also puts pressure on the industry’s long-standing focus on quantum readiness. Migration plans have often assumed that quantum computers would be the main reason to replace elliptic-curve signatures. AI-assisted mathematics introduces a separate pathway: cryptographic systems could face stress if new algorithms reduce the difficulty of their underlying problems, even without a quantum machine capable of running Shor’s algorithm at scale.
Worried about AI breaking crypto? Learn how crypto safety standards help protect your keys before threats escalate.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
