Ethereum Foundation researcher Justin Drake has called on major cryptocurrency holders and custodians to prepare for a rapid migration away from addresses whose public keys have been exposed, arguing that a breakthrough against the Elliptic Curve Digital Signature Algorithm, or ECDSA, could leave little time for a response.
Drake described a “worst case” in which cryptographic assumptions fail over “months not years,” rather than claiming that ECDSA has already been broken. His proposal centers on moving assets in a controlled sequence to newly created addresses whose public keys remain concealed by a hash until they are used to sign a transaction.
The warning places operational security alongside Ethereum’s longer-term cryptographic roadmap. Bitcoin and Ethereum accounts use ECDSA-based signatures to prove that a transaction was authorized by the holder of a private key. If an attacker could derive a private key from a visible public key, they could sign transactions as that account holder and potentially take funds before their owner completed a migration.
Drake said an ECDSA break could theoretically allow private-key recovery within a week using conventional computing hardware, such as a large GPU cluster. That scenario remains hypothetical, but it would differ sharply from the usual quantum-computing discussion, which assumes that sufficiently capable quantum machines would be required to defeat elliptic-curve cryptography.
A plan for exposed public keys
The practical concern is not simply whether an address has a balance. It is whether its public key is already visible on-chain.
On Bitcoin, common address formats generally conceal the public key until coins are spent. Older pay-to-public-key outputs, by contrast, contain a public key directly in the locking script. On Ethereum, the public key behind an externally owned account can be recovered from the signature of a transaction sent from that account. An address that has never sent a transaction therefore offers an additional layer of protection in a scenario where public-key exposure becomes dangerous.
Drake’s recommended process would start with the largest holders moving funds to new addresses. Once an address signs a transaction to perform that migration, its public key becomes exposed. Any remaining balance at the original address should then be transferred again, he said, rather than leaving residual funds behind.
The approach resembles a security “bunker” strategy: use new destination addresses for storage and avoid spending from them unless a further migration is necessary. It would create operational trade-offs for institutions that need regular withdrawals, collateral movements or automated treasury payments. A cold-storage system designed for long-term inactivity can offer fewer convenient paths for routine transactions.
Drake named Binance, Bitbank, Robinhood, Bitfinex and Tether as entities that could consider stronger cold-storage protection. The companies have not been cited as reporting an ECDSA compromise. His point was directed at the scale of assets controlled by large custodians and stablecoin issuers, where a cryptographic failure could create concentrated losses.
Quantum risk is only one part of the argument
Drake tied his warning to “q-day,” the term commonly used for the point at which quantum computers become capable of defeating widely deployed public-key cryptography. Today’s quantum machines cannot break the cryptography protecting Ethereum, according to current Ethereum guidance, and Ethereum users have not been told they need to move funds because of an immediate quantum threat.
His more unusual concern is that a powerful artificial-intelligence system, or a future mathematical breakthrough aided by one, could uncover a classical attack on elliptic curves before quantum hardware reaches that level. Drake argued that elliptic-curve systems may offer more mathematical structure for researchers to exploit than hash functions, which are generally designed to behave like one-way functions.
He pointed to OpenAI’s publication of 722 mathematical manuscripts generated by an internal model as evidence that AI systems are beginning to contribute more substantially to mathematical research. The manuscripts do not establish a method to break ECDSA, RSA or any deployed blockchain signature scheme. They illustrate the kind of accelerating research environment Drake believes protocol developers should consider in contingency planning.
An attack on elliptic curves using ordinary computers would have implications well beyond cryptocurrency. RSA and elliptic-curve cryptography underpin authentication and encryption systems across financial services, internet infrastructure and government networks. The difference for public blockchains is that their balances, transaction history and exposed keys are visible indefinitely, potentially giving attackers a ready-made target list.
Bitcoin’s exposed-key addresses offer a visible target set
Drake referred to Project Eleven’s Bitcoin Risq List, which tracks Bitcoin addresses holding funds where public keys are exposed. The project’s list covers more than 14 million addresses, according to Drake.
He also highlighted roughly 20,000 exposed addresses holding 50 BTC each that have been associated with Satoshi Nakamoto-era mining activity. The ownership of those addresses has never been conclusively established, but their large, dormant balances could make them attractive targets if private-key extraction became feasible.
Drake called this potential buffer “Satoshi’s shield.” The theory is that attackers seeking the largest and most accessible exposed balances could focus on those 50 BTC outputs before attempting to drain smaller exposed wallets. That would not remove the risk for other holders, and the sequence of any attack would depend on technical capability, transaction fees and the speed at which owners react.
For smaller Bitcoin holders, the immediate security lesson is narrower: avoid reusing addresses, understand whether older coins sit in outputs with exposed public keys, and protect recovery phrases and signing devices. Complex emergency migrations can introduce their own hazards, including sending funds to an incorrect address or losing access to newly generated backup material.
Ethereum’s roadmap favors hash-based defenses
Drake said Ethereum’s draft roadmap already points toward cryptographic tools intended to reduce dependence on vulnerable public-key systems. These include hash-based cryptography and formal verification, a method of using mathematical proofs to check whether software meets specified security properties.
Hash-based signatures can offer resistance to quantum attacks under assumptions related to the security of hash functions. They also come with practical constraints, including larger signatures and different key-management requirements than ECDSA. Moving an active blockchain ecosystem to such systems would require protocol upgrades, wallet changes and careful treatment of smart contracts and accounts that cannot simply be replaced with a new address.
Drake’s preferred direction is security grounded more heavily in hash functions than in algebraic structures such as elliptic curves. That preference does not create an immediate migration requirement for ordinary users, but it gives custodians and protocol teams a concrete planning question: how quickly could they identify exposed keys, create fresh addresses and move funds if the underlying assumptions changed faster than expected?
Concerned about Ethereum’s cryptography future? Deepen your understanding by exploring our guide on what Ethereum is and how it works.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
