Ethereum researchers urge crypto holders to prepare for AI-driven threats to wallet security

Wait 5 sec.

Two of Ethereum's most senior researchers have warned that rapid advances in AI-driven mathematics could undermine the cryptography that protects crypto wallets, possibly much sooner than the industry has planned for. They agree on the basic precaution, using wallet addresses that have never sent a transaction. They differ on how urgently holders should act. Neither has pointed to any actual break of the cryptography, and no attack has been reported.What happenedEthereum Foundation researcher Justin Drake posted on X on 7 October (US time), calling on the blockchain industry to "calmly begin planning for 'bunker mode'". He recommended a "controlled mass migration" of assets to fresh addresses, starting with large, sophisticated holders.Drake said it is now reasonable to brace for the possibility that the signature scheme securing Bitcoin and Ethereum wallets could be broken before practical quantum computers arrive, "in the worst case in months not years". By "broken" he meant recovering a private key in about a week using widely available hardware, such as a large cluster of graphics processors.He tied the warning to a run of AI-generated mathematical results that overturned long-held assumptions, including the disproof in May of an 80-year-old conjecture by mathematician Paul Erdős. He also pointed to a new release from OpenAI this week, saying "mathematical superintelligence is upon us."Ethereum co-founder Vitalik Buterin followed about 10 hours later. He agreed the risk deserves serious attention, but his opening line was cautious: "I don't recommend anyone scramble to move their funds to new wallets today."Why fresh addresses matterA crypto wallet has a private key, which must stay secret, and a public key derived from it. Most addresses show the world only a hash of the public key, a scrambled fingerprint that reveals nothing useful. The full public key becomes visible on the blockchain the first time the address sends a transaction.The concern is that an attacker who can work backwards from a public key to the private key could take the funds. Coins sitting in an address that has never sent a transaction keep the public key hidden, so there is nothing to attack. That is why both researchers suggest keeping funds in unused addresses and moving the remainder to a new address after each transaction.Drake stressed that this does not require new cryptography or new wallets. He also said holdings below 50 BTC have some cover, because thousands of early-era Bitcoin addresses that hold 50 BTC each, and whose public keys are already exposed, would be more attractive first targets.Where the two researchers differThe difference is about speed, not direction.Drake wants the industry to start moving now, with large holders leading by example. He named several major exchanges and stablecoin issuer Tether as having an opportunity to harden their cold storage.Buterin's advice is more measured: move to fresh addresses if it is easy for you, but be careful. "I personally have lost more money in botched migrations than I have lost in all hacks combined," he wrote. For most holders, a careless transfer, such as a wrong address or a mishandled seed phrase, is a more immediate risk than a mathematical breakthrough.Buterin also widened the concern. The quantum-resistant cryptography the industry has been preparing to adopt is mostly built on mathematical structures called lattices, and he argued these may also "take serious hits" from AI over the next two years. Both researchers favour hash-based cryptography, which is designed to have as little mathematical structure as possible for an attacker to exploit. That approach is already part of Ethereum's long-term roadmap, and Drake said its timelines should now be accelerated.Interpretation: a warning, not a breakThese are personal views from two influential researchers, and both label them as such. Nobody has demonstrated a practical attack on the elliptic-curve cryptography used by Bitcoin and Ethereum. The argument rests on a principle that has been borne out before: unexpected mathematical shortcuts have weakened cryptography in the past, and increasingly capable AI could find more of them faster.It also marks a shift in tone for Buterin, who argued only recently that AI would help defenders more than attackers in software security.What to watch nextReaction from other cryptographers. Strong pushback from leading cryptographers would weaken the case for urgency. Broad agreement would strengthen it.Verified AI results against the underlying mathematics. Any confirmed result weakening elliptic-curve or lattice cryptography would turn a warning into an event.Exchange and custodian responses. Watch whether large holders publicly reorganise their cold storage, as Drake has urged.Ethereum's roadmap. Any decision to bring forward its move to hash-based cryptography.For individual holders, the practical takeaway is modest. If your wallet makes it simple to receive funds at a new, unused address, there is little downside to doing so. If it isn't simple, the researchers' own advice is not to rush. A botched migration is the more immediate risk. This article was written by Eamonn Sheridan at investinglive.com.