YFarmX logoYFarmX

Crypto NewsSecurity

Buterin backs warning that AI could threaten crypto signatures

Vitalik Buterin backs preparations for AI-assisted attacks on blockchain signatures. Bitcoin research estimates about 6.7 million BTC behind exposed public keys.

Editorial illustration of Vitalik Buterin beside an intact key, an elliptic-curve sketch and Ethereum and Bitcoin logos.

Listen to this articleListen

Ethereum co-founder Vitalik Buterin has backed a warning that AI-assisted mathematics could threaten the signatures that secure cryptocurrency wallets before quantum computers do. In a 7 October post, he urged the industry to take that possibility seriously and prepare carefully.

Buterin was responding to Ethereum researcher Justin Drake, who called for planning around “bunker mode”: reducing the exposure of public keys while developing stronger cryptography. Their posts discuss a future attack scenario and preparations for it.

How could AI threaten a wallet signature?

Drake’s concern is that AI could discover mathematical shortcuts for recovering a private key from a public key. A private key authorises spending; its corresponding public key lets the network verify the signature.

Ethereum accounts and many Bitcoin transactions use ECDSA, the elliptic curve digital signature algorithm. Bitcoin’s Taproot uses Schnorr signatures. Both rely on elliptic-curve mathematics, which is examined in research by Google, Ethereum Foundation and Stanford authors.

Drake argues that the structure of elliptic curves could give advanced AI new approaches to cryptanalysis. He presents a worst-case scenario in which a practical breakthrough arrives within months, before a cryptographically capable quantum computer. That timescale is his assessment of a possibility; establishing an attack would require a reproducible method that works against the deployed cryptography.

Diagram showing a public key used to verify a signature, and the hypothetical risk of recovering its private key after a cryptanalytic breakthrough.
The warning concerns a future shortcut from a visible public key to its private key. A wallet signature authorises a transaction.

Why are exposed Bitcoin keys getting attention?

Figure 7 of the cryptocurrency quantum-vulnerability research estimates about 6.7 million BTC in addresses with exposed public keys. This is the paper’s estimate of an attack surface, with its underlying data and assumptions.

Some Bitcoin outputs, including Pay-to-Public-Key and Taproot, expose public keys from creation. Other common address types conceal them behind hashes until spending reveals the key or script. Reusing an address can leave funds behind a key that has already been revealed.

The estimated balance describes key exposure. Exploiting it would require an attacker to acquire the cryptanalytic capability discussed in the research.

Buterin also questions lattice-based security

Buterin extends the AI warning to lattice-based cryptography, including approaches used in post-quantum systems. He thinks accelerated mathematical research could reduce the security margins of these constructions over the next two years.

He favours hash-based signatures and proofs where those designs are practical, and describes that preference as part of Ethereum’s lean roadmap. Post-quantum security addresses a quantum threat; Buterin wants future designs assessed against AI-assisted mathematical discoveries too.

What does bunker mode involve?

Drake proposes a controlled migration towards addresses whose public keys remain hidden behind hashes. He asks large, technically equipped holders to lead and recommends moving remaining funds when a transaction reveals a key.

Buterin supports fresh, previously unused addresses where moving is straightforward, while stressing the operational risk of migrations. The protection depends on the address design and how it is used: a fresh Taproot address already exposes a public key.

Reducing key exposure buys a narrower attack surface. Replacing vulnerable signatures with new cryptographic schemes is a separate, broader upgrade.

Animated conceptual diagram showing a revealed public key, an address with a key hidden behind a hash, and a future signing upgrade.
Address hygiene and a signing-system upgrade address different parts of the cryptographic risk.

Solana and BitGo have already outlined preparations

Solana’s foundation published a three-stage quantum-readiness plan on 27 April 2026: continue research, introduce a post-quantum scheme for new wallets if the threat becomes credible, then migrate existing wallets. Its update says Anza and Firedancer independently investigated Falcon and produced initial implementations.

BitGo introduced Bitcoin quantum-risk controls on 22 July 2026. The release added a Quantum Risk Score, a Fix Exposed Addresses workflow, address controls and coin selection that aims to empty an address when it is spent from.

Timeline showing Solana's 27 April quantum roadmap, BitGo's 22 July Bitcoin risk controls and the 7 October Drake and Buterin AI warnings.
Solana and BitGo's preparations predate the October AI warning. Sources: their dated announcements and the researchers' posts.

These are distinct approaches: Solana describes a future signature migration, while BitGo gives institutions tools to measure and reduce existing Bitcoin key exposure. Drake and Buterin’s latest warning adds AI-assisted mathematical discovery to the risks those preparations need to consider.

Sources

  1. Justin Drake: AI cryptanalysis and bunker-mode preparations, 7 October 2026x.com
  2. Vitalik Buterin: AI-assisted mathematics and cryptographic risk, 7 October 2026x.com
  3. Google, Ethereum Foundation and Stanford researchers: cryptocurrency quantum vulnerabilities, figure 7arxiv.org
  4. Solana Foundation: quantum-readiness roadmap, 27 April 2026solana.com
  5. BitGo: Bitcoin quantum-risk controls, 22 July 2026bitgo.com

How we use AI