1. Bitcoin, Ether Face Potential AI Security Threat as Holders Told to Stay Alert
Ethereum researcher Justin Drake has warned the crypto industry to begin preparing for a potential “bunker mode” as artificial intelligence advances raise the possibility of attacks on the cryptography securing Bitcoin, Ether and tokens built on both networks.
In the worst-case scenario, Drake said AI could discover a way to break the mathematics behind crypto wallet signatures “in months, not years.” That would potentially happen well before quantum computers are capable of carrying out similar attacks.
Drake urged the blockchain industry on Wednesday to start preparing gradually, particularly encouraging major holders to move their funds to fresh addresses.
Crypto wallets use private keys to authorize transactions, while corresponding public keys allow the blockchain to verify those signatures. Creating a public key from a private key is relatively easy, but working backward to recover the private key is designed to require an impractical level of computing power.
The risk Drake highlighted is that AI could identify a shortcut in the underlying mathematics, allowing attackers to recover private keys with conventional computers. That would create a more immediate threat than the quantum attacks that have dominated long-term crypto security planning.
A successful attack could potentially expose a large amount of cryptocurrency. Millions of bitcoin are stored at addresses whose public keys are already visible onchain, according to previous CoinDesk reporting. On Ethereum, any account that has previously sent a transaction has exposed its key. Stablecoins and tokenized funds issued on Ethereum also depend on the same signature system.
No practical attack capable of breaking Bitcoin or Ethereum wallet keys has been demonstrated, and CoinDesk found no such attack in the research it reviewed.
AI Is Already Uncovering Crypto Vulnerabilities
Drake’s warning came after OpenAI released 722 mathematical manuscripts Tuesday generated by an unreleased AI model that had been tested on roughly 4,000 research problems.
OpenAI said some of the manuscripts included computer-checkable proofs, while other findings had not been verified and could contain errors.
The manuscripts were produced by a model that OpenAI said last month had solved the Navier–Stokes problem, one of seven Millennium Prize Problems. The company said each result consumed an average amount of computing equivalent to about three hours of ChatGPT Pro reasoning.
Within a day, an outside researcher independently reran the computer check on one of the findings. The result established a new limit on how quickly computers can multiply large grids of numbers, a problem mathematicians have studied since 1969, and the verification confirmed it.
Drake said elliptic-curve mathematics, which underpins Bitcoin and Ethereum wallet signatures, contains structured patterns that sufficiently powerful AI could potentially learn to exploit. Hash functions are designed differently, transforming data into fixed-length digital fingerprints while minimizing exploitable patterns.
AI-assisted security research has already uncovered vulnerabilities in crypto systems and, in some cases, contributed to attacks.
Anthropic researchers demonstrated in December that advanced AI models could generate working exploits against simulated versions of real DeFi contracts. In late July, the volunteer Bitcoin Red Team used AI models to scan 390 Bitcoin software projects in roughly 27 hours, identifying nearly 5,000 potential vulnerabilities, including 85 rated critical.
On July 30, an attacker began draining Coldcard hardware wallets by exploiting a five-year-old firmware vulnerability, stealing at least 1,367 BTC. Coinkite, the wallet maker, said it suspected AI may have helped identify the weakness.
Days later, BTCPay Server confirmed that attackers had stolen funds from merchants’ Lightning nodes through a flaw first identified during an AI-assisted audit. On Aug. 27, Core Lightning developers issued an emergency warning after AI-generated reports helped expose real vulnerabilities in their software.
Researchers have also used AI coding agents to improve a calculation involved in a potential future quantum attack, CoinDesk reported in September. That work still required quantum hardware and covered only part of the broader attack.
The AI Timeline Could Be Much Shorter
The Ethereum Foundation has targeted December 2029 for moving Ethereum to quantum-resistant cryptography.
Drake’s worst-case scenario would arrive years earlier, potentially allowing conventional computers to break existing wallet protections before Ethereum completes that transition.
Post-Quantum Cryptography Could Also Face AI Risks
Ethereum co-founder Vitalik Buterin agreed that the threat deserves attention but warned that some cryptographic systems designed to resist quantum computers may also be vulnerable to rapid advances in AI-powered mathematics.
Some quantum-resistant systems use lattice-based cryptography, which depends on mathematical problems believed to be difficult for both traditional and quantum computers. The approach also forms the basis of a digital-signature standard approved by the U.S. National Institute of Standards and Technology.
Buterin said AI-driven advances in mathematics over the next two years could significantly affect the practical security of lattice systems. If AI can compress 50 years of mathematical progress into two years, he argued, that progress could potentially include major improvements in techniques for breaking lattice cryptography.
Ethereum’s proposed long-term cryptographic redesign increasingly favors hash-based signatures. These rely on digital fingerprints that are designed to be difficult to reverse and may provide fewer opportunities for unexpected mathematical shortcuts, although Buterin acknowledged that they could still face attacks.
Drake recommended that sophisticated holders take precautions by gradually moving funds to addresses whose public keys have never appeared onchain. This could prevent a potential attacker from obtaining the public-key information needed to begin an attack.
Buterin agreed that reducing public-key exposure where possible is worthwhile but warned users against rushing into migrations. Poorly executed transfers can introduce new vulnerabilities and cause losses.
“I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin wrote.
Share this content:













