Ethereum co-founder Vitalik Buterin says faster AI-driven mathematical research could narrow the security margins of some cryptographic signatures and post-quantum schemes. But he stressed that there is no evidence that the elliptic-curve signatures used by Bitcoin or Ethereum have been broken, and warned holders against rushing to move funds: mistakes during migration could cause more immediate losses.
In remarks on October 7, Buterin said users could reduce relevant risks where practical, but advised against large-scale transfers for now. He said he had lost more money through failed migrations than through hacks.
OpenAI mathematics work prompts cryptography debate
The discussion was set in motion earlier by Ethereum researcher Justin Drake, who urged the industry to prepare for a “fortress mode.” That could include moving assets to new addresses whose public keys have never been exposed on-chain. Drake is concerned that AI advances could accelerate mathematical attacks on the elliptic-curve cryptography used by Bitcoin and Ethereum.
The debate intensified after OpenAI announced on October 6 that an internal frontier model had produced mathematical results, including machine-generated proofs formalized in Lean. OpenAI did not report an attack on blockchain cryptography, and neither Buterin nor Drake presented evidence that ECDSA had been practically broken.
Buterin’s concern extends beyond elliptic curves. He singled out lattice cryptography, including ML-DSA, saying AI-assisted mathematical discoveries could weaken confidence in the security margins of such schemes over the next two years. This adds uncertainty for an industry preparing for quantum computing: lattice cryptography is one of the leading alternatives to conventional cryptographic techniques that quantum computers could threaten. The US National Institute of Standards and Technology (NIST) standardized ML-DSA as a post-quantum digital signature algorithm in 2024.
The mathematical foundations of these systems could still contain weaknesses that have yet to be discovered, Buterin said. He pointed to advances in integer factorization: methods such as the general number field sieve substantially reduced the computational work needed to attack RSA, prompting the use of longer keys. In his view, AI could compress decades of mathematical progress into a much shorter period and improve methods for attacking elliptic curves or lattice problems.
“If AI gives us 50 years of math progress in 2 years,” Buterin wrote, that progress could also significantly improve attacks on lattice cryptography. This is a possible research trajectory, not a confirmed practical method for breaking the schemes.
Ethereum roadmap puts more weight on hash-based cryptography
These concerns help explain why Ethereum developers are leaning further toward cryptographic designs based on hash functions. Buterin said Ethereum’s “lean” roadmap has shifted over the past year toward hash-only systems, reducing reliance on lattice-based signatures such as ML-DSA and Falcon, as well as on lattice commitments in zero-knowledge proofs.
Hash-based signature schemes such as WOTS and SPHINCS are taking on a larger role in that direction. Compared with elliptic-curve and lattice cryptography, hash-based schemes rely less on complex mathematical structures where researchers might discover new shortcuts. Elliptic curves depend on properties such as group operations; lattice cryptography rests on a set of computationally hard problems. If attack methods become more efficient, assessments of those schemes’ practical resistance could change. Hash functions have a relatively simple mathematical structure, but they cannot meet every cryptographic need.
Public-key encryption used for secure communications, anonymous messaging and website connections, for example, generally cannot be built using hash functions alone. These systems require particular mathematical structures that provide a decryption “trapdoor” available only to authorized users. Buterin said systems that depend on such structures might need higher security parameters if AI significantly improves cryptanalysis. In some cases, he suggested, increasing key sizes tenfold could be reasonable.
The potential effects reach beyond blockchains. Secure messaging tools, VPNs, Tor, encrypted web traffic and privacy protocols could all face trade-offs between larger keys, performance and security margins.
Holders can monitor public-key exposure without rushing to move funds
For crypto holders, Buterin’s immediate precautions are limited. If assets remain at an address that has never signed a transaction, the public key is generally concealed behind the address hash. Once the account sends a transaction, its public key is revealed. That difference could affect an address’s exposure to future cryptographic risks, but it does not mean an attack is under way.
Multisig operators could also consider collecting signatures off-chain and rotating signing keys after an operation, reducing the time an exposed key might be usable. But key rotation and asset migration require careful execution. Wallet providers, custodians and protocol developers need to assess the long-term implications of cryptographic advances while avoiding operational failures during upgrades.
Public information does not show that the ECDSA signatures used by Bitcoin or Ethereum have been practically broken. Buterin’s central message is to track the potential impact of AI on mathematical research and cryptanalysis, without mistaking a forward-looking risk for an urgent instruction to move assets.