Ethereum co-founder Vitalik Buterin has warned that AI-driven advances in mathematics could weaken lattice cryptography within two years, potentially affecting digital signatures and encryption that rely on it. He also said elliptic-curve signatures used by Bitcoin and Ethereum wallets could face challenges sooner than expected. Buterin did not call for users to move funds or change wallets immediately. The debate instead highlights the longer-term security of crypto keys and how blockchain networks can prepare for changes to cryptographic standards.
Buterin questions lattice cryptography’s long-term security
Buterin raised the concern in response to Ethereum researcher Justin Drake’s call for the industry to plan for a “bunker mode.” Buterin said many had previously viewed elliptic curves as vulnerable to quantum computing while considering hash-based and lattice-based methods comparatively safe. He now questions whether lattice cryptography can be treated as secure over the long term.
Lattice cryptography is a major foundation of post-quantum security. The Module-Lattice-Based Digital Signature Algorithm (ML-DSA) uses lattice structures and is designed to withstand quantum-computing attacks. Fully homomorphic encryption (FHE), which allows computations on encrypted data without first decrypting it, also relies on lattice cryptography. A new mathematical shortcut for solving lattice problems could therefore affect applications beyond digital-asset signatures.
Buterin drew a comparison with advances in integer factorization. Methods such as the number field sieve changed estimates of how difficult factorization was and contributed to steadily longer cryptographic keys over several decades. He posed a hypothetical: if AI enabled mathematical progress equivalent to decades of work in just two years, lattice cryptography could face a similar reassessment. This is a scenario about potential risk, not evidence that lattice systems have been practically broken.
Ethereum’s roadmap shifts toward hash-based signatures
Buterin said hash functions may offer a more robust alternative to elliptic curves and lattice structures because they have less mathematical structure that can be exploited. Over the past year, Ethereum’s long-term Lean roadmap has shifted toward hash-based designs, including signature techniques such as SPHINCS and WOTS.
The shift reflects developers’ focus on the long-term resilience of cryptographic infrastructure. On a blockchain, signatures establish a user’s control over assets associated with an address. Replacing a signature scheme would raise practical questions about network upgrades, wallet compatibility and asset migration. Buterin’s comments do not call for an immediate change to existing wallets or signature systems.
Bitcoin’s ECDSA exposure depends on a worst-case scenario
Bitcoin also uses elliptic-curve signatures, so Drake’s warning applies to the network as well. He said ECDSA could be broken within months in a worst-case scenario. That is an assessment of an extreme possibility; the information presented does not indicate that ECDSA has been cracked.
Drake also cited Project11’s “risq list,” a tracking tool that records Bitcoin addresses whose public keys have been exposed on-chain. He said wallets holding fewer than 50 BTC receive partial protection from what he called “Satoshi’s shield,” a claim tied to around 20,000 exposed addresses. Public information does not further explain how that protection works, so it does not establish that the wallets are fully insulated from cryptographic risks.
For holders, the current issues are public-key exposure, the evolution of signature algorithms and whether the industry can coordinate a migration if needed—not an immediate need to move assets. Buterin explicitly advised against rushing. The security outlook for lattice cryptography and ECDSA will depend on future mathematical advances and whether they can be turned into practical attacks.