This is not the first time a warning like this has spread fear across crypto.
In March, Google Quantum AI published a paper estimating that breaking the cryptography behind Bitcoin and Ethereum would need fewer than 500,000 physical qubits, about 20x fewer than earlier estimates.
Google's Willow chip has 105 qubits today, and the paper says no quantum computer can run the attack yet.
Justin Drake of the Ethereum Foundation co authored the paper. He puts at least 10% odds on a quantum computer recovering a private key by 2032.
That warning was about quantum computers. The new warning, from yesterday, is about AI.
On Oct 6, OpenAI published 722 math papers from a model it has not released.
On Oct 7, Drake posted that AI math could break ECDSA, the signature method behind Bitcoin and Ethereum, in the worst case within months.
HERE'S WHAT HE'S WARNING:
Every wallet has a private key and a public key. The private key lets you spend.
An address is a hash of the public key. The public key stays hidden until you spend from the address, and after that it is visible on the blockchain permanently.
If someone could calculate the private key from a public key, they could move the coins. Nobody knows a way to do that in practical time today.
Drake defines a break as recovering a private key in about 1 week on a large GPU cluster.
His comparison is RSA, an older system.
Researchers found faster ways to factor numbers over decades, and RSA keys had to grow from 64 bytes to about 400 bytes.
He asks whether elliptic curves have a similar shortcut that has not been found, and whether AI will find it.
The evidence shows less than the fear suggests.
No weakness in ECDSA has been shown by anyone. Drake asks whether ECDSA is "too good to be true."
None of OpenAI's reported papers are about cryptography. They cover pure math and physics problems, such as number theory and models of magnetism.
OpenAI says many proofs are computer checked but not all, some may contain errors, and no outside group has reviewed them yet.
The RSA comparison is not an exact match.
The RSA shortcuts took decades of work by many researchers, and elliptic curves have been studied since the mid 1980s with no practical attack published on the curve Bitcoin uses.
AI could speed this up, but that speed up is an assumption.
Coinbase's head of cryptography, Yehuda Lindell, says there is "no evidence whatsoever" that elliptic curves are close to failing.
This is not something to panic about today. It is a risk to plan for.
Using a break would also be hard to do at scale.
The quantum attack needs hardware that is about 4,700x larger than Willow's 105 qubits.
Drake's AI scenario takes about 1 week of a large GPU cluster to recover a single key, so an attacker could only go after a few wallets at a time.
And Only part of the supply is exposed. A March paper by Ark Invest and Unchained estimated 34.6% of Bitcoin supply, about 6.9M BTC, has a visible public key:
- 5M BTC in reused addresses.
- 1.7M BTC in old P2PK addresses.
- 200K BTC in Taproot addresses.
The other 65.4% has its public key hidden. Holders keep it hidden by not reusing addresses.
Hash functions are not the target. Bitcoin mining and address hashing use them, and both Drake and Vitalik treat them as the most secure part of the system.
If you hold crypto, here is what you should do:
1. Use a new address for every receive. Most modern wallets can do this automatically.
2. Check whether your coins sit in an address that has already sent a transaction. Its public key is visible, so move those coins to a new address.
3. Taproot addresses show the public key from the start, so a fresh Taproot address gives no protection from this risk.
4. Ethereum works the same way.
Once an account sends a transaction, its public key is visible.
Large holders can use multisig wallets with confirmations collected offchain.
That keeps signatures private, and if ECDSA breaks, the wallet falls back to being controlled by whoever collects the signatures, instead of anyone being able to take the money.
Two problems are still open.
The first is the 1.7M BTC in old P2PK addresses, which are assumed to be lost.
A draft proposal called BIP-361, written by Jameson Lopp and five co-authors in April, would handle them in phases:
1. 3 years after activation, no new BTC can be sent to old-style addresses.
2. 5 years after activation, old-style signatures are invalidated and coins left in vulnerable addresses are frozen.
3. Later, a zero knowledge proof method would let owners who missed the deadline recover frozen funds if they still have their seed phrase.
It has no activation date. Critics call it confiscation and Metaplanet's Phil Geiger said, "We have to steal people's money to prevent their money from being stolen."
The second is encryption.
Hashes cannot replace public key encryption, which secures websites, messaging apps and VPNs, so the issue goes beyond crypto.
Vitalik also warns that lattice based cryptography, the main option for quantum safe encryption, could lose security from AI math as well.
So far, no one has shown that AI can break ECDSA, and no quantum computer can run the attack today.
What exists today is a known weak spot. About 6.9M BTC has a visible public key, and holders can reduce that exposure by moving coins to fresh addresses.

