$ETH What’s more worth discussing this time is how security preparedness can keep pace with advances in mathematics. Vitalik warned that AI could accelerate the weakening of cryptography, while also urging people not to rush to move their wallets. These two points aren’t contradictory: we need to prepare early for long-term risks, but hasty action could also cause people to lose their funds first.

I read his original post and correction. At 07:28 Beijing time on October 8, he expanded his concerns from quantum computing to AI-assisted mathematical research. At 11:17, he added conditions for multisig, and at 12:07, he posted the latest edited version. Those later additions matter, because “it’s better to collect signatures off-chain” is not a universally safe conclusion for every configuration.

His core concern isn’t that AI will guess a few more passwords, but that it could discover more powerful mathematical algorithms, making attacks that were previously considered very difficult cheaper to carry out. The security margin of the same password scheme with the same parameter sizes could therefore shrink. He believes advances in AI-driven mathematics over the next two years could significantly affect the concrete security of lattice-based cryptography. But this is his risk forecast: the original post provides no experiments showing that mainstream wallets have been cracked, nor any definite countdown to failure.

Lattice-based cryptography can be understood as placing security on specific mathematical problems. ML-DSA is a digital signature scheme in this category. NIST published its standard on August 13, 2024, and also published the hash-based SLH-DSA signature standard on the same day. Having a standard means it has gone through a standardization process; it doesn’t mean it will never need to be reviewed. Conversely, one researcher’s recommendation to use more conservative parameters doesn’t mean these standards have been withdrawn.

Vitalik favors hash-based constructions where applicable and describes the Lean roadmap as moving in that direction. What I care more about here is the boundary between use cases: signatures prove authorization, while public-key encryption lets designated recipients decipher content. They are not the same thing. You can’t take “signatures can switch approaches” and extend it to “all encryption can be replaced with hashes,” much less claim that the Ethereum mainnet has already completed such a replacement.

The latest correction further clarifies the assumptions behind the multisig discussion: he envisages ECDSA weakening, but not an attack happening instantly. The ideal rule would involve signers changing keys after every operation; collecting signatures off-chain as much as possible would shorten the period after a signature becomes public while the old key is still active. This is an engineering idea under a specific threat model, not an upgrade plan that ordinary users can safely carry out just by following a viral post. At the end, he again warns that a hasty upgrade with an incorrect configuration can easily lead to losses.

So I’d view this message as a prompt to reassess security margins and migration design, not as a ready-made reason to be bearish on ETH in the short term. What could genuinely change the assessment next would be reproducible attack results, cost estimates for different parameters, and auditable upgrade and rollback procedures from wallets and protocols. Price movements alone can’t prove cryptographic security. Sources: Vitalik’s two posts and NIST FIPS 204/205; the image illustrates how risk can propagate.