BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

When AI Starts Conquering Mathematics, a Crypto Sage Urges the Entire Industry to Retreat into a "Bunker"

Azuma
Odaily资深作者
@azuma_eth
This article is about 3515 words, reading the full article takes about 6 minutes
Once seemingly impregnable cryptography may be vulnerable simply because the human brain navigates the mathematical labyrinth too slowly.
AI Summary
Expand
  • Core Viewpoint: After OpenAI published a large number of AI mathematics breakthroughs, Ethereum researcher Justin Drake called on the crypto industry to plan for "bunker mode," warning that AI's mathematical capabilities could enable ECDSA to be broken before quantum computing matures, threatening the security of mainstream blockchain accounts; Vitalik acknowledged the risk but advocated a cautious response, with both expressing optimism about pure hash-based cryptography.
  • Key Elements:
    1. OpenAI publicly released 722 manuscripts and 372 result families, covering number theory, geometry, and other fields, with approximately 4,000 questions posed during evaluation and an average of about 3 hours of ChatGPT Pro thinking compute consumed per result.
    2. Drake warned that AI could potentially find shortcuts similar to Shor's algorithm on classical hardware; under the most pessimistic scenario, an attacker would only need a GPU cluster to reverse-engineer private keys within weeks, with ECDSA being particularly dangerous due to its rich mathematical structure.
    3. Drake suggested that ordinary token holders migrate assets to new addresses that have never signed transactions, and that key signers should strengthen cold wallets, rotate public keys, or adopt hash-based signature schemes, but emphasized that migration should be done "slowly."
    4. Vitalik agreed that migration to new addresses is feasible but opposed hasty migration, pointing out that the operational risks of key migration itself could outweigh those of a hacker attack; he also warned that post-quantum solutions such as lattice cryptography, ML-DSA, and FHE may not necessarily be safe under the assumption of AI-accelerated mathematics.
    5. Vitalik suggested that privacy protocols move encrypted credentials off-chain and that multi-signature wallets complete signature confirmation off-chain to delay public key exposure, so that even if ECDSA is broken, there can be a "graceful degradation."
    6. Vitalik noted that pure hashing can solve signature and proof problems, but public key encryption (PKE) cannot be built on hashing alone and must introduce trapdoor structures; he suggested scaling up lattice-based system parameters and key sizes by tenfold to maintain long-term security.

Original | Odaily (@OdailyChina)

Author|Azuma (@azuma_eth)

AI has once again made astonishing progress in the field of mathematics.

On the morning of October 7 (Beijing time), OpenAI announced a series of mathematical results produced by its internal frontier model, ultimately compiling 722 manuscripts and 372 result families on GitHub, covering number theory, geometry, combinatorics, theoretical computer science, and other fields — including important mathematical directions such as the Milne rationality conjecture and algebraic specialization, the quasi-Riemann hypothesis, and Hilbert's tenth problem. OpenAI revealed that approximately 4,000 questions were posed to the model throughout the evaluation process, with each result consuming an average of computing equivalent to about 3 hours of ChatGPT Pro thinking.

That same evening, Ethereum Foundation researcher and technical virtuoso Justin Drake issued a rather radical call — the crypto industry should begin calmly planning for "bunker mode," i.e., gradually migrating assets to new addresses that have never signed a transaction.

Drake's logic is straightforward: the terrifying pace at which AI's mathematical capabilities are evolving could cause the Elliptic Curve Digital Signature Algorithm (ECDSA) to be broken before quantum computing truly matures, directly threatening the security of accounts on mainstream blockchains like Bitcoin and Ethereum.

ECDSA and "Bunker Mode"

For a long time, the cryptocurrency industry has pinned its account security defense on the distant "Q-day" (the day quantum computing breaks modern public-key cryptography). But what Drake is warning about this time is that the mathematical superintelligence brought by AI could well pronounce a death sentence on ECDSA prematurely — on classical computing hardware — and the timescale of this risk can no longer be simply measured in "decades." In the most pessimistic scenario, it could happen within months or years. An attacker might only need to deploy a large GPU cluster to directly reverse-engineer a private key within a single week.

Drake's concern is not entirely unfounded — AI's rate of evolution in mathematical capability is plain for all to see. In May of this year, OpenAI announced AI's counterexample to the Erdős unit distance conjecture; in August, it published progress on a batch of long-standing open problems; in September, it further announced that its internal model had solved the Navier-Stokes Millennium Prize problem; and now, it has publicly released hundreds of mathematical research results at once…

In his call-to-action article, Drake mentioned that we may be at an inflection point where "centuries of mathematical progress unfold within weeks." If AI can challenge humanity's long-held judgments about the difficulty of mathematical problems in an extremely short time, then the problems in cryptography that "we currently consider sufficiently hard" may likewise harbor undiscovered shortcuts.

What makes ECDSA particularly dangerous is that it possesses an extremely rich mathematical structure. Tools ranging from the Schoof algorithm and Frobenius to pairing are all built upon these structures, and one of the design goals of cryptographic hash functions is precisely to minimize exploitable mathematical structure — the richer the structure, the more undiscovered "shortcuts" may theoretically exist.

As a result, Drake proposed a rather extreme hypothesis that he nonetheless believes is worth preparing for in advance. In the future, AI might find a classical algorithm similar to Shor's algorithm that allows an attacker to rapidly derive a private key from public information without relying on a quantum computer. If this happens, assets protected by ECDSA could be directly exposed.

It is against this backdrop that Drake proposed the so-called "bunker mode." For ordinary coin holders, the core recommendation is to gradually migrate assets to new addresses that have never initiated a transaction. The reason for doing so is that the public key of such addresses has not yet been directly exposed on-chain — the address itself has only undergone hashing. Once an address completes a signed transaction, the public key may become public, and if a new type of attack targeting ECDSA emerges in the future, attackers would theoretically have more information to exploit. For key signers such as exchanges, custodians, oracles, and L2 security councils, he offered more aggressive recommendations, including hardening cold wallets, periodically rotating ECDSA public keys, and even adopting hash-based signature schemes for multi-signature where conditions permit.

Drake specifically emphasized that this process should be "slow" — do not panic, and do not rush into large-scale migration, because migration itself generates new operational risks. In particular, addresses holding fewer than 50 BTC are to some extent implicitly protected by the "Satoshi Shield" — that is, the 20,000 addresses under Satoshi Nakamoto's name, each holding 50 BTC, whose public keys are already exposed.

Drake concluded by noting that to safely exit bunker mode in the future, the industry will need a set of "post-AI cryptography" capable of addressing the AI era. He recommended going all-in on hash-based cryptography, completely avoiding any mathematical assumptions that carry structure — because as long as something relies on some complex mathematical structure, one should assume that AI might find a new attack path in the future.

Vitalik's Stance: Transfer Is Fine, but Don't Rush

After Drake issued his warning, Ethereum co-founder Vitalik Buterin also published his own views on the matter.

Compared to Drake's radical warning, Vitalik's stance was noticeably more restrained. He first made clear that he agrees with keeping funds in entirely new addresses that have never signed a transaction, provided the operation is not cumbersome — but he does not recommend that anyone rush to migrate assets today because of AI mathematical breakthroughs, since key migration itself carries operational risks, and a botched migration could cause even greater losses than a hack.

But this does not mean Vitalik considers the risk negligible. On the contrary, Vitalik believes the industry should seriously consider a possibility that has not been adequately incorporated into risk models — not only might elliptic curves be impacted by AI-accelerated mathematics, but even "post-quantum cryptography," which is expected to be the future safeguard, may not be entirely safe.

Vitalik specifically named ML-DSA, FHE, and lattice-based cryptography. The industry has generally believed that quantum computing mainly threatens elliptic curves and RSA, while schemes like lattice-based cryptography can serve as the next-generation security foundation. But Vitalik argues that under the assumption of AI-accelerated mathematics, this distinction may not be so solid.

Vitalik's explanation is that similar situations have repeatedly occurred throughout human history — a problem originally believed to require extremely high computational complexity, yet after decades of research, mathematicians eventually found hidden structure that dramatically reduced the difficulty of breaking it. If AI can compress mathematical exploration that would originally take decades of human effort into years or even months, then undiscovered shortcuts may also exist in lattice-based cryptography.

Like Drake, Vitalik is also more optimistic about purely hash-based cryptography. In his view, schemes such as elliptic curves and lattice-based cryptography are all built on specific mathematical structures, whereas the design goal of hash functions is precisely to avoid such exploitable structure as much as possible. If AI's advantage lies in discovering hidden mathematical structures, then a cryptographic system with "no structure to discover" is clearly more trustworthy.

However, pure hashing cannot solve all problems once and for all. Signatures and proofs can be fully converted to pure hashing, but the real deadlock lies in public-key encryption (PKE) — and this concerns secure website access, encrypted communication, VPNs, and the security foundation of the entire internet. Mathematical theorems have long proven that a public-key encryption system simply cannot be constructed using hash functions alone without any algebraic structure. To achieve it, one must introduce mathematical structures with trapdoors — and as long as structure exists, one must assume AI is capable of making breakthroughs on such structures. Faced with this practical dilemma, Vitalik's suggestion is that if one wants a lattice-based encryption system to remain theoretically secure over the long term, the simplest approach is to directly scale up the parameters and key sizes by a factor of ten.

As for Vitalik's operational recommendations, in addition to advising users against hastily transferring funds, he also proposed two defensive strategies for on-chain applications. First, privacy protocols should preferably stop writing encrypted notes directly on-chain and instead route through off-chain third-party channels as much as possible; second, multi-signature wallets should prioritize completing signature confirmation off-chain to avoid exposing signers' public keys prematurely to the entire network's view. In this way, even if the underlying ECDSA suffers an irreversible mathematical blow, the multi-signature system would merely "gracefully degrade" into a single-signature mode controlled by the signature collector — at least far better than a catastrophic outcome where the doors are wide open and anyone can withdraw at will.

In the AI Era, Is the Industry's Security Foundation Still Solid?

Whether it is Justin Drake advocating extreme defense or Vitalik Buterin emphasizing engineering reality, the successive warnings from these two core Ethereum minds at the same point in time have in effect thrown a heavier philosophical question to the entire cryptocurrency world: When AI begins to lead mathematical research, is the foundation the industry stands on truly solid?

For over a decade, "In Math We Trust" has been the underlying totem of decentralized belief. We have grown accustomed to believing that elegantly complex algebraic structures are firm safe harbors, and we have pushed unknown cracking risks into the distant future. However, OpenAI's progress on hundreds of mathematical conjectures cruelly reveals a fact — what appears "indestructible" in human eyes may simply be because our own computational power moves too slowly through the mathematical maze.

When AI begins to deduce vulnerabilities at a speed that spans centuries in weeks, the balance between offense and defense has already tipped. Future defense may have to move toward a kind of "return to simplicity" minimalism — retreating from the worship of complex and intricate structures to a purely hash-based model with no structure to speak of.

This may be the first true collision at the underlying security level between blockchain and artificial intelligence. For ordinary people caught in the midst of it, there is no need to panic and flee in terror, but one must bid farewell to blind faith in static security. In a new cycle inaugurated by mathematical superintelligence, staying clear-headed and maintaining reverence for unknown attack surfaces is the best "bunker" for protecting on-chain wealth.

Safety
BTC
Satoshi Nakamoto
Vitalik
AI
Welcome to Join Odaily Official Community