AI × Crypto
'Bunker Mode': Drake Says AI Math Could Break ECDSA Within Months; Coinbase's Cryptographer Calls It FUD
Ethereum Foundation researcher Justin Drake asked the industry on October 7 to plan a controlled migration to addresses that have never signed, because AI-assisted mathematics might break ECDSA before any quantum computer does, in the worst case within months. Coinbase's head of cryptography called it FUD with no evidence. The OpenAI release Drake cites contains hundreds of proofs and, in its own README, no claimed attack on elliptic curves. Vitalik Buterin said the risk is real and the migration is where people lose money.
On October 7, Justin Drake, a researcher at the Ethereum Foundation, asked the blockchain industry to "calmly begin planning for 'bunker mode.'" The plan, in his post on X as relayed by Crypto Briefing, is "a controlled mass migration of assets to fresh addresses," meaning addresses whose public keys have never appeared on a chain. The reason is not a quantum computer. It is the possibility, in Drake's words to The Block, that ECDSA, the signature scheme behind most Bitcoin and Ethereum accounts, breaks before "q-day," and that the worst case arrives in "months not years."
He was specific about what a break means: the ability to "recover a private key quickly, for example within one week using available hardware such as a large group of GPUs." He was also specific that nothing has broken. The Block reported that he called the plan "his personal recommendation," that he "did not say that existing cryptography has already been broken," and that "a rushed move could do more harm than good."
By the next morning the industry had split along a line that has nothing to do with elliptic curves and everything to do with what counts as evidence.
What Drake pointed at
The trigger was OpenAI's October 6 release of mathematical results produced by an unreleased internal model, which Drake, per The Block, read as proof that "mathematical superintelligence is upon us." He told Decrypt that "elliptic curves feel especially vulnerable to superintelligence" because of their rich structure, and contrasted them with hash functions, which are built to have none worth exploiting. The outlets covering the release put the count at 722 manuscripts. The repository README, read by this desk on October 9, says 719 manuscripts in 372 families, produced after the model "was posed approximately 4,000 problems," with "~42% top-line results formalized" in Lean. The rest carry a caveat: "Some of the unformalized results could have issues."
What the README does not contain is any claimed result on elliptic curves, discrete logarithms or signature schemes. Its named number-theory results are an irrationality exponent for π and a zero-free region for the Riemann zeta function. crypto.news made the point directly: OpenAI announced no attack on ECDSA. Drake's argument is about the rate of progress, not a paper. That is a legitimate thing to argue, and it is also unfalsifiable on the day it is made, which is where the disagreement starts.
Who said what
The first 24 hours, by position
| Who | Role | Position |
|---|---|---|
| Justin Drake | Ethereum Foundation researcher | Plan a controlled migration now; worst case "months not years" |
| Yehuda Lindell | Head of cryptography, Coinbase | "No evidence whatsoever"; "FUD"; "a really bad take" |
| Charles Guillemet | CTO, Ledger | Looks "like FUD"; migration risks "operational mistakes that lose funds" |
| Vitalik Buterin | Ethereum co-founder | Take it seriously, "don't rush anything" |
| Haseeb Qureshi | Managing partner, Dragonfly | "A very sober call" |
| Dankrad Feist | Ethereum researcher | If keys become exploitable, "your coins are going to zero" |
| Mert Mumtaz | Helius | "Absolutely do not take justin's advice" |
| Jacob Creech | Solana Foundation | Solana users "don't need to go into 'bunker mode'" |
The sharpest reply came from Yehuda Lindell, who runs cryptography at Coinbase and whose name is on a two-party ECDSA signing protocol custodians have used for years. Per The Block, he called the warning "FUD" and wrote that there is "no evidence whatsoever" that the decades-old hardness assumptions behind elliptic-curve cryptography have weakened, and that "making such statements without any evidence is the opposite of responsible behavior." Unchained quoted him calling it "a really bad take." Ledger's Charles Guillemet landed in the same place from the operator's side: a mass migration, he wrote, produces "operational mistakes that lose funds with higher probability" than the thing it guards against.
Haseeb Qureshi of Dragonfly called it "a very sober call," and located the threat where Drake did, in AI-assisted mathematics rather than quantum hardware. Jacob Creech of the Solana Foundation noted that Solana signs with Ed25519 and could add quantum-resistant options through hash-based proofs, so its users need no bunker. Mert Mumtaz of Helius was blunter, per Unchained: "absolutely do not take justin's advice," and the post was "unnecessarily performative."
Buterin: the risk is real, the rush is the danger
Vitalik Buterin's reply, reported by The Block at 1:00 a.m. Eastern on October 8, agreed with Drake's premise and disagreed with the instruction. He said there is "a good chance the concrete security of lattices will take serious hits from the next two years of AI math," which is a statement about the post-quantum replacements, ML-DSA and fully homomorphic encryption among them, more than about ECDSA. His advice to builders was to be "more conservative on lattice parameters and prefer hash-based constructions," and to privacy protocols to "strongly favor not putting encrypted notes onchain."
To holders he said something different. "It's very easy to lose funds from a misconfigured rushed upgrade, so don't rush anything." Unchained quoted the line that travelled furthest: "I personally have lost more money in botched migrations than I have lost in all hacks combined." Keeping funds in an address that has never signed is fine, he said, "if it is easy."
That is the practical core of the whole exchange. On Ethereum, an account that has never sent a transaction has not exposed its public key; the address is a hash of it. Bitcoin is less tidy, as crypto.news noted: pay-to-public-key outputs and Taproot reveal keys without a spend. Drake pointed to Project Eleven's Bitcoin Risq List, which The Block said tracks more than 14 million addresses with exposed keys; crypto.news put the same firm's count at 8.1 million BTC in addresses it classifies as vulnerable. Drake's own comfort for small holders, per The Block, was "Satoshi's shield": roughly 20,000 early addresses holding 50 BTC each, exposed, and the obvious first target for anyone who ever gets the capability. He named Binance, Bitbank, Robinhood, Bitfinex and Tether as institutions that should "consider stronger protection for their cold storage." None had responded in the coverage this desk read.
What the roadmap already said
Drake's third audience was Ethereum's own developers, and here the ask was acceleration rather than a new direction. The Block reported his view that the draft roadmap "already moves toward hash-based cryptography and formal verification to prepare for quantum risks"; Unchained quoted him saying it "must now be revisited and accelerated." Decrypt noted the Foundation has a dedicated post-quantum team. Buterin's preference for WOTS and SPHINCS-style hash signatures over lattices, reported by CryptoPotato, is the same direction with a different reason attached: not that a quantum computer is coming, but that whatever AI does to mathematics, it will have the least purchase on a hash.
The Take
Lindell is right that there is no evidence, and Drake never claimed there was; he claimed a trend, and a trend is not something you can refute with a proof. So the argument is really about burden. Drake's position is that the cost of moving to a fresh address is low and the cost of being wrong the other way is total, which is Feist's "going to zero." Buterin's position is that the cost of moving is not low for most people, and he has the receipts. Both are true, and the second is the one with a body count. The release Drake cites is 719 manuscripts with a 42 percent formalization rate and a note that the rest may be wrong; it is impressive and it is not about curves. The right reading of this week is narrower than either camp wants: nobody has a reason to move funds today, everybody building a post-quantum migration has a reason to finish it sooner, and anyone whose cold storage has signed from a key it still uses has had a reason to rotate for years that has nothing to do with AI. If a classical attack on secp256k1 ever appears, it will not arrive as a thread on X. It will arrive as a transaction from an address nobody has the key to, and by then the only addresses that matter are the ones that never signed.