Ethereum researcher Justin Drake is urging the crypto industry to begin preparing for what he calls “bunker mode,” warning that advanced artificial intelligence could potentially break the cryptographic protections securing Bitcoin, Ether and tokens built on those networks.
In a worst-case scenario, Drake said AI could undermine the mathematics protecting crypto wallets “in months, not years,” potentially well before quantum computers become capable of carrying out similar attacks.
Drake called on the blockchain industry Wednesday to start preparing gradually and advised major crypto holders to consider moving their assets to fresh addresses.
Bitcoin and Ethereum wallets depend on private keys to authorize transactions. The corresponding public keys allow networks to verify those signatures. Although generating a public key from its private key is straightforward, reversing the process is designed to require an infeasible amount of computing power.
Drake’s concern is that AI could discover a mathematical shortcut that makes this reversal possible on conventional computers. Such a development would remove the need for the quantum computing systems that the crypto industry has largely viewed as the longer-term threat to existing wallet security.
The potential impact would be significant. Millions of BTC are held in addresses where public keys are already exposed onchain, according to previous CoinDesk reporting. On Ethereum, any account that has previously sent a transaction has revealed its public key. Stablecoins and tokenized assets issued on Ethereum also depend on the same digital-signature infrastructure.
There is currently no demonstrated practical attack capable of breaking Bitcoin or Ethereum wallet keys, and CoinDesk found no such attack in the research it reviewed.
AI Attacks Are Already Emerging
Drake’s warning followed OpenAI’s release Tuesday of 722 mathematical manuscripts generated by an unreleased AI model that was tested against about 4,000 research problems. OpenAI said some of the results had proofs that could be verified by computers, while other findings remained unconfirmed and could contain errors.
The manuscripts came from a model OpenAI said last month had solved the Navier–Stokes problem, one of the seven Millennium Prize Problems. The company said each result required computing resources equivalent, on average, to about three hours of ChatGPT Pro reasoning.
An outside researcher subsequently reran the computer verification of one result within a day. The work established a new limit on how quickly computers can multiply large numerical grids, a mathematical problem that has been studied since 1969. The researcher found the result held.
Drake said the elliptic-curve mathematics used by Bitcoin and Ethereum signatures contains organized structures that sufficiently powerful AI could potentially learn to exploit. Hash functions are designed differently, converting data into fixed-length digital fingerprints while minimizing exploitable patterns.
AI-assisted security attacks have already caused financial losses in the crypto industry.
Anthropic researchers demonstrated last December that advanced AI models could create working exploits against simulated versions of real DeFi contracts. In late July, the volunteer Bitcoin Red Team used AI models to examine 390 Bitcoin software projects in roughly 27 hours and identified nearly 5,000 potential vulnerabilities, including 85 considered critical.
On July 30, an attacker exploited a five-year-old firmware vulnerability in Coldcard hardware wallets, stealing at least 1,367 BTC. Coinkite, the wallet manufacturer, said it suspected AI may have helped identify the vulnerability.
Days later, BTCPay Server said attackers had stolen funds from merchants’ Lightning nodes through a flaw that had initially emerged during an AI-assisted audit. On Aug. 27, Core Lightning developers issued an emergency alert after AI-generated bug reports helped identify real vulnerabilities in their software.
Researchers have also used AI coding agents to improve part of a calculation involved in a potential quantum attack, according to CoinDesk reporting in September. That work still required quantum hardware and addressed only one portion of the broader attack process.
AI Risk Could Arrive Before Quantum Threat
The timeline for quantum resistance is already established. The Ethereum Foundation has set December 2029 as its target for transitioning Ethereum to quantum-resistant cryptography.
Drake’s worst-case AI scenario would arrive years earlier, potentially allowing conventional computers to break existing wallet protections before the planned transition.
Post-Quantum Systems Face Their Own Questions
Ethereum co-founder Vitalik Buterin agreed that the AI threat should be taken seriously but warned that some cryptographic systems being considered as replacements may also be vulnerable to advances in AI-driven mathematics.
Some post-quantum cryptographic systems use lattice-based methods, which rely on mathematical problems believed to remain difficult for both traditional and quantum computers. Lattice cryptography also underpins a digital-signature standard approved by the U.S. National Institute of Standards and Technology.
Buterin argued that major advances in AI mathematics over the next two years could weaken the practical security of lattice-based systems. If AI manages to compress decades of mathematical progress into a few years, he said, that progress could potentially produce major improvements in techniques for attacking lattice-based cryptography.
Ethereum’s proposed long-term redesign increasingly favors hash-based signatures, which rely on digital fingerprints designed to be difficult to reverse. Buterin sees fewer opportunities for unexpected mathematical shortcuts in those systems, while acknowledging that they could still face new attacks.
Drake recommended that sophisticated holders take precautions early by transferring funds to addresses whose public keys have never appeared onchain. Keeping the public key hidden could remove information a potential attacker would need to begin an attack.
Buterin agreed that reducing public-key exposure where possible makes sense, but warned against rushing into migrations. Poorly executed transfers can introduce their own security risks and lead to losses.
“I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin wrote.

































