Skip to content
Cryptocurrencies

Cryptographers Urgently Debating Whether AI Could Break Bitcoin’s Security ‘in Months’

Coinbase's cryptography head called the idea "the very definition of FUD."
By

Reading time 5 minutes

Comments (1)

Ethereum Foundation researcher Justin Drake warned the blockchain industry on Wednesday to begin preparing for what he called “bunker mode,” arguing that AI-driven mathematical breakthroughs could crack a digital signature scheme used by Bitcoin before quantum computers do. Bitcoin has historically relied on ECDSA signatures, while newer Taproot outputs use Schnorr signatures. Drake’s warning specifically concerns the possibility of an imminent break in ECDSA.

“IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years,” Drake wrote. “By ‘break’ I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).”

Drake is a researcher at the Ethereum Foundation, where he has worked on Ethereum scaling, consensus, and more recently post-quantum security.

No Quantum Computer Necessary?

Tuesday’s OpenAI math dump was the backdrop for Drake’s post. The company published a GitHub pile of new results related to mathematics from an internal model. Drake treated the thin showing on cryptography in OpenAI’s latest release and other similar releases as a tell. “I’ve witnessed first-hand the US government censoring academic quantum cryptanalysis results,” he wrote. “Backroom interventionism is my base case.”

According to Drake, large crypto holders (e.g. Binance, Robinhood, Tether) should move funds to addresses that have never signed a transaction, so the public key stays hidden behind a hash, and should send the remainder to a fresh address whenever they do sign. He added not to rush, because a rushed migration would do more harm than good. According to Drake, getting out of “bunker mode” would necessitate post-AI cryptography, and he said he would push to accelerate the Ethereum roadmap on that front.

Notably, this is the same researcher who has spent much of the past year warning about quantum computing-related threats to crypto. In January, he announced that the Ethereum Foundation had formed a Post-Quantum team led by Thomas Coratger, which he referred to as an inflection point as the foundation had made post-quantum security a top priority after years of quieter work.

Now, Drake claims a classical break, found by an LLM rather than a quantum lab, could land first.

Bitcoiners Push Back

Rob Hamilton, CEO of the bitcoin custody and insurance firm AnchorWatch, and also not a cryptographer, replied that Drake’s post did not show which piece of the math was actually degrading. “Its a strict hypothetical ‘math may break’, which I wouldn’t say is impossible, but I’m looking for meaningful progress on math related to ECDSA that would raise concern,” he wrote. He later asked which open problems, other than the discrete log and P versus NP, would break ECDSA if solved, and argued the recent breakthroughs were answers to defined questions rather than a general crack in hardness assumptions.

Others pointed out that not reusing addresses is already ordinary Bitcoin practice, while Ethereum’s account-based model makes address reuse more natural, as users typically maintain persistent accounts and can receive and send transactions from the same address repeatedly. “Only an Ethereum developer would think that not reusing addresses is ‘Bunker mode’,” wrote pseudonymous Bitcoin Magazine reporter Juan Galt.

Satoshi-candidate Adam Back, who is a cryptographer, the inventor of hashcash, and co-founder and CEO of Blockstream, replied to a public request for comment on Drake’s post with “fud-burger.” Separately, Back pointed to a 2019 post where he had also used the “bunker-mode” terminology when discussing potential issues related to Bitcoin’s long-term security budget, which is an area where Drake has routinely criticized Bitcoin and favored Ethereum’s approach.

Coinbase’s Cryptography Head Says This is ‘Fear Mongering’

The sharpest rebuttal to Drake’s X post came from Yehuda Lindell, who is head of cryptography at Coinbase and a professor of computer science at Bar-Ilan University. He is also an IACR Fellow and the 2026 recipient of the RSA Conference Award for Excellence in the Field of Mathematics.

“I wasn’t going to comment since this is a really bad take IMO, but since it’s taken off I feel the need to,” Lindell wrote. “To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.”

Models proving theorems, he argued, do not show that problems assumed to be hard are not. “But just throwing out – AI is doing amazing math so elliptic curve hardness is in danger has no logical basis whatsoever.”

Lindell also pointed out that a sufficiently general break of widely used public-key cryptography would extend far beyond Bitcoin. For example, fake public-key certificates could impersonate bank websites, and signed malware could be pushed as banking apps or entire operating systems. “But this is fear mongering since there’s zero evidence to this capability existing.”

He also rejected Drake’s claim that curves are softer than hash functions. “In fact historically hash functions have been more broken than elliptic curves. So this is also based on conjecture rather than any evidence.”

Matthew Green, a professor of cryptography at Johns Hopkins, landed somewhere between the takes from Drake and Lindell. “For the record, I don’t know if there are any new cryptanalytic results coming out of the major labs,” he wrote. “If there are, I hope they’d be cautious about disclosure. I do know they have cryptanalysts. They’re not uninterested.”

“What I do think is: you live in a world where machines are outperforming humans on mathematics problems that we’ve fought for years,” he added. These posts appeared to be follow-ups to claims he had made earlier that night where he had gone further. “I think we might lose public key cryptography,” he wrote, then later clarified it. “Well, encryption specifically.”

Jose Storopoli, an engineer at Alpen Labs, posted, “Extraordinary claims demand extraordinary evidence” in response to Green’s suggestion that public-key cryptography could be lost.

The closing statement in Lindell’s thread gets to the clearest reasoning as to why Drake’s original post may have traveled farther than the evidence warranted. “It is the very definition of FUD — it cannot be proven wrong but there’s also no evidence whatsoever of it being true,” Lindell wrote.

The quantum version of this argument already had its moment last year when the theoretical threat, and the $460 billion (at the time) reward attached to Satoshi’s unmoved coins, was the talk of Crypto Twitter. Discussions around that issue are quieter now, even though Coinbase and others have dumped resources into tackling the theoretical issue, and the first quantum-resistant Bitcoin transaction has now been mined.

Drake’s point of view on the potential LLM threat to Bitcoin was good for a viral moment on X, but there’s currently no publicly disclosed evidence of an ECDSA-breaking breakthrough, which makes the idea that this threat could materialize in a matter of months a hard sell.

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.