AI Threats Prompt Call for Bitcoin and Ether Holders to Enter ‘Bunker Mode’

Ethereum researcher Justin Drake has urged the crypto industry to start preparing for a possible “bunker mode” as artificial intelligence advances raise concerns about the cryptography securing Bitcoin, Ether and tokens issued on their networks.

Drake said that in the worst-case scenario, AI could find a way to defeat the mathematics behind crypto wallet signatures “in months, not years,” potentially years before quantum computers pose the threat the industry has been preparing for.

In a post on X Wednesday, Drake called for the blockchain industry to begin planning calmly and gradually. He specifically advised large crypto holders to consider moving their assets to new addresses.

Bitcoin and Ethereum wallets rely on private keys to approve transactions. Their corresponding public keys allow the networks to verify those approvals. While deriving a public key from a private key is relatively easy, recovering the private key from the public key is designed to require an infeasible amount of computation.

Drake’s concern is that advanced AI could uncover a shortcut in the underlying mathematics, allowing attackers to recover private keys with conventional computers. Such an attack would potentially bypass the need for quantum hardware.

The consequences could extend across a large portion of the crypto market. Millions of bitcoin are held in addresses where public keys are already visible onchain, according to previous CoinDesk reporting. On Ethereum, any account that has previously sent a transaction has exposed its public key. Stablecoins and tokenized funds issued on Ethereum also depend on the same signature system.

There is no known practical attack that can currently break Bitcoin or Ethereum wallet keys, and CoinDesk found no evidence of one in the research it examined.

AI Is Already Being Used to Find Crypto Flaws

Drake’s warning came shortly after OpenAI released 722 mathematical manuscripts produced by an unreleased AI model tested on roughly 4,000 research problems.

OpenAI said some of the manuscripts contained proofs that could be checked computationally, while other results had not been independently verified and could contain errors.

The manuscripts came from a model OpenAI said last month had solved the Navier–Stokes problem, one of seven Millennium Prize Problems. OpenAI said the model used, on average, computing resources equivalent to about three hours of ChatGPT Pro reasoning for each result.

An independent researcher checked one of the findings within a day and confirmed it. The result involved a new limit on the speed at which computers can multiply large numerical grids, a problem mathematicians have studied since 1969.

Drake said the elliptic-curve mathematics used in Bitcoin and Ethereum signatures has recognizable structures that a sufficiently advanced AI system could potentially learn to exploit. Hash functions are designed differently, turning data into fixed-length fingerprints while minimizing patterns that could be used to reverse them.

AI-assisted attacks have already produced real security problems for crypto projects.

Anthropic researchers showed in December that frontier AI models could develop functional exploits against simulated versions of real DeFi contracts. In late July, the Bitcoin Red Team used AI models to analyze 390 Bitcoin software projects in about 27 hours, identifying nearly 5,000 potential vulnerabilities, including 85 classified as critical.

On July 30, an attacker exploited a five-year-old firmware vulnerability in Coldcard hardware wallets and stole at least 1,367 BTC. Coinkite, Coldcard’s manufacturer, said it suspected AI may have helped discover the flaw.

Days later, BTCPay Server confirmed that attackers had stolen funds from merchants’ Lightning nodes through a vulnerability initially identified during an AI-assisted audit. On Aug. 27, Core Lightning developers issued an emergency warning after AI-generated reports uncovered real vulnerabilities in their software.

Researchers have also used AI coding agents to improve part of a calculation associated with a possible future quantum attack, according to CoinDesk’s September report. That work still required quantum hardware and covered only one portion of the wider attack.

AI Risk Could Precede Quantum Attacks

The potential AI timeline is significantly shorter than the current timetable for quantum resistance. The Ethereum Foundation has set December 2029 as its target for moving Ethereum to quantum-resistant cryptography.

Drake’s worst-case scenario would arrive years earlier, potentially allowing conventional computers to compromise existing wallet protections before that transition is completed.

Post-Quantum Solutions Could Face AI Advances

Ethereum co-founder Vitalik Buterin agreed that AI-driven mathematical advances could pose a serious risk, including to some cryptographic systems designed specifically to withstand quantum computers.

Some post-quantum systems rely on lattice-based cryptography, which is based on mathematical problems considered difficult for both conventional and quantum computers. The technology also underpins a digital-signature standard approved by the U.S. National Institute of Standards and Technology.

Buterin warned that rapid AI advances in mathematics could weaken the practical security of lattice-based systems. If AI can compress decades of mathematical progress into just a few years, he said, that progress could potentially produce significant improvements in methods for attacking lattice cryptography.

Ethereum’s proposed long-term approach increasingly emphasizes hash-based signatures, which use hard-to-reverse digital fingerprints. Buterin believes these designs may provide fewer opportunities for unexpected mathematical shortcuts, although he acknowledged they could still be attacked.

Drake recommended that sophisticated holders move funds gradually to addresses whose public keys have never been exposed onchain. Doing so could deny a potential attacker the public-key information needed to launch an attack.

Buterin agreed that limiting public-key exposure where possible is sensible but warned against rushed migrations. Mistakes during a migration can themselves result in substantial losses.

“I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin wrote.

  • Related Posts

    Ripple Takes On Banks With Fees From Leveraged Stock Financing

    Ripple is expanding its prime brokerage business into leveraged stock ETF financing, entering a market where banks and major securities firms have traditionally provided much of the funding. The move…

    Continue reading
    Bitcoin Loans Move Beyond Trading Into Tuition and Business Funding

    Bitcoin-backed lending is increasingly being used as a source of everyday credit, with borrowers turning to their BTC holdings for liquidity without having to sell. The market is also moving…

    Continue reading