On October 6, Ethereum co-founder Vitalik Buterin spoke about AI security at the OKX NOW conference in Singapore. He noted that AI models are already breaking out of sandboxes, attacking websites and finding vulnerabilities in software.
“Future generations of AI will also find flaws that nobody has spotted yet,” he said.
Buterin isn’t urging anyone to rush their funds to new wallets. Still, he believes the risks to cryptography from AI-accelerated progress in mathematics already deserve serious attention.
By his estimate, new mathematical methods could seriously weaken some post-quantum encryption systems within the next two years. ECDSA, a digital signature algorithm that, among other things, proves you have the right to spend crypto, could also turn out to be vulnerable sooner than expected.
How Interface Security Is Already Changing
Vitalik stressed that AI models help Ethereum find bugs and run formal verification at the protocol and application level, but they have also shown a real ability to attack. They have escaped sandboxes, knocked websites offline and found exploitable flaws in code.
“As long as there’s a vulnerability in the system, AI will find it. GPT-7 will find it, Claude 7 will find it, DeepSeek 7 will find it too,” he said.
As a real-world example, Buterin pointed to the hack of Safe, one of the largest crypto wallets. The attack hit the layer between the blockchain and the user, and losses totaled almost $1.4B. Buterin sees this layer as the main source of risk, since a significant share of big losses happens at the interface level.
“About a month ago, I updated an ENS record for the first time without a traditional interface. I asked a local AI agent to write a script, and the whole thing took about five minutes. I think this will soon become the norm: we’ll be able to carry out complex blockchain operations directly with AI, and it will gradually become the main way to interact with the network. That will bring its own risks. We’ll need to check whether the AI itself is safe, whether it has been handed someone else’s instructions, and whether it understands what operation it’s performing on the network. Some old problems will go away, and new ones will take their place,” Vitalik said.
Read also: Adam Back: Bitcoin’s Quantum Transition Will Reveal Whether Satoshi’s Coins Are Still Alive
Who’s at Risk and What to Do
On October 7, Ethereum Foundation researcher Justin Drake urged the crypto industry to prepare for “bunker mode” in case ECDSA gets broken. He advises large holders to move most of their funds to addresses that have never sent a transaction, since their public keys stay hidden behind a hash.
“When they do sign a transaction, they should also move the remaining balance to a new address (possibly generated from the same seed phrase),” he wrote.
There’s no need to rush or panic: a hasty migration would do more harm than good, and the transfer itself doesn’t require new cryptography or new wallets. Even so, Drake estimates that ECDSA signatures could be broken before powerful quantum computers arrive, in the worst case within a few months.
What worries him is that AI has started disproving mathematical conjectures that had been considered unassailable for decades. In his view, OpenAI’s latest release signals the arrival of mathematical superintelligence, and the cryptography protecting Bitcoin and Ethereum may turn out to be the weakest link.
Drake also pointed out that almost none of OpenAI’s 722 mathematical results deal with cryptography, and said it’s possible that US authorities are intervening behind the scenes.
“I’ve seen firsthand how they censored academic papers on quantum cryptanalysis,” he said.
The researcher called on major players to set an example. According to him, Binance, Bitbank, Robinhood, Bitfinex and Tether could tighten the protection of their cold storage. Wallets holding less than 50 BTC are partly covered by the “Satoshi shield”: about 20,000 exposed Satoshi addresses, each holding 50 BTC. In the long term, he suggests betting on hash-based cryptography and accelerating Ethereum’s roadmap.
Read also: Galaxy Research Assesses Quantum Attack Risks to Bitcoin
Unlike Drake, Buterin doesn’t recommend moving funds. He says it’s worth keeping coins on addresses that have never sent a transaction if it isn’t difficult, but migrations call for caution.
“Be careful with migrations: I personally have lost more money to failed migrations than to all hacks combined,” Vitalik wrote.
He advises multisig wallet owners to collect confirmations off-chain.
Who Else Weighed In
Coinbase’s head of cryptography, Yehuda Lindell, criticized Drake’s warning.
“There is no evidence that the old assumptions about cryptographic security were wrong. The fact that AI can prove complex mathematical theorems doesn’t mean that problems considered hard today have stopped being hard. The argument that AI is strong at math, so elliptic curve security is under threat, doesn’t hold up logically,” he said.
Lindell also said there’s no evidence that elliptic curves are more vulnerable than hash functions.
“Warning about such a threat without evidence is FUD,” he said.
He noted that if elliptic curve cryptography were actually broken, the consequences would reach far beyond crypto wallets. Attackers could, for example, forge bank certificates and sign malicious apps, but talking about such a threat now is “just scaremongering.”
Casa co-founder and chief security officer Jameson Lopp responded to Drake’s post by pointing to Lindell’s arguments. He said he has spent the past few months watching AI speed up vulnerability discovery, and he considers talk of breaking the cryptography itself premature.
“For the past few months, I’ve watched AI accelerate the search for vulnerabilities, so I think worrying about broken cryptography is premature. We have far more pressing problems to deal with right now. Theoretical future threats can wait,” he wrote.
Haseeb Qureshi, managing partner at the venture fund Dragonfly, replied to Drake’s post in support. He said the warning looks “very sober”: given how fast math is advancing, there’s no reason to take on extra risk.
“The risk isn’t quantum: ordinary math can disprove unproven assumptions about cryptographic security,” he stressed.
Qureshi also noted that for a while, users will have to operate in UTXO mode, meaning they should avoid reusing addresses so that public keys stay hidden.
Our Take
The threat has come from an unexpected direction. The industry used to fear quantum computers that could break a blockchain by sheer computing power. Now the question mark hangs not over the blockchains themselves but over the digital signature system that controls access to funds. For now, this is only a hypothesis: there’s no proof that ECDSA has been broken, and some experts consider the warnings premature.
Market behavior matters too. Hasty mass transfers are dangerous in their own right: Drake warns they would do more harm than good, and Buterin admits he has lost more money to failed migrations than to hacks. And if some holders go looking for protection on exchanges, it’s worth remembering the problems we’ve covered in recent weeks: vulnerabilities and frozen user funds.
Crypto has always carried risks, but each one has pushed the industry to improve its defenses. We can only hope the industry revises and reinforces its security protocols ahead of time. Perhaps the very talk of AI-assisted wallet hacks will lead to more reliable ways to protect wallets.