- Ethereum Foundation researcher Justin Drake warned in October 2026 that an AI-enabled mathematical breakthrough could undermine crypto wallet protections before quantum computers do.
- Industry experts said no practical attack on the ECDSA algorithm has been demonstrated, but a successful compromise would threaten the digital signatures used by bitcoin and Ethereum.
- Experts urged blockchain projects to assess their cryptographic dependencies and prepare migration or recovery plans, while warning that premature changes could create additional risks.
Ethereum Foundation researcher Justin Drake warned in October 2026 that artificial intelligence could enable attackers to recover private keys from public keys, potentially compromising crypto wallets before quantum computers can. The scenario matters because it could undermine digital signatures that confirm a user’s right to manage cryptoassets on networks including bitcoin and Ethereum.
Drake urged investors to prepare for “bunker mode.” Ethereum co-founder Vitalik Buterin agreed that the risks should be considered but urged people not to panic.
How AI could threaten wallet security
Drake’s warning concerned the possible discovery of new mathematical methods capable of deriving private keys from public keys. Such a breakthrough would threaten the Elliptic Curve Digital Signature Algorithm, or ECDSA, used by bitcoin and Ethereum.
LTV Protocol co-founder Andrii Sobol said: “This is the foundation on which both the bitcoin and Ethereum protocols are built. The foundation that, when a transaction is made, confirms that you, as a user, have the funds you are going to spend in that transaction. The potential (though for now rather hypothetical) vulnerability is that an attacker could impersonate the user and spend the user’s money for them.”
Hacken Offensive Security Services Director Grzegorz Trawiński said the scenario does not involve ordinary password guessing or accelerating existing attacks. It would require a major cryptanalytic breakthrough that invalidates the mathematical assumptions underpinning digital signatures.
Sobol pointed to mathematical research published by OpenAI. He said the company had released a large body of results from a new model across several fields of mathematics, but little material directly related to cryptography.
“The hypothesis is that OpenAI achieved no less impressive results, but simply did not publish them,” Sobol said. He added that the absence of public findings could mean either that no major breakthrough occurred or that potential vulnerabilities were being withheld until they could be addressed.
Tezos co-founder Arthur Breitman drew a parallel with the Manhattan Project, when scientists who had published research on nuclear fission stopped doing so. In an Oct. 7, 2026 post, Breitman said the lack of cryptographic findings in OpenAI’s mathematical results could itself be a sign, while publication of incremental improvements would weigh against that interpretation.
Experts advise preparation without panic
Drake advised users to move cryptoassets more frequently to new wallets whose public keys have not been disclosed. Trawiński, however, said there was insufficient evidence to justify an immediate move to new wallets or key rotation after every transaction because no practical ECDSA attack had been demonstrated.
“It is important to distinguish between the severity of a hypothetical event and the evidence for how likely it is to occur. A practical compromise would have extremely serious consequences, but that does not mean it is inevitable in the near term,” Trawiński said.
Quantus Network founder Yuvi Lightman said the risks from AI and quantum computers were interconnected because AI could both strengthen and undermine cryptography. He emphasized cryptographic agility, or the ability to update algorithms quickly as new threats emerge.
Lightman said that if U.S. quantum hardware and software company IonQ was not overstating its technological progress, the quantum memory resources needed to break ECDSA could become available as early as 2027.
If such a breakthrough occurs, Lightman said blockchain projects could divide into those with some form of post-quantum protection and those without it. He said capital could move from the latter group to the former, while some investors might leave the crypto market entirely.
Trawiński said projects should prepare for potential threats without treating them as an incident that has already occurred. Priorities include assessing cryptographic dependencies, determining how widely public keys have been exposed and developing plans to migrate to other algorithms.
He also warned that premature migration could introduce risks, including permission-configuration errors and loss of access to funds. A large-scale transition should therefore depend on compelling evidence of a cryptanalytic breakthrough rather than alarming forecasts alone, he said.
Sobol described the likelihood that the cryptographic foundations of some blockchains would be broken in the coming years as “low, but not zero.” He said blockchain protocols should consider recovery mechanisms that could limit losses in a catastrophic scenario.
Source: Incrypted
