On October 7, 2026, Ethereum Foundation researcher Justin Drake published a call for the blockchain industry to begin planning "bunker mode" — a controlled mass migration of funds to addresses whose public keys have never been exposed on-chain. The trigger: OpenAI's October 6 release of 722 AI-ge...
"IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years." — Justin Drake, Ethereum Foundation Researcher
On October 7, 2026, Ethereum Foundation researcher Justin Drake published a call for the blockchain industry to begin planning "bunker mode" — a controlled mass migration of funds to addresses whose public keys have never been exposed on-chain. The trigger: OpenAI's October 6 release of 722 AI-generated mathematical manuscripts, which Drake interpreted as evidence that artificial intelligence could compromise the elliptic-curve digital signature algorithm (ECDSA) securing Bitcoin and Ethereum before quantum computers do.
The response split the industry along a clean fault line. Coinbase's head of cryptography Yehuda Lindell called it "the very definition of FUD." Blockstream CEO Adam Back dismissed it as a "fud-burger." On the other side, Dragonfly's Haseeb Qureshi endorsed precautionary action, and Johns Hopkins cryptography professor Matthew Green said he believes the industry could "lose public-key cryptography." Vitalik Buterin landed between both camps: he agreed the AI-math risk is real but cautioned against hasty wallet migrations, citing personal losses from botched key rotations.
At stake is not an abstract cryptographic debate. Over 6 million BTC — 31.2% of circulating supply — sit behind exposed public keys visible on-chain, according to Glassnode data cited by CoinDesk. On Ethereum, every externally owned account that has ever signed an outbound transaction has its public key permanently exposed. Google Quantum AI's April 2026 whitepaper, co-authored with Drake and Stanford's Dan Boneh, mapped five attack paths putting more than $100 billion of on-chain value at risk.
On October 6, 2026, OpenAI pushed 722 mathematics manuscripts to a public GitHub repository, crediting the work to an unnamed internal frontier model. The manuscripts are grouped into 372 result families across 17 mathematical fields. Of the 722 papers, 162 include Lean proof formalizations for machine verification. OpenAI disclosed that the model was posed roughly 4,000 problems in total, with the 722 manuscripts representing the subset the company judged worth publishing. Each result consumed approximately three hours of ChatGPT Pro compute on average.
The claims are substantial: a zero-free half-plane for every Dirichlet L-function, the Mahler conjectures, a counterexample to Kaplansky's zero-divisor conjecture, and the isomorphism of the free group factors. Twenty-five Fields Medalists have publicly pushed back on the unverified claims, and mathematician Terence Tao criticized OpenAI for releasing 722 manuscripts at once, arguing it risks degrading the verification process.
For Drake, the signal was not whether any individual result was correct. It was the velocity of AI mathematical capability. Elliptic curves — the mathematical structures underpinning ECDSA — carry "rich structure with room for sophisticated mathematical techniques," Drake wrote. If AI systems can now generate plausible proofs across 17 mathematical fields in hours, the safety margin on elliptic-curve assumptions narrows.
Drake defined a practical break of ECDSA as the ability to recover a private key in roughly one week using accessible hardware, such as a large GPU cluster. His proposed countermeasure, "bunker mode," consists of three elements:
Drake emphasized that institutions should review exposed public keys in cold storage, and that critical infrastructure operators — oracles, layer-2 security councils, multisig holders — should rotate keys or add hash-function-based backup signatures. His long-term recommendation: abandon structured mathematical assumptions entirely and move to hash-based cryptography using SHA or BLAKE family hash functions.
Drake characterized his call as a personal recommendation, not an emergency alert. No practical attack on Bitcoin or Ethereum signatures has been demonstrated.
The numbers define the stakes. According to Glassnode data reported by CoinDesk on October 8, more than 6 million BTC sit behind public keys already visible on-chain. That figure represents 31.2% of Bitcoin's circulating supply — roughly 5 to 6 percentage points above the low reached in 2023. At Bitcoin's current price near $81,000, the exposed value exceeds $486 billion.
Bitcoin addresses that have never been spent from expose only the hash of the public key, which provides an additional layer of protection. But once a transaction is signed, the full public key is permanently visible. Newer Taproot outputs use Schnorr signatures rather than ECDSA, but both rely on the same elliptic-curve discrete logarithm problem (ECDLP).
On Ethereum, the exposure is structurally broader. Every externally owned account (EOA) that has ever sent a transaction has its public key on-chain. Google Quantum AI's April 2026 whitepaper identified the top 1,000 wallets by ETH balance — collectively holding about 20.5 million ETH — as the most economically rational targets for a future attacker. Additionally, about 37 million ETH is staked and exposed to potential slashing and ejection through consensus-layer attacks. The paper enumerated 70-plus admin-controlled smart contracts, including upgrade or minter keys behind major stablecoins, where a compromised key could let an attacker mint, freeze, or rewrite contract logic.
The pushback was immediate and forceful.
Yehuda Lindell, head of cryptography at Coinbase, stated: "To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography." He characterized Drake's warning as "the very definition of FUD — it cannot be proven wrong but there's also no evidence whatsoever of it being true."
Blockstream CEO Adam Back dismissed the concerns as a "fud-burger."
Charles Guillemet, CTO of Ledger, said AI has not produced any practical break of Bitcoin's ECDSA cryptography. "A new maths result is not the same as a working attack," Guillemet stated, citing a recent integer multiplication algorithm improvement as an example of theoretical advance that does not translate to a deployed exploit. He warned that a broad failure of asymmetric cryptography would extend far beyond Bitcoin, affecting internet security, banking systems, secure communications, and critical infrastructure simultaneously.
Rob Hamilton, CEO of AnchorWatch, noted there was insufficient evidence showing which mathematical problems, if degraded, would actually impact ECDSA security in practice.
The skeptics' core argument: OpenAI's 722 manuscripts are mathematical artifacts, not cryptanalytic attacks. No model has demonstrated the ability to solve the elliptic-curve discrete logarithm problem. Solving the Unique Games Conjecture, while mathematically significant, does not create a path to breaking ECDSA. The leap from "AI is getting better at math" to "AI will break cryptography" requires intermediate steps that have not been shown.
Two voices landed between the camps with notable precision.
Vitalik Buterin agreed the risk is real but urged calm. "We should take the risks to cryptography from AI-accelerated math seriously," he wrote, before adding: "I don't recommend anyone scramble to move their funds to new wallets today." Buterin cited his own losses from botched migrations as reason for measured action over panic. He offered a more unsettling secondary warning: the lattice-based schemes the industry has been treating as the quantum-safe fallback "will take serious hits from the next two years of AI math." If both ECDSA and lattice-based cryptography prove fragile, the industry's current post-quantum roadmap loses its assumed safe harbor.
Matthew Green, cryptography professor at Johns Hopkins, offered the most measured technical assessment: "You live in a world where machines are outperforming humans on mathematics problems that we've fought for years. Do you also think humans just nailed it down the line with our analysis of Module LWE and ECDLP and (already weirdly subexponential) factoring?" Green later clarified that he believes the industry could "lose public-key cryptography" — specifically public-key encryption — as a result of continued AI mathematical progress.
Dragonfly's Haseeb Qureshi called Drake's warning "a very sober call" but rejected the bunker mode approach itself. Qureshi characterized bunker mode as "cryptographic doomerism," arguing that migrating tokens to fresh addresses was not a real solution. Instead, he proposed "cryptographic recovery mode" using hash-based backup signatures to secure digital signatures — an approach that could protect funds even if ECDSA is broken without requiring a preemptive mass migration.
Computer scientist Scott Aaronson, formerly of OpenAI's safety team and currently at the University of Texas, added a separate data point. In an October 2026 update on his Shtetl-Optimized blog, Aaronson wrote that major AI companies had begun "gingerly and discreetly" investigating whether their latest internal models could compromise "important cryptographic protocols and primitives." His information came from sources inside AI companies rather than official statements.
Aaronson flagged one additional observation: among OpenAI's 722 published manuscripts, there was a notable under-representation of cryptographic results. He characterized this absence as "potentially significant" — implying either that the models had not been tested against cryptographic problems, or that results in that domain were being withheld.
No source has confirmed that any AI model has found a practical way to break ECDSA, RSA, or any other deployed cryptographic scheme. Aaronson's warnings remain a risk assessment, not proof of an attack.
Ethereum's formal timeline targets quantum-resistant cryptography across execution, consensus, and data layers by December 2029. Buterin has assigned roughly 20% probability to a pre-2030 quantum breakthrough.
The primary mechanism is EIP-8141, which uses native account abstraction to give individual accounts signature agility — the ability to switch to a post-quantum signature scheme without waiting for the entire protocol to change. EIP-8141 is under consideration for the Hegotá upgrade, expected in 2027. Before that, the Glamsterdam upgrade targeting mainnet in early December 2026 includes EIP-7976 (64-gas-per-byte pricing), which lays groundwork for post-quantum transaction formats.
Between Glamsterdam and the target completion date, the network would need to ship five additional upgrades at an average interval of roughly 7.2 months. The team has not set fixed mainnet dates for upgrades after Glamsterdam.
Bitcoin has no equivalent roadmap. Taproot introduced Schnorr signatures, but both Schnorr and ECDSA rely on the same underlying ECDLP hardness assumption. A break of one implies a break of both.
The debate crystallizes a fundamental question about economic value distribution in blockchain infrastructure: who bears the cost of a cryptographic migration, and who benefits from inaction?
A mass migration to fresh addresses carries real economic costs: transaction fees, operational risk from key management, and the possibility of permanent fund loss from migration errors — the exact risk Buterin cited from personal experience. Smart contracts with admin keys cannot simply be "migrated"; they require governance votes, multisig coordination, and in many cases, protocol upgrades.
Inaction is free until the moment it is catastrophic. The $486 billion in BTC and $100 billion-plus in ETH behind exposed public keys represent a theoretical maximum loss in a worst-case ECDSA break. In practice, an attacker would need to drain funds faster than the market could respond — but Drake's one-week break timeline, if realized, would likely outpace any coordinated emergency response.
The economic incentive structure favors waiting. Until evidence of a practical attack emerges, migration costs are certain while attack costs are probabilistic. This asymmetry explains the industry's muted response to quantum and AI threats over the past decade.
The bunker mode debate is not about whether ECDSA is broken today. It is about whether the rate of AI mathematical progress justifies spending real resources to prepare for a break that may never come — or may arrive faster than institutional processes can respond.
The data is inconclusive on the core technical question. No AI model has demonstrated the ability to solve ECDLP. OpenAI's 722 manuscripts, while broad, do not include published cryptanalytic results. But the absence of published results, as Aaronson noted, may itself carry information.
What is not in dispute: hundreds of billions of dollars in crypto assets sit behind cryptographic assumptions that were designed in an era before AI systems could produce plausible mathematical proofs across 17 fields in a single release. Whether that changes the probability of a break is the question the industry now has to price.