News Global

Ethereum Researcher Urges "Bunker Mode" as AI Threatens Wallet Security

Ethereum researcher pictured beside a hardware wallet and security warning as the graphic highlights calls for “Bunker Mode” amid AI-related wallet security concerns.
An Ethereum researcher is urging stronger wallet security measures as AI capabilities raise new concerns about potential threats to crypto users.

Executive summary

Ethereum Foundation researcher Justin Drake has urged the blockchain industry to begin calmly preparing for a possible AI-assisted break of ECDSA, the cryptographic signature scheme securing most Ethereum and Bitcoin wallets, warning on October 7 that a worst-case failure could arrive "in months not years," well ahead of the quantum computing threat the industry has been preparing for.

Drake is calling for a gradual, controlled migration of funds into fresh addresses whose public keys remain unexposed, starting with large holders and institutions. Ethereum co-founder Vitalik Buterin responded by backing the need to take AI-driven cryptography risks seriously, while explicitly cautioning against panic or rushed wallet migrations. Importantly, this remains a risk scenario: no working attack against ECDSA has been published, and OpenAI's own recent math research release, which partly prompted Drake's warning, did not claim to break any cryptographic system.

Drake's Proposal: A Controlled Retreat, Not a Scramble

Drake's warning, posted to X on October 7, calls on the blockchain industry to "calmly begin planning for 'bunker mode.'" His core proposal is a gradual, voluntary migration: holders move remaining assets into addresses whose public keys have never been exposed onchain, starting with large holders and institutions rather than everyday users. Notably, Drake's immediate proposal doesn't require a new wallet format or a new cryptographic algorithm, addresses generated from the same seed phrase can serve the purpose, since the vulnerability lies specifically in exposed public keys, not in the underlying wallet technology itself.

The mechanics matter here. ECDSA secures standard Ethereum accounts and most Bitcoin wallets by using a private key to generate a signature, while the matching public key lets the network verify that signature without revealing the private key itself. Ethereum's own documentation confirms that an account which has only received funds, and never sent a transaction, has not exposed its public key onchain. The moment an account signs a transaction, though, its public key becomes recoverable from that signature, which is the exposure Drake is warning about. He repeatedly cautioned against panic throughout his post, warning that a poorly managed migration could introduce its own risks, user error during a rushed move is arguably a more immediate danger than the theoretical attack itself.

Buterin Agrees on the Risk, Not the Urgency

Vitalik Buterin's reaction adds useful nuance rather than amplifying alarm. He said he doesn't "recommend anyone scramble" to move funds today, while agreeing that AI-driven advances in mathematics deserve to be taken seriously, and that the industry should generally reduce its dependence on cryptographic assumptions that could prove weaker than currently believed. His concern isn't limited to elliptic-curve cryptography like ECDSA, Buterin specifically flagged that the concrete security of lattice-based cryptography could also face pressure from AI-assisted mathematical discovery over roughly the next two years, though he stopped short of claiming any lattice-based system has actually been broken. His practical guidance favors hash-based cryptographic designs where feasible and more conservative parameters for lattice-reliant systems, alongside his broader message: take the risk seriously, but don't let urgency create new mistakes.

Where OpenAI's Math Release Actually Fits In

Drake explicitly tied the timing of his warning to OpenAI's October 6 publication of mathematical research generated by an internal, unreleased frontier model, a public repository now containing 722 manuscripts across 372 result families, produced after the model was tested on roughly 4,000 research problems.

It's worth being precise about what that release actually was. OpenAI's announcement did not claim any attack against ECDSA, RSA, or cryptocurrency systems specifically, and the repository itself states that results are at varying stages of verification, not every manuscript includes formal proof verification, and some unverified results "could have issues." Drake's interpretation of what this pace of progress might eventually enable is considerably more aggressive than OpenAI's own framing; he wrote that "mathematical superintelligence is upon us" and questioned whether AI-assisted classical algorithms could find shortcuts against elliptic-curve cryptography before quantum computers become capable of the attack at meaningful scale. That remains his personal risk assessment, not a demonstrated cryptographic break, a distinction several outlets covering this story have been careful to preserve.

Ethereum's Post-Quantum Groundwork Was Already Underway

This warning doesn't arrive in a vacuum. Ethereum has been preparing for cryptographic transition for some time: its Post-Quantum Security team, formed in January 2026, has been testing hash-based validator signatures, new proof systems, and post-quantum interoperability across multiple client teams. The current roadmap centers on leanXMSS, a hash-based signature design meant to eventually replace quantum-vulnerable validator signatures, paired with leanVM for efficiently aggregating larger post-quantum signatures, targeting core infrastructure readiness around 2029, though Ethereum describes that date as a planning target rather than a firm commitment. Separately, EIP-8141 would eventually give individual accounts more flexibility in how transactions are authenticated, potentially allowing a quantum-resistant signature method without requiring a full move to a new address format. Outside Ethereum, NIST finalized a hash-based post-quantum signature standard (SLH-DSA) back in 2024, and institutional custody providers including BitGo and Coinbase have separately begun testing post-quantum approaches of their own.

References

  1. crypto.news: Ethereum researcher warns AI could crack crypto wallets https://crypto.news/researcher-warns-ai-could-crack-crypto-wallets/

Cite this

Evelyn (2026, October 8). Ethereum Researcher Urges "Bunker Mode" as AI Threatens Wallet Security. AI News Report. https://ainewsreport.org/blog/ethereum-researcher-urges-bunker-mode-as-ai-threatens-wallet-security