Justin Drake proposed gradually moving large crypto holdings to addresses whose public keys have never been exposed.
Fresh Ethereum addresses can keep their public keys hidden until they sign transactions.
Photo Credit: Unsplash/Immo Wegmann
Justin Drake, an Ethereum Foundation researcher, has asked crypto holders to be ready for the possibility of an AI-enabled cracking of the Elliptic Curve Digital Signature Algorithm (ECDSA), stating on October 7 that a worst-case scenario is possible “in months, not years” before quantum computers become a threat. In an October 7 post on X, Drake called on the blockchain industry to start thinking about “bunker mode,” which is a term that he coined. The idea is based on a slow transfer of funds to new addresses, where the public keys have never been exposed, starting with large wallets.
This warning of Drake is still relevant as a risk scenario, but is definitely not proof that ECDSA can be broken. In Drake's definition of the extreme case, he describes the possibility of an attack when a private key is revealed from a public key within one week using the existing hardware. The large GPU clusters might be used for this purpose. However, no attack of this kind has yet been developed.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026The ECDSA algorithm is used to authenticate transactions originating from standard Ethereum addresses. This protocol serves an important purpose for Bitcoin wallet security. The private key creates a digital signature, whereas the public key allows for its verification without knowing the private key.
The official Ethereum post-quantum document indicates that a regular Ethereum address that is just receiving transactions and has never made a transaction would not have exposed its public key to the chain. However, after signing a transaction by this account, the public key will be able to be derived from the signature, which may enable future techniques to derive the private key from it.
Ethereum co-founder Vitalik Buterin has commented on this warning by promoting more caution about AI-assisted math without suggesting immediate movement of funds.
Buterin mentioned that he “does not recommend anyone scramble” to move funds into new wallets now. He explained that developers need to be careful about these advances in math and avoid relying on cryptographic algorithms that could appear to be weaker than anticipated.
But his concerns do not end there. Buterin stated that the security provided by lattice-based cryptography might come under stress because of some AI-assisted mathematical breakthroughs within the next two years. However, he did not say that any of the lattice-based systems have been cracked. He prefers hash-based schemes where possible and uses more conservative parameter sets for lattices.
Earlier this year, research by Google said that quantum computers may require far less computational power than previously estimated to break encryption. The study suggests that cryptographic systems could be more vulnerable than earlier projections indicated. This has raised fresh concerns across the crypto industry, as advances in quantum computing may accelerate the timeline for potential attacks on widely used encryption standards and challenge the long-term security of blockchain-based systems globally.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.