MCAP $2.80T ▼ 2.88% 24H VOL $118.3B BTC.D 59.1% FEAR & GREED 59 Greed BTC FEE 1 sat/vB BTC $82,583 ▼ 0.41% ETH $2,501 ▼ 2.52% USDT $0.9992 ▼ 0.02% BNB $743.71 ▼ 3.17% XRP $1.40 ▼ 0.69% USDC $0.9996 ▼ 0.01% SOL $110.32 ▼ 4.07% TRX $0.3319 ▼ 0.81% FIGR_HELOC $1.03 ▲ 1.17% ZEC $1,226 ▼ 1.30%

Ethereum

Vitalik Buterin says AI risk does not justify rushed wallet moves

Buterin told holders not to scramble into new wallets while warning that AI-driven math progress may weaken ECDSA and lattice-based cryptography.

CoinDesk AI Desk
· 3 min read
✓ 2 SOURCES CHECKED
Vitalik Buterin says AI risk does not justify rushed wallet moves
Image: CryptoPotato

Key takeaways

  1. Timelines differ. Drake said ECDSA could theoretically be broken in months rather than years in a worst case.
  2. Lattices are included. Buterin said lattice-based systems could take damage from AI math progress over the next two years.
  3. Migrations cost money. Buterin said botched migrations had cost him more money than all hacks combined.

What happened

Vitalik Buterin said holders should not rush to move funds into new wallets, even as he warned that AI-assisted mathematics could weaken established cryptography sooner than expected.

His post answered a call from Ethereum researcher Justin Drake for the industry to prepare for bunker mode. Drake urged large holders to move funds to fresh addresses whose public keys stay hidden behind hashes.

Drake argued ECDSA could theoretically be broken in months rather than years, and said a breakthrough could happen within months in a worst-case scenario.

Buterin disputed the pace, not the risk. He wrote that users should not "scramble to move their funds to new wallets today," and said the industry should cut exposure to quantum-vulnerable and potentially AI-vulnerable cryptography.

Why it matters

Buterin's concern extends beyond quantum computing. He argued that humans may have missed mathematical shortcuts that AI systems could discover, and he said lattice-based systems such as ML-DSA and fully homomorphic encryption deserve the same scrutiny as elliptic curves.

He said lattice-based systems could take damage from AI math progress over the next two years, and asked what happens if flaws exist in both elliptic curves and lattices that humans have not found yet, but AI tools soon will.

Yehuda Lindell, head of cryptography at Coinbase, pushed back, saying there is "no evidence whatsoever" that decades-old assumptions behind elliptic-curve cryptography are close to failing.

For holders, rushing carries its own cost. Buterin said botched migrations had cost him more money than all hacks combined.

Background

Ethereum's long-term plan already leans toward hash-based signatures such as WOTS and SPHINCS rather than lattice methods. Buterin said hash-based methods lack the kind of mathematical structure that could be exploited by AI tools.

He noted that public key encryption is harder to build this way, and long-standing math results show it cannot rely on hashes alone. Public-key encryption is still required for communications, privacy networks, websites, and VPNs.

What is still unclear

  • It is not settled whether AI will find weaknesses in elliptic curves, in lattices, or in neither.
  • Drake's worst-case timeline of months is disputed. Lindell says the old assumptions are not close to failing.
  • Whether hash-based tools can cover every use case remains open, because public-key encryption cannot rely on hashes alone.

Questions readers ask

Should I move my crypto to a new wallet now?

Buterin said he does not recommend scrambling to move funds to new wallets today. Keeping money in addresses that have never signed a transaction is a smart move if it is easy to do, he added.

Is ECDSA at risk from AI?

Drake said ECDSA could theoretically be broken in months rather than years, and warned a breakthrough could happen within months in a worst-case scenario. Lindell said there is "no evidence whatsoever" that decades-old assumptions behind elliptic-curve cryptography are close to failing.

What does Buterin suggest for multisig wallets?

He said each signer should change their key after every operation. He first suggested gathering confirmations offchain so signer keys remain hidden, then corrected himself.

Why does Ethereum favor hash-based signatures?

Buterin said hash-based methods lack the kind of mathematical structure that could be exploited by AI tools. Ethereum's plan already leans toward WOTS and SPHINCS.

Sources · 2 publishers

  1. CryptoPotato TIER 2 FIRST REPORT
    Vitalik Buterin: AI Risk Doesn’t Justify Rushed Wallet Moves
  2. CoinCentral TIER 3
    Vitalik Buterin Warns Crypto Industry Against Rushing Wallet Moves as AI Threatens Cryptography