Home/News/Bitcoin and ether holders urged to enter ‘bunker mode’ against possible AI attacks
BTCUSDETHUSD

Bitcoin and ether holders urged to enter ‘bunker mode’ against possible AI attacks

CoinDeskPublished on 2 hours ago

Ethereum researchers warned AI could break the signatures guarding bitcoin, ether and the tokens built on them "in months, not years" in the worst case, well before quantum computers arrive.

Bitcoin and ether holders urged to enter ‘bunker mode’ against possible AI attacks

Ethereum researchers warned AI could break the signatures guarding bitcoin, ether and the tokens built on them "in months, not years" in the worst case, well before quantum computers arrive.

Ethereum researcher Justin Drake urged the crypto industry to prepare for “bunker mode,” warning that artificial intelligence could potentially break the mathematics protecting Bitcoin and Ethereum wallets within months. No practical attack has been demonstrated, but Drake recommended that large holders gradually move funds to addresses whose public keys have never appeared onchain. Ethereum co-founder Vitalik Buterin said AI could also weaken some quantum-resistant cryptography, though he cautioned that rushed wallet migrations can cause losses.

Ethereum researcher Justin Drake has told the crypto industry to start preparing for "bunker mode," warning that artificial intelligence could find a way to break the mathematics protecting bitcoin and ether wallets in the worst case "in months, not years."

"Today I call upon the blockchain industry to calmly start planning for 'bunker mode,'" Drake wrote on X on Wednesday, urging large holders to begin a gradual move of their funds to fresh addresses.

A wallet uses a secret number, called a private key, to authorize payments. A related public key lets the network check those approvals. Generating the public key is easy, but working backward from it to the secret is supposed to take an impractical amount of computing work.

Drake's concern is that AI may help someone find a shortcut, letting an attacker recover the secret and spend the coins on ordinary computers, with no need for the quantum machines the industry has been preparing for.

That would theoretically put a large share of crypto within reach. Millions of bitcoin sit in addresses whose public keys are already visible onchain, as CoinDesk has previously reported. On Ethereum, any account that has ever sent a transaction has revealed its key, and the stablecoins and tokenized funds issued on the network are controlled through that signature system as well.

No practical attack on bitcoin or Ethereum's wallet keys has been demonstrated, and none appeared in the research reviewed by CoinDesk.

AI already a crypto threat

The warning followed OpenAI's release on Tuesday of 722 mathematical manuscripts produced by an unreleased model tested on approximately 4,000 research problems. Some findings have computer-checkable proofs, while others remain unverified and could contain errors, the company said.

The manuscripts came from the model OpenAI said last month had solved the Navier–Stokes problem, one of seven Millennium Prize challenges in mathematics. Each result used, on average, computing power equal to roughly three hours of ChatGPT Pro reasoning, the company said.

Within a day, an outside researcher reran the computer check on one result, a new limit on how fast computers can multiply large grids of numbers, a question mathematicians have worked on since 1969, and found it held.

Drake said the math behind bitcoin and ether wallet signatures, known as elliptic curves, follows tidy patterns that a powerful enough AI could learn to exploit. Hash functions, which turn any piece of data into a fixed-length digital fingerprint that can't be worked backward, are built to scramble information with as little pattern as possible.

AI-assisted attacks on crypto systems have already cost real money.

Last December, Anthropic researchers showed frontier models could write working exploits against simulated copies of real DeFi contracts. In late July, a volunteer group called the Bitcoin Red Team used AI models to sweep 390 Bitcoin software projects in about 27 hours, logging nearly 5,000 possible flaws, 85 of them rated critical.

On July 30, an attacker began draining Coldcard hardware wallets through a five-year-old firmware bug, taking at least 1,367 BTC, and maker Coinkite said it suspected AI helped find the flaw.

Days later, BTCPay Server confirmed attackers had stolen funds from merchants' Lightning nodes through a flaw first surfaced in an AI-assisted audit, and on Aug. 27, Core Lightning's developers issued an emergency warning after AI-generated bug reports turned up real vulnerabilities in their software.

Researchers also used AI coding agents to improve a calculation inside a future quantum attack, as CoinDesk reported in September, though that work still required quantum hardware and covered only part of the attack.

Read More: Crypto researchers cut Bitcoin and Ethereum quantum attack estimate by 50%

The timelines don't line up. The Ethereum Foundation has set December 2029 as its target for moving the network onto quantum-resistant cryptography.

But Drake's worst case puts a classical break years earlier than that.

Quantum resistance has limits

Ethereum co-founder Vitalik Buterin agreed the risk is real and extended it to some of the replacements developers have been counting on.

Some quantum-resistant designs use lattice-based cryptography, mathematical problems believed to be hard for both ordinary and quantum computers, and the approach underlies a digital-signature standard approved by the U.S. National Institute of Standards and Technology.

"There is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math," Buterin wrote on X.“ If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices.

Ethereum's proposed long-term rebuild increasingly favors hash-based signatures, which turn information into digital fingerprints designed to be hard to reverse. Buterin sees fewer openings for unexpected shortcuts in those designs, though he acknowledged they could also face attacks.

Drake recommended that sophisticated holders move first, shifting funds to addresses whose public keys have never appeared onchain, which withholds the starting point the attack would need. On the other hand, Buterin backed reducing public-key exposure where practical, but told holders not to rush, warning that mistakes during a migration can cause losses of their own.

"I personally have lost more money in botched migrations than I have lost in all hacks combined," he wrote.

Read More: Google warns five quantum attack paths could put $100 billion on Ethereum at risk

1NUVA brings U.S. residential mortgage credit to offshore investors 33 minutes ago 2Bitcoin mined for pennies in 2010 moves after 16 years, now worth $8.5 million39 minutes ago 3Bitcoin ETF investors head for the exit, and it's the biggest rush in months55 minutes ago 4Live news: Risk assets under pressure as bond selloff and oil rally intensify1 hour ago 5Bitcoin slips below $83,000 as Ethereum researcher's 'bunker mode' call divides crypto1 hour ago 6Standard Chartered to expand institutional crypto and RWA custody to Singapore2 hours ago 7Greece prepares to levy 10% capital gains tax on cryptocurrency2 hours ago 8Samsung integrates USDC to overhaul cross-border remittances for 82 million Galaxy users3 hours ago 9Crypto investment firm Deus X Capital shuts down as backers pursue separate strategies4 hours ago 10Ripple is earning fees financing leveraged stock bets, a business long run by banks5 hours ago

The Definitive Stablecoin Landscape Series: Asia Pacific

The Definitive Stablecoin Landscape Series: Asia Pacific

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

Why it matters:

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

Bitcoin mined for pennies in 2010 moves after 16 years, now worth $8.5 million

Samsung integrates USDC to overhaul cross-border remittances for 82 million Galaxy users

Ethereum’s Glamsterdam test runs near 200 million gas per block after upgrade