Ethereum researcher Justin Drake is warning crypto users to begin preparing for a potential “bunker mode” scenario, arguing that increasingly capable artificial intelligence could eventually undermine the cryptography protecting Bitcoin, Ether and tokens built on both networks.
In the most severe scenario, Drake said AI could discover ways to break the mathematics behind crypto wallet signatures “in months, not years,” potentially long before quantum computers are capable of carrying out comparable attacks.
Drake urged the blockchain industry on Wednesday to start planning gradually and recommended that major holders consider moving their funds to newly generated addresses.
Crypto wallets use private keys to authorize transactions, while corresponding public keys allow networks to verify those signatures. Producing a public key from a private key is easy, but calculating the private key from the public key is designed to require an impractical amount of computational effort.
The concern is that AI could discover a shortcut in that mathematics, allowing attackers to recover private keys using ordinary computers. That would create a different and potentially earlier threat than the quantum attacks the crypto industry has been preparing for.
A successful attack could put a substantial amount of crypto at risk. Millions of BTC are stored at addresses whose public keys are already visible onchain, according to previous CoinDesk reporting. On Ethereum, accounts that have previously sent transactions have exposed their public keys, while stablecoins and tokenized funds issued on the network also rely on the same signature technology.
No practical method for breaking Bitcoin or Ethereum wallet keys has been demonstrated, and CoinDesk did not find evidence of such an attack in the research it reviewed.
AI Is Already Finding Crypto Vulnerabilities
Drake’s warning came after OpenAI released 722 mathematical manuscripts Tuesday that were generated by an unreleased model tested against approximately 4,000 research problems. OpenAI said some results included proofs that could be verified by computers, while others remained unverified and could contain errors.
The work was produced by a model that OpenAI said last month had solved the Navier–Stokes problem, one of seven Millennium Prize Problems. According to the company, each result required an average amount of computing equivalent to about three hours of ChatGPT Pro reasoning.
An outside researcher independently checked one of the results within a day. The result established a new limit for the speed at which computers can multiply large grids of numbers, a problem mathematicians have studied since 1969, and the verification confirmed it.
Drake said elliptic curves, which underpin Bitcoin and Ethereum wallet signatures, have mathematical structures that a sufficiently powerful AI system could potentially learn to exploit. Hash functions work differently, converting data into fixed-length digital fingerprints and intentionally minimizing patterns that could make them easier to reverse.
There is already evidence that AI can contribute to attacks against crypto software.
Anthropic researchers demonstrated in December that advanced AI models could produce functional exploits targeting simulated versions of real DeFi contracts. In late July, the volunteer Bitcoin Red Team used AI models to examine 390 Bitcoin software projects in roughly 27 hours, identifying almost 5,000 potential vulnerabilities, including 85 rated critical.
On July 30, an attacker exploited a five-year-old firmware vulnerability affecting Coldcard hardware wallets and stole at least 1,367 BTC. Coinkite, the company behind Coldcard, said it suspected AI may have helped identify the weakness.
Days later, BTCPay Server confirmed that attackers had taken funds from merchants’ Lightning nodes through a vulnerability that had first appeared in an AI-assisted audit. On Aug. 27, Core Lightning developers issued an emergency warning after AI-generated reports helped uncover genuine software vulnerabilities.
Researchers have also used AI coding agents to improve part of a calculation involved in a potential future quantum attack, CoinDesk reported in September. That research still depended on quantum hardware and addressed only part of the overall attack.
AI Could Move Faster Than Quantum Defenses
The Ethereum Foundation currently targets December 2029 for moving Ethereum to quantum-resistant cryptography.
Drake’s worst-case AI scenario would come much sooner, potentially giving conventional computers the ability to break existing wallet protections years before Ethereum’s planned transition.
Quantum-Resistant Cryptography Faces AI Questions
Ethereum co-founder Vitalik Buterin agreed that the risk deserves attention but warned that some cryptographic alternatives designed to withstand quantum attacks could also be affected by rapid advances in AI mathematics.
Some post-quantum systems rely on lattice-based cryptography, which uses mathematical problems believed to be difficult for both conventional and quantum computers. The approach is also used in a digital-signature standard approved by the U.S. National Institute of Standards and Technology.
Buterin said the practical security of lattice systems could face significant pressure from advances in AI-driven mathematics over the next two years. If AI can generate the equivalent of decades of mathematical progress in a short period, he said, that progress could potentially include major improvements in techniques for breaking lattice-based systems.
Ethereum’s proposed long-term cryptographic redesign increasingly favors hash-based signatures. These systems use digital fingerprints designed to be difficult to reverse and may offer fewer opportunities for unexpected mathematical shortcuts, although Buterin acknowledged that they could still face attacks.
Drake’s recommendation for sophisticated holders is to move funds gradually to addresses whose public keys have never appeared onchain. Keeping those keys hidden could remove the information an attacker would need to begin a cryptographic attack.
Buterin supported reducing public-key exposure when practical but warned users not to rush into migrations. Errors during a large-scale transfer could create significant losses of their own.
“I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin wrote.





