[Digital Today reporter Seung-ah Yoo] Justin Drake (저스틴 드레이크), a researcher at the Ethereum Foundation, urged the industry to prepare for “bunker mode,” saying ECDSA, the digital signature scheme used by Bitcoin and Ethereum, could be broken by artificial intelligence (AI) before quantum computers.
Decrypt reported on Oct. 7 that Drake recommended a controlled, large-scale transfer that gradually moves assets to new addresses whose public keys are not exposed.
Drake said on X, formerly Twitter, that the blockchain industry should calmly begin planning bunker mode. He proposed a controlled mass migration of assets to fresh addresses that have never been used in transactions. These addresses keep public keys hidden behind a hash, which can reduce the risk of public key exposure.
The core issue is ECDSA. Bitcoin and Ethereum use ECDSA to prove a transaction was approved by the correct private key. When a wallet signs a transaction, the public key can be exposed on-chain. If ECDSA is broken, attackers could derive the private key from the public key and steal assets from a wallet, Drake said.
Drake argued the industry should be prepared for ECDSA to break before “Q-day,” when quantum computers become powerful enough to break current cryptography. In the worst case, he said, the problem could emerge in months rather than years. By “break,” he meant private key recovery fast enough to reconstruct a private key in about 1 week using currently available hardware such as large graphics processing unit (GPU) clusters.
He cited rapid advances in AI-led mathematical research. Referring to 722 research results released by OpenAI on Oct. 7, he said long-held assumptions were being shaken. Drake said elliptic curves appear particularly vulnerable to superintelligence and that their complex mathematical structure leaves room to find new attack methods. By contrast, he said hash functions are designed to withstand this type of attack.
He stressed that holders do not need to rush or panic. Moving assets does not require new cryptography or new wallets, he said. Drake urged Binance, Bitbank, Robinhood, Bitfinex and Tether to strengthen cold storage security.
He also said wallets holding under 50 BTC could be partially protected. Drake called this “Satoshi’s shield.” He said about 20,000 exposed addresses believed to be linked to Bitcoin’s creator hold 50 BTC each, meaning they could be targeted first if an attack becomes reality.
The warning marks an escalation from Drake’s previous claims about threats from quantum computers. After a Google paper in March suggested the timing for quantum decryption could be earlier than expected, he has put the probability of Q-day by 2032 at more than 10 percent. Q-day refers to the point when quantum computers become powerful enough to break currently used cryptography.
The Ethereum Foundation formed a dedicated post-quantum team earlier this year, and co-founder Vitalik Buterin (비탈릭 부테린) has also proposed ways to shift the network to quantum-resistant cryptography. Drake said Ethereum’s roadmap to move to hash-based cryptography should be brought forward further and that he would push for maximum acceleration of defensive measures.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.