Coinbase Cryptographer Challenges AI Crypto Security Warning as FUD
A growing debate over artificial intelligence and cryptocurrency security has divided prominent researchers after Ethereum Foundation researcher Justin Drake warned that advances in AI-powered mathematics could threaten the cryptographic systems protecting digital assets sooner than expected.
Yehuda Lindell, head of cryptography at Coinbase, strongly disputed the urgency of Drake’s warning, describing the recommendation for cryptocurrency holders to move funds into fresh addresses as “the very definition of FUD.” Vitalik Buterin, Ethereum’s co-founder, took a more measured position: he urged the industry to investigate AI-related cryptographic risks but advised against rushing into wallet migrations.
The disagreement centers on whether increasingly capable AI systems could uncover weaknesses in mathematical problems that underpin digital signatures. Although the researchers differ over the likelihood and timing of a breakthrough, the discussion has renewed attention on long-term security planning for Bitcoin, Ethereum and other blockchain networks.
Coinbase’s Lindell Challenges the Warning
Drake raised the alarm in a post on X, arguing that it was reasonable to prepare for the possibility that the Elliptic Curve Digital Signature Algorithm (ECDSA) could be broken before the arrival of a sufficiently powerful quantum computer. He described the worst-case timeline as potentially months rather than years.
ECDSA is a digital-signature system used to authorize transactions on Bitcoin and Ethereum. A signature demonstrates that someone controls the relevant private key without revealing the key itself. If an attacker could reliably derive private keys or forge valid signatures, affected accounts could become vulnerable to unauthorized transactions.
Lindell challenged the evidence behind Drake’s assessment. In his response on X, he argued that AI’s growing ability to prove difficult mathematical theorems does not establish that established cryptographic assumptions are about to fail.
He also disputed the suggestion that elliptic-curve cryptography is necessarily more vulnerable to AI-assisted mathematical advances than hash functions. In Lindell’s view, claims about which cryptographic systems will fail first remain speculative without concrete cryptanalytic results demonstrating such a weakness.
What “Bunker Mode” Means for Crypto Holders
Drake recommended that cryptocurrency holders consider moving assets to addresses that have never signed a transaction. The idea is to keep public keys hidden behind cryptographic hashes for as long as possible, reducing exposure if a future attack can exploit a revealed public key.
A public key is used to verify digital signatures, while a private key authorizes them. Some blockchain address formats expose or reveal the public key when funds are spent. If the underlying signature scheme were compromised, an exposed public key could give an attacker a more direct target.
However, moving assets introduces its own risks. Users must verify destination addresses, manage transaction fees and protect their recovery information. Complex migrations can also create opportunities for mistakes, phishing attacks or lost funds.
The debate is therefore not simply about whether new addresses offer additional protection. It is also about whether the available evidence justifies urgent action, and whether the operational risks of moving funds outweigh the potential benefit for a particular user.
Buterin Urges Research Beyond Elliptic Curves
Vitalik Buterin rejected the idea that users should immediately rush to move their assets, while agreeing that AI-assisted mathematical research deserves serious attention. In his response on X, he encouraged reducing exposure to cryptographic systems that could become vulnerable to either quantum computing or advances in AI-driven mathematics.
Buterin highlighted a less-discussed concern: post-quantum cryptography may not be immune to future mathematical breakthroughs. He specifically pointed to lattice-based systems, including ML-DSA and technologies used in fully homomorphic encryption (FHE).
ML-DSA, or Module-Lattice-Based Digital Signature Algorithm, is a post-quantum digital-signature standard designed to resist known attacks from both conventional and quantum computers. Its standardization is part of the broader effort to prepare digital infrastructure for advances in computing. The U.S. National Institute of Standards and Technology’s post-quantum cryptography program documents this transition.
Buterin’s concern is that the security estimates for these systems could also change if AI helps researchers discover substantially more efficient attacks. That does not mean lattice-based cryptography has been broken; it means its long-term security assumptions should continue to be tested.
He also said that moving funds to unused addresses can be reasonable when the process is straightforward, but cautioned against complicated migrations. He noted that he had personally lost more money through poorly executed migrations than through hacks.
Researchers Disagree Over the Consequences
Dankrad Feist, formerly an Ethereum Foundation researcher and now associated with Tempo, questioned whether address migration would help if elliptic-curve cryptography were broadly broken. In his view, a powerful attack capable of compromising exposed public keys could undermine confidence in the assets themselves, making a move to a fresh address insufficient protection.
Ledger chief technology officer Charles Guillemet raised a related point. A practical attack against secp256k1, the elliptic curve used by Bitcoin and Ethereum, could have implications beyond cryptocurrencies. Public-key cryptography also supports encrypted communications, software signing and other security systems.
Matthew Green, a cryptography professor at Johns Hopkins University, expressed concern that AI could substantially improve attacks against standardized public-key schemes. He argued that cryptographic security has historically relied on the best attacks researchers knew how to construct, and that AI could change what is considered feasible.
Green also noted that the absence of a major cryptanalysis result in publicly released AI research does not establish that such work is not happening privately. However, no published result described in this debate demonstrates that AI has broken Bitcoin’s or Ethereum’s elliptic-curve cryptography.
Haseeb Qureshi, managing partner at Dragonfly, supported taking Drake’s warning seriously, arguing that rapid progress in mathematics could challenge assumptions that have remained secure for decades.
AI Advances Renew the Post-Quantum Security Debate
Drake’s warning followed OpenAI’s October 6 publication of mathematical results produced by an internal model, including formalized proofs. The company’s mathematics research update describes the work, but the published results discussed in this debate were not cryptanalytic attacks against cryptocurrency signature systems.
Drake cited developments involving integer multiplication, the 3SUM conjecture and the Erdős unit distance conjecture as reasons to reassess assumptions about the limits of mathematical problem-solving. His argument is that AI could uncover results that human researchers have not found, potentially changing the estimated security of existing cryptographic systems.
Ethereum’s post-quantum research efforts have already explored ways to prepare for future changes in cryptography. The debate has increased pressure to evaluate those plans not only against quantum computing, but also against possible improvements in conventional mathematical attacks.
For now, the central question remains unresolved: AI systems are improving at mathematical reasoning, but there is no publicly demonstrated break of the elliptic-curve cryptography protecting Bitcoin and Ethereum in the evidence discussed here. The disagreement highlights the challenge of preparing for emerging threats without presenting unproven scenarios as established facts.