AI News

Justin Drake warns OpenAI math advances threaten Bitcoin and Ethereum wallet security

AI NewsCrypto Coin Show News Team·October 7, 2026·5 min read

OpenAI’s release of a broad collection of new mathematical results has prompted Ethereum researcher Justin Drake to warn that AI could break elliptic-curve cryptography, the foundation of Bitcoin and Ethereum wallet security, far sooner than quantum computing poses a threat, possibly within months in a worst-case scenario. For institutions holding large balances, the implication is immediate: moving assets to addresses with unexposed public keys may now be a prudent interim defense while blockchains work toward quantum-resistant cryptography.

  • OpenAI’s internal model generated 722 mathematical manuscripts using an average of three hours of ChatGPT Pro reasoning per result across roughly 4,000 problems tested.
  • Justin Drake urged large custodians including Binance, Bitfinex, Robinhood and Tether to migrate holdings to fresh addresses that have never signed transactions to hide public keys.
  • Ethereum’s post-quantum security roadmap is currently targeted for around 2029, but Drake argues AI-driven mathematical breakthroughs now demand accelerated defensive timelines.
  • 722 mathematical manuscripts released by OpenAI in a single collection, compared to previous isolated publications.
  • 2029 Ethereum’s current target date for core post-quantum infrastructure, subject to revision based on threat acceleration.
  • 3 hours average ChatGPT Pro reasoning compute used per mathematical result in OpenAI’s internal model evaluation.

According to first reporting on the subject, OpenAI released a catalog of 722 mathematical manuscripts on October 6 produced by an internal frontier model. The company spent approximately three hours of ChatGPT Pro thinking compute on the average result and tested the model across thousands of problems. The release includes computer-verifiable Lean formalizations of many proofs but does not claim a practical attack on Bitcoin’s or Ethereum’s cryptography. On October 7, Ethereum researcher Justin Drake responded by urging the blockchain industry to enter “bunker mode,” warning that accelerating AI-driven mathematical discovery could collapse the security assumptions underlying both networks.

Drake warns AI could break ECDSA within months, not the years quantum computing requires

Bitcoin and Ethereum rely on the Elliptic Curve Digital Signature Algorithm (ECDSA) on the secp256k1 curve to authorize transactions and prove ownership of funds. Once an account sends a transaction, its public key becomes visible on the blockchain. If an attacker could efficiently derive the private key from that public key, they could take control of all assets in that account.

Drake argued that OpenAI’s mathematical breakthroughs should force the industry to reconsider how long ECDSA will remain secure against classical algorithms, not merely quantum computers. He said an effective break of ECDSA could arrive “in months, not years” in a worst-case scenario. That timeline differs sharply from the industry’s traditional post-quantum roadmap: Ethereum’s documentation indicates core post-quantum infrastructure is targeted for roughly 2029. Drake cited the historical precedent of quantum algorithms occasionally inspiring faster classical approaches and said researchers should remain open to discovering a classical counterpart to Shor’s algorithm, which would threaten both elliptic-curve cryptography and RSA.

OpenAI’s announcement does not report a practical attack on ECDSA or RSA, and Drake’s months timeline is an unverified conjecture, not a demonstrated capability.

Moving to fresh addresses with hidden public keys offers interim protection without blockchain upgrades

Drake proposed a practical response that does not require waiting for new blockchain infrastructure or consensus upgrades. He urged large custodians including Binance, Bitfinex, Robinhood, Bitbank and Tether to migrate holdings into addresses that have never signed a transaction. Once a new address is used to send funds, he recommended transferring any remaining balance into another fresh address. The protection works because standard Ethereum externally owned accounts only expose an address hash on-chain until they send a transaction; the public key itself remains hidden behind that hash until the first outgoing transaction is signed.

The distinction matters for different address types. Bitcoin Taproot outputs expose a public key from the outset, and Taproot uses Schnorr signatures rather than ECDSA, although both rely on the secp256k1 curve.

For critical blockchain infrastructure such as oracles and layer-2 security councils, Drake recommended more aggressive precautions: rotating ECDSA keys after signing messages or combining existing signatures with hash-based systems such as SPHINCS. He cautioned against rushed transfers, warning that hurried moves could create more risk than they eliminate, but argued that Ethereum’s existing post-quantum timelines should now be revisited as AI changes the underlying assumptions.

Ethereum’s post-quantum roadmap includes hash-based signatures, but Drake’s concerns demand faster action

Ethereum has already established a dedicated post-quantum security effort, with work underway on hash-based signatures, account abstraction and replacements for cryptographic systems vulnerable to quantum computers.

Drake said his preferred long-term approach would rely heavily on hash-based cryptography, which has less algebraic structure for future AI systems to exploit than elliptic curves, lattices or isogenies.

Ethereum’s roadmap includes hash-based validator signatures and mechanisms designed to let individual accounts adopt different signature schemes without requiring the entire network to migrate at once.

The timing question remains unsettled. Ethereum’s second annual post-quantum research retreat is scheduled for October 9 to October 12, and Drake said he plans to address institutional participants in London next month as he pushes for faster defensive preparations. Europol separately added urgency to the broader issue, warning that quantum computing could eventually undermine cryptography protecting cryptocurrency wallets and urging the industry to begin preparing before the threat becomes practical. The agency argued that uncertainty over timing should not delay migration because upgrading systems and coordinating defenses could itself take years.

The core question remains unresolved: whether a classical algorithm capable of breaking ECDSA actually exists or could be discovered soon enough to pose a threat before quantum computers do.

The CCS read. Drake’s proposal does not require Ethereum or Bitcoin to change their protocols, only that custodians and holders change their behavior. For institutional holders, the move to fresh addresses is low-friction and costs only transaction fees, creating a hedge against both AI-discovered classical breaks and quantum threats. The pressure now falls on major exchanges and self-custody platforms to lead the transition and make address rotation a standard practice rather than an edge case.

Ethereum’s October 9 to October 12 post-quantum research retreat and Drake’s stated plan to address London-based institutional participants next month will serve as concrete markers for whether the industry accelerates its defensive timeline or maintains the existing 2029 target for core post-quantum infrastructure migration.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe