Ethereum co-founder Vitalik Buterin has warned that fast advances in artificial intelligence could weaken the security of some cryptographic systems within the next two years. Responding to Ethereum Foundation researcher Justin Drake’s call for the industry to enter a defensive “bunker mode,” Buterin said the risk extends beyond traditional quantum threats.
He pointed to potential vulnerabilities in lattice-based cryptography, including ML-DSA and fully homomorphic encryption (FHE), as AI accelerates research in complex areas of mathematics such as number theory and algebra. Ethereum is also exploring simpler, hash-based signature systems such as WOTS and SPHINCS+ that rely less on complex mathematical assumptions.
I don’t recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices.
(and it’s also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the “fresh address” recommendation)
So far most people have been in the mode of thinking “elliptic curves broken, hashes safe, lattices safe”. But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be?
This is a major part of the reason why for the past year ethereum’s lean roadmap has been going in the “hash-only” direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption.
And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable “structure” – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that’s a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a “naive factoring -> GNFS” level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety.
And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it’s possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it’s much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems.
For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
* Hash-based > lattice-based, in those situations where hash-based is possible at all
* For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs …
* For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
* If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**.
* For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig “gracefully degrades” to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than “anyone can take the money”
https://t.co/oVjwZog2lL— vitalik.eth (@VitalikButerin) October 7, 2026
However, Buterin’s most immediate warning was directed at crypto users themselves “do not panic”. He cautioned against rushing to migrate wallets in response to the emerging AI threat, arguing that poorly executed security changes could cause more damage than the threat they are intended to prevent. “I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin said. He recommended using fresh, unused addresses where public keys have not previously been exposed, while also suggesting larger key sizes for certain public-key encryption systems and offline or off-chain confirmations for multisig wallets.
Crypto community questions the scale of the risk
One X user @walicoin highlighted the “extra algebraic structure in Ring/Module LWE” as the real exposure, pointing to previous weaknesses such as cyclotomic ideal SVP and the 2022 classical attack on SIKE. The user said hashes avoid this structure, although that remains “heuristic not proven,” while agreeing with the hedging approach but calling the proposed 10x increase “a guess.”
ignore this and you can lose everything.
vitalik’s post is hard to follow if you’re not technical. here’s a simplified version so you can understand it.
1. the last lock on your coins is a math problem nobody has solved. not uncrackable. uncracked. rsa (the early internet’s lock) had to grow to ~400-byte signatures because mathematicians kept finding shortcuts. your wallet gets away with 64 because nobody has found one. yet.
2. his scenario: ai brings “50 years of math in 2 years” and bots find the shortcuts we missed. nothing is broken today.
3. the scary new: your wallet’s math has gears a locksmith can study. so do lattices, the “quantum-safe” lock the world is switching to. he sees “a good chance” they “take serious hits from the next two years of ai math.” quantum-safe might not be ai-safe.
hashes are a blender, built to have no gears. a big reason ethereum’s long-term plan is going hash-only.4. the trick: your address is a sealed box with your lock inside. receiving doesn’t open it. signing anything does. you can’t pick a lock you’ve never seen.
already open: any eth wallet that ever sent or signed, and 6-8m btc (30-40% of supply, depending on who counts).
open from day one: solana and btc taproot (bc1p).5. his first line is don’t scramble today. he’s lost more money in botched migrations than in all hacks combined.
only if it’s easy:
> park savings on an address that never signed anything (permits, nft listings, “sign in” pop-ups all count)
> btc: a fresh bc1q, not bc1p
> tiny test send first. check every character. no rush
> “quantum migration tool” in your dms = a drainer (a scam that empties your wallet). never type your seed into a website— The Smart Ape 🔥 (@the_smart_ape) October 8, 2026
Another X user @the_smart_ape described crypto security as a math problem that remains “uncracked,” rather than “uncrackable.” He noted that AI could potentially bring “50 years of math in 2 years,” meaning “quantum-safe might not be AI-safe,” while stressing that users should “don’t scramble today” and instead focus on careful security hygiene.
An X user @stacymuur put the threat into better perspective, arguing that if quantum technology eventually breaks modern cryptography, the consequences would extend beyond crypto to “your bank account, your brokerage account, your Google, X, and Apple account.” Muur said crypto would be “the least of the problems” because such an event would effectively become “the endgame for the entire internet.”
READ ALSO: The People Building AI Are Warning Us About AI
Can crypto actually migrate billions of dollars to safer cryptography?
A blockchain migration would mainly involve changing the cryptographic method used to authorize transactions, rather than manually transferring every token to a new wallet. On Ethereum, for example, developers could upgrade accounts so they use a new, safer signature scheme to approve transactions. This could protect the ETH, tokens and DeFi positions already controlled by those accounts without requiring each asset to be moved separately.
Ethereum’s current post-quantum plan is designed around signature agility, allowing individual accounts to adopt new authentication without waiting for a network-wide “flag day.” Ethereum is also exploring EIP-8141 to make this possible, while its post-quantum roadmap targets core infrastructure by about 2029.
However, Ethereum’s security transition covers not only account signatures but also Boneh–Lynn–Shacham (BLS) validator signatures, Kate–Zaverucha–Goldberg commitments and zero-knowledge systems. For example, replacing BLS is difficult because BLS signatures are only about 96 bytes, while the proposed hash-based leanXMSS signatures are roughly 3,000 bytes. Bitcoin presents a more difficult governance question because a protocol-level migration could affect coins whose owners are inactive or lost.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.



















































































