Ethereum researcher Justin Drake urged crypto holders to prepare for “bunker mode” after OpenAI published mathematical results produced by an internal frontier model. Drake’s worst-case warning is that an effective break of the Elliptic Curve Digital Signature Algorithm (ECDSA) could arrive “in months, not years.” OpenAI has not reported a practical attack on ECDSA or RSA, and Drake’s timeline is conjecture, not a demonstrated capability.
Why it matters
Bitcoin and Ethereum rely on elliptic-curve cryptography to authorize transactions. On standard Ethereum accounts, sending a transaction exposes information that can be used to reconstruct the public key. An address that has not sent funds keeps its public key hidden behind a hash, providing an additional layer of protection. Bitcoin Taproot outputs, by contrast, expose a public key from the outset, although Taproot uses Schnorr signatures rather than ECDSA. Both rely on the secp256k1 curve.
Drake’s concern is that AI-driven mathematical discovery could produce a classical algorithm that weakens these systems, rather than requiring a future fault-tolerant quantum computer. Whether such an algorithm exists is unknown. Ethereum’s post-quantum infrastructure is targeted for roughly 2029, but its roadmap may change.
Market impact
Drake recommends that large holders move assets to fresh addresses whose public keys have never been exposed, and that any remaining funds be moved again after an address sends a transaction. He named Binance, Bitbank, Robinhood, Bitfinex and Tether as firms that could strengthen cold-storage practices. He also pointed to key rotation for oracles and layer-2 security councils, and hash-based signatures such as SPHINCS, as interim defenses.
Ethereum is working on a post-quantum roadmap that includes hash-based validator signatures and ways for individual accounts to adopt different signature schemes. Drake cautioned that rushed transfers could introduce new risks. Ethereum’s post-quantum research retreat is scheduled for Oct. 9 to Oct. 12, as the industry weighs whether its security timelines need to change.
Frequently asked questions
-
What did Justin Drake mean by “bunker mode” for crypto holders?
He urged holders to move funds to fresh addresses whose public keys have never been exposed. After an address sends funds, he recommends moving any remaining balance to another fresh address.
-
Has OpenAI demonstrated an attack that breaks ECDSA or RSA?
No. OpenAI’s announcement did not report a practical attack on ECDSA or RSA. Drake described a break within months as a worst-case conjecture, not a demonstrated capability.
-
Why can an unused Ethereum address offer an additional layer of protection?
A standard Ethereum address shows a hash of its public key. Once the account sends a transaction, information onchain can be used to reconstruct the public key.
-
How does Bitcoin Taproot differ from an unused standard Ethereum account?
Bitcoin Taproot outputs expose a public key from the outset. Taproot uses Schnorr signatures rather than ECDSA, but both rely on the secp256k1 curve.
-
What post-quantum measures is Ethereum considering?
Ethereum’s roadmap includes hash-based validator signatures and mechanisms that could let individual accounts adopt different signature schemes. Core post-quantum infrastructure is targeted for roughly 2029, subject to change.
CryptoSlate