Justin Drake, a researcher at the Ethereum Foundation, wrote on X on October 7, 2026 that artificial intelligence may break the signatures of Bitcoin and Ethereum sooner than a quantum comput
Justin Drake, a researcher at the Ethereum Foundation, wrote on X on October 7, 2026 that artificial intelligence may break the signatures of Bitcoin and Ethereum sooner than a quantum computer will. He called on the industry to plan a “bunker mode” for large holdings: an orderly move to addresses that have never signed a transfer.
The short answer to the question hanging on this: your coins are not under acute threat today. There is no demonstrated attack on the signature scheme, Drake is describing a worst case, and clear objections came out of the cryptography world within hours. The point matters all the same, because it touches a property of blockchains that most holders have never noticed: an address only reveals its public key once something leaves it for the first time. Knowing that, you can lower your risk without haste and without new technology.
“Bunker Mode”: What Justin Drake Wrote on October 7
Drake names a concrete yardstick in his post for what he counts as a break. For him the scheme is broken once a private key can be computed back in about a week on available hardware, for instance on a large cluster of graphics processors. That is a different threshold from the theoretical vulnerability cryptographers have been discussing for years, and it sits considerably lower.
He put the time frame in the formula that in the worst case this is a matter of months, not years. In the original he wrote of a break “in the worst case in months not years”. As the trigger he cited a series of 722 mathematical results that OpenAI had published the Tuesday before. His reasoning for why elliptic curves of all things should be susceptible, he put like this: “Elliptic curves feel especially vulnerable to superintelligence.” Decrypt has documented the wording of the post. Curves carry a rich mathematical structure, and structure is what clever attacks can work their way along. Hash functions are built precisely to offer as little of it as possible.
For Ethereum, Drake announced that he would push for “maximum defensive acceleration” in the switch to hash-based cryptography. He addressed a separate appeal to the custodians: Binance, Bitbank, Robinhood, Bitfinex and Tether should harden their cold storage. That is notable, because together these houses hold a substantial share of traded balances and have been signing from their addresses for years.
ECDSA: the Signature With Which Bitcoin and Ether Authorise Every Transfer
ECDSA stands for Elliptic Curve Digital Signature Algorithm. It is the scheme with which both Bitcoin and Ethereum check whether a transfer comes from the entitled party. Two numbers belong to every account: a private key that only you know, and a public key that can be computed from it. The computation works in one direction only. The public key follows from the private one in fractions of a second, while the reverse path is considered practically impossible as things stand.
That one-way street is the foundation. Were it to fall, anyone knowing an address's public key could derive the private one from it and move the coins. Neither a hardware wallet nor a passphrase nor an exchange with two-factor protection would change anything about that, because the attack would not take place at your device but at the mathematics behind it.
One restriction makes the difference between panic and planning. Your Bitcoin address is not the public key but a hash of it. A hash cannot be computed backwards, not even by a machine that cracks elliptic curves. As long as an address has only ever received, nothing but that hash stands in the blockchain. The public key becomes visible only when you send something away from it for the first time, because the signature carries it along.

Drake's yardstick for a break: one private key in roughly a week on a large compute cluster.
Why an Address Becomes Attackable Only Through Its First Transfer
From this mechanism follows a division you can trace on your own holdings. Addresses that have never sent anything count as protected, because their public key sits behind the hash. Addresses that have already sent once count as exposed. There is nothing in between, and the line does not run along the question of how secure your wallet is, but along the question of whether it has already signed.
For Ethereum the picture is worse. There the account itself is derived from the public key, and every interaction with a smart contract involves signing. Anyone who has held Ether for years and swapped, staked or granted an approval even once is sitting on an exposed address. With Bitcoin the position is mixed: anyone who sent their coins to a fresh address once and has only held since then is on the better side.
The practical snag: spending necessarily exposes the address. A wallet you use regularly cannot be kept in the protected state permanently. Drake's proposal therefore targets the holdings that are going to sit still anyway, not the money you trade with. How to separate custody and use cleanly is shown in our hardware wallet comparison, which also ranks the devices by how well they manage several separate accounts under one seed.
Satoshi's Shield: 20,000 Old Addresses Holding 50 BTC Each as the First Target
Drake makes an argument that has drawn little attention in the debate so far and that sounds reassuring for small holders. Around 20,000 exposed addresses are attributed to the inventor of Bitcoin, each holding 50 BTC, the reward of the earliest blocks. These addresses have been untouched for a decade and a half and are visible to everyone.
An attacker who really could break ECDSA would face a question of sequence. Computing time is finite, every key costs about a week on a large cluster by Drake's own estimate, and at the top end of the field sit those twenty thousand addresses with the highest value per attack. He calls this, in effect, a shield: anyone holding less than 50 BTC on one address is not the first target, because the effort pays off better elsewhere.
This shield is a time buffer and not security. It assumes that the attacker thinks economically, that they do not parallelise, and that nobody would rather damage a chain for political reasons than enrich themselves. As a planning figure it serves all the same: it tells you that you have days and weeks to act cleanly, not hours.
Buterin Applies the Brakes: Botched Moves Cost Him More Than All Hacks Combined
The most prominent reaction came from Vitalik Buterin, and it fell into two parts. On substance he agrees with Drake that AI-driven advances in mathematics deserve more attention than the industry has given them so far. On the pace he clearly disagrees. Nobody, he says, should start shoving balances onto new wallets in a hurry today.
He draws his reasoning from his own experience, and it is the strongest argument against acting too fast: by his own account, botched moves have cost him more than all the hacks he has lived through put together. A mistyped destination, a clipboard manipulated by malware, a seed that ends up in a photo while the new wallet is being set up: these mistakes happen in haste, and unlike a mathematical breakthrough they are real today.
There is also a risk that surfaces in every wave of migration. As soon as a headline moves holders to switch, guides, helper services and supposed checking tools appear that harvest precisely what they promise to protect. Signing an approval in such a phase without having read it loses your money to a drainer, not to a superintelligence.
Objection From Cryptography: Coinbase's Chief Cryptographer Sees No Evidence
Yehuda Lindell, who runs cryptography at Coinbase, was more pointed than Buterin. In his own words he sees “no evidence whatsoever” that the assumptions behind elliptic curve cryptography are close to falling. The mathematical advances that AI systems have achieved this year are no argument against ECDSA, he says, because they concern different classes of problem.
Samson Mow, head of the company Jan3, likewise told his readership to stay calm and thought little of the warning. The specialist coverage classified the episode consistently as a risk scenario: OpenAI has presented no practical attack on ECDSA, and Drake's months-long horizon is an upper bound of the conceivable, not a forecast.
What remains notable is that the lines do not sort along the usual camps. In March of this year, after a widely noted paper from Google, Drake himself put the probability of a quantum breakthrough by 2032 at ten percent or more. That he now considers AI the faster route is a sharpening within his own argument, not a reversal.

Moving to a fresh address requires no new hardware and no new cryptography.
Hash-Based Signatures: WOTS and SPHINCS as the Goal of the Ethereum Roadmap
The technical answer to the scenario has been on the table for years and is called a hash-based signature. Instead of relying on the structure of elliptic curves, it rests on hash functions alone, on exactly the components Drake considers comparatively robust. Buterin names WOTS and SPHINCS as candidates and argues for avoiding lattice-based schemes where alternatives exist.
A switch of this kind is not a software update rolled out overnight. It affects the signature format of every transfer, every wallet, every exchange and every service that builds transactions. With Bitcoin, a change of this magnitude would come about only through a consensus of developers, miners and the industry, and that is exactly where it sticks: proposals that would invalidate old signatures after a deadline meet the charge that they expropriate everyone who does not move in time. The other side counters that unmoved old balances otherwise become a quarry for the first successful attacker.
For you this means the protocol layer will not rescue you in the coming months. What lies in your hands is the choice of the address your holding sits on.
What a Move to a Fresh Address Means for Your Holding Period
At this point a cryptography debate turns into a German tax question, and it is the reason many holders hesitate. The worry runs: if I send my coins to a new address, does the one-year holding period start again, and do I thereby lose the tax exemption on a gain?
The answer is reassuring. A transfer between two wallets that both belong to you is not a sale. No beneficial owner changes, no price is realised, and neither gain nor loss arises. The holding period on your coins therefore runs on as though nothing had happened. The case is different only if you take the detour of a swap for the move, by selling and buying anew: that is a disposal with all the tax consequences.
What really matters with a transfer between your own wallets is the documentation. The tax office sees a transfer in the blockchain and cannot tell whether two of your own wallets or a sale to a stranger stands behind it. So record which address you moved how much from, to which address, and when, and keep the original purchase receipt with it, because that carries the acquisition date that counts. With larger holdings or nested transactions, your tax adviser decides in the end, not a rule of thumb from an article.
Custody at an Exchange, on a Hardware Wallet or in Multisig: Where Your Public Key Sits
Whether you can act at all depends on who holds your keys. If your coins sit at an exchange, you own no address of your own but a claim against the house. Whether its cold storage sits on exposed addresses cannot be told from outside, and it was precisely these houses that Drake's appeal addressed. What is left to you is the choice between trust and self-custody.
With your own wallet the decision is in your hands. Every common hardware wallet generates any number of addresses from a single seed, and one of them can stay untouched while you trade with another. You need no second device and no new seed for that, only a fresh account in the software you already use.
With multisig constructions a closer look pays off, because several public keys are in play there and the setup alone can expose them. Anyone running such a solution should look at which of the participating keys have already signed.
Old Bitcoin Addresses: as Long as No Signature Is Out There, Time Remains
The finding of this day is unspectacular and therefore usable: a break of ECDSA has not occurred, has not been demonstrated and, in the judgement of several cryptographers, is not foreseeable either. What has occurred is an occasion to take a look at which addresses your own money sits on. That work costs half an hour, is useful for every future risk, and can be done without any haste at all.
- Look at which of your addresses have already sent. Every blockchain explorer shows you the outgoing transactions for an address. If none is to be seen there, your public key sits behind a hash. If you have no address of your own at all because everything sits at an exchange, the first step is the decision about custody: which software solutions are suited to it is set out in our software wallet comparison.
- Set up a separate account for the part that stays put. Separate the holding you do not touch from the one you trade with, and move it in a single, calmly checked operation to an address that has never signed. Document the date, the amount and both addresses while you are at it; a portfolio tracker takes that off your hands, and which of them carry the holding period correctly is in our overview of tax tools and portfolio trackers.
- Let your exchange know you are watching. If a substantial part of your holding sits at a trading venue, the question about its custody practice is a fair one, and it will be asked more often. How the large houses stand on custody, regulation and transparency is shown in our overview of the best crypto exchanges.
What remains is the sentence that sticks from this week, and it comes not from Drake but from Buterin: the most expensive part of a move is almost never the attack it is meant to protect against.
(As of October 8, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)