Tech News, Blockchain, Cryptocurrency and the Internet

Can AI Break Crypto Wallets? Justin Drake and Vitalik Buterin’s Warnings Explained

AI Break Crypto Wallets

Your crypto wallet does not stay secure because nobody knows it exists. Its security depends on mathematics that lets you prove ownership without revealing the secret needed to spend your funds.

Now researchers are asking an uncomfortable question: what happens if AI discovers a shortcut through that mathematics?

Ethereum researcher Justin Drake raised that concern in an X post on 7 October, also shared through Firefly. Vitalik Buterin responded with a wider warning about digital security and the dangers of rushed migrations.

Neither post demonstrates a practical break of wallet cryptography. They discuss a possible future threat, not an announcement that someone can already drain everyone’s wallets.

What Justin Drake is worried about

Drake called for calm preparation, beginning with large, sophisticated holders. His proposed temporary precaution is to store assets at suitable fresh addresses whose public keys have not been exposed.

His concern is that AI-assisted mathematics might enable private-key recovery on conventional computing hardware before powerful quantum computers arrive. His worst-case timing of months rather than years is a personal risk assessment, not a verified countdown.

He also warns that rushing a migration could cause more harm than it prevents. His post is available here.

First, understand the three things people call a “wallet”

These terms are related, but they are different:

Term What it does
Private key The secret used to authorize actions such as spending funds.
Public key Lets others check that a signature is valid. It is mathematically related to the private key.
Address The identifier used to receive assets. How it relates to the public key depends on the blockchain and address type.

A seed phrase can generate multiple private keys and addresses. A wallet app manages those keys and creates signatures; the assets themselves are recorded on the blockchain.

Think of a private key as a secret signing stamp. The public key is the information others use to recognize a genuine stamp impression. Seeing an impression should not let someone manufacture your stamp.

That is an analogy, but it captures the purpose of digital signatures. Ethereum’s account documentation explains the underlying relationship.

What does ECDSA actually do?

ECDSA stands for Elliptic Curve Digital Signature Algorithm. Standard Ethereum accounts use it to authorize transactions.

When you send funds, your wallet creates a signature. The network checks that signature rather than asking for your private key. With the intended security assumptions intact, this lets strangers verify your instruction without learning how to impersonate you.

Many Bitcoin transactions also use ECDSA, although Bitcoin Taproot uses another signature scheme called Schnorr. Both rely on elliptic-curve mathematics.

A successful attack on the underlying mathematics could therefore be much broader than a bug in one wallet app. The hypothetical danger is an attacker creating valid authorizations—not merely viewing your balance. See the Bitcoin transaction guide and Taproot specification.

Why AI could matter even without a quantum computer

Imagine a lock with an enormous number of possible combinations. Trying every combination is impractical.

But discovering a flaw in the lock’s design could make the number of combinations irrelevant.

The concern here is similar: AI might help researchers discover a better mathematical attack, rather than simply try existing attacks faster.

Quantum computing is a separate route. A sufficiently capable quantum computer could use algorithms that attack the mathematics behind widely used public-key systems. AI-assisted research could, in principle, discover improvements that run on ordinary computers.

Progress in mathematical research does not automatically produce a practical cryptographic attack. The shortcut would have to apply to the relevant problem and work at real-world sizes and costs.

What triggered the discussion?

On 6 October, OpenAI published a collection of mathematical research results produced by an internal frontier model. The release included computer-checkable Lean formalizations for many proofs and information about how the results were obtained.

Drake interpreted the release as a reason to reconsider security timelines.

That interpretation needs to be separated from the release itself. The announcement is evidence of AI-assisted mathematical research; it is not, by itself, evidence that ECDSA has been defeated.

Why would a fresh address help?

For a standard Ethereum account, the address is derived from a hash of the public key. Simply receiving ETH does not reveal the full public key onchain.

Sending a signed transaction makes that public key recoverable from public transaction data. A publicly available recoverable message signature can expose it too.

That distinction matters for a hypothetical attack that needs the public key as its input. Hiding that input behind a hash could provide another barrier.

However, public keys are normally safe to expose. Exposure becomes dangerous if the mathematical assumptions protecting the private key fail. A used address is not automatically a compromised address.

Ethereum explains this distinction in its post-quantum security guide.

“Fresh address” does not mean “unhackable wallet”

The proposed protection has important limits.

Address types differ. Bitcoin Taproot outputs contain an elliptic-curve public key from the start. A newly generated Taproot address does not provide the same hidden-public-key protection as a suitable public-key-hash construction.

Spending can expose the key. Even where the key was initially hidden, making a transaction can reveal it. If a future attacker could recover a private key quickly enough, the period before confirmation could become dangerous.

A leaked seed defeats the precaution. Creating another address from a compromised seed does not restore security.

A fresh address can reduce a particular exposure under particular assumptions. It does not replace stronger cryptography or solve phishing, malware and unsafe approvals. The limitations of hash-hidden keys are discussed in Bitcoin’s Taproot design rationale.

What Vitalik adds to the discussion

Vitalik agrees that AI-assisted mathematics deserves attention, but opposes scrambling to move funds. He says his own losses from botched migrations have exceeded his losses from hacks.

He also questions whether lattice-based systems should automatically be treated as safe from future mathematical advances. He favors hash-based constructions where they can perform the required job.

His post presents these as personal views, not proof that lattice cryptography is broken.

Lattices and hashes, without the jargon

A lattice is a mathematical arrangement of points extending across many dimensions. Cryptographic systems use problems involving these arrangements that are believed to be difficult to solve.

A hash function turns input into a fixed-size digital fingerprint. Secure hashes are designed to make tasks such as reconstructing an input from its fingerprint impractical.

These lead to different families of security tools:

Approach Example Purpose
Lattice-based signatures ML-DSA Verify digital signatures.
Hash-based signatures SLH-DSA, derived from SPHINCS+ Verify signatures using hash-based constructions.
Lattice-based key establishment ML-KEM Help two parties establish a shared secret for encrypted communication.

NIST standardized these approaches in 2024 after a multi-year evaluation. Its standards announcement describes SLH-DSA as an alternative in case ML-DSA proves vulnerable.

“Post-quantum” means designed to withstand known quantum attacks. It does not mean immune to every future discovery.

Why this goes beyond Bitcoin and Ethereum

Signing a transaction and keeping a conversation private are different jobs.

A signature proves who authorized something. Encryption hides information from people who should not read it. A hash-based signature system does not automatically supply a complete replacement for public-key encryption.

Vitalik therefore extends his warning to secure messaging and other internet infrastructure. He also raises the danger of permanently publishing encrypted information: someone could save it now and attempt to decrypt it later.

He suggests more conservative lattice parameters, including a speculative tenfold size increase for some long-term uses. That is a research judgment—not a wallet setting users should change.

His multisig suggestion also needs care: offchain collection does not guarantee secrecy if signatures are later published during execution. The wallet’s actual design matters.

Would a hardware wallet solve this?

A hardware wallet helps keep your secret keys away from an internet-connected computer. That addresses risks such as key theft from a compromised device.

It does not change the mathematics used by the blockchain to check signatures.

If an attacker could derive a private key from public information, keeping your original copy offline would not prevent that attack. Device security and cryptographic security protect against different threats.

This follows from how Ethereum account keys work; the device is not the source of the mathematical security assumption.

What should an everyday user do?

Neither post provides evidence that ordinary users need an emergency migration today. A sensible response is to understand the issue and avoid creating immediate risks while reacting to a hypothetical one.

  • Keep seed phrases private and backed up securely.
  • Treat unsolicited “AI-proof wallet upgrade” links as suspicious.
  • If you independently choose to transfer assets, verify the destination and network, check recovery access, and test with a small amount.
  • Do not assume all address types offer the same protection.
  • Follow official wallet and network guidance as supported migration tools develop.

Institutions and protocol teams have a larger task: audit exposed keys, understand their signing systems, and prepare carefully tested cryptographic upgrades.

What this debate means

Crypto security depends on both mathematics and how people use the systems built around it.

AI could accelerate research that changes our confidence in some mathematical assumptions. That possibility deserves serious investigation. It does not establish that today’s wallets have been broken.

For readers, the useful response is informed preparation. For developers and custodians, it is planning a transition that protects assets without exposing users to unnecessary migration mistakes.

Share this article
Shareable URL
Prev Post

The Story of Solana (SOL): Origin, Journey, and Milestones

Leave a Reply

Your email address will not be published. Required fields are marked *

Read next