Vitalik Warns Ethereum About a Cryptographic Threat
Vitalik Buterin and Justin Drake warn of AI and quantum risks to Ethereum cryptography while urging caution against rushed wallet migrations.
Ethereum co-founder Vitalik Buterin and Ethereum Foundation researcher Justin Drake have raised fresh concerns about the long-term security of blockchain cryptography as advances in quantum computing and artificial intelligence (AI) challenge existing security assumptions. In separate posts on X on October 7–8, 2026, both researchers emphasized the importance of preparing for a future in which widely used cryptographic systems, particularly elliptic curve cryptography, could become vulnerable to increasingly powerful attacks.
However, neither researcher recommended an immediate migration of funds. Instead, they warned that rushing into new wallets or cryptographic systems without adequate preparation could introduce additional security risks.
Justin Drake Warns About Quantum Computing and AI-Accelerated Cryptographic Risks
Ethereum researcher Justin Drake warned that the blockchain industry should begin planning for potential cryptographic vulnerabilities rather than waiting for existing security mechanisms to fail. His concerns center on elliptic curve digital signature algorithms (ECDSA), which are currently used to authorize transactions from Ethereum's traditional externally owned accounts.
ECDSA relies on mathematical problems that are extremely difficult for conventional computers to solve. However, sufficiently capable quantum computers running algorithms such as Shor's algorithm could eventually recover private keys from exposed public keys.
Drake argued that even without a fully capable quantum computer today, the possibility of future attacks makes early migration planning important. The risks also extend beyond quantum computing.
He pointed to recent advances in AI-assisted mathematical reasoning, including OpenAI's reported progress on difficult mathematical problems, as another reason to reconsider long-standing security assumptions. While these developments do not establish that AI can currently break ECDSA, they raise questions about whether mathematical breakthroughs could arrive faster than previously anticipated.
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices.
(and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation)
So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2O(n(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be?
This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption.
And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety.
And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems.
For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
- Hash-based > lattice-based, in those situations where hash-based is possible at all
- For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ...
- For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
- If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.
- For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money"
https://t.co/oVjwZog2lL— vitalik.eth (@VitalikButerin) October 7, 2026
Drake referenced several cryptographic systems whose security could face greater scrutiny, including elliptic curves commonly used in blockchain infrastructure and some zero-knowledge proof constructions. The issue is particularly relevant for Ethereum because cryptography protects multiple layers of the network, from transaction authorization to validator participation and data commitments.
In June, EtherWorld covered research surrounding Google's Shor algorithm optimization, examining how improvements in quantum algorithms could influence expectations about the timeline for breaking elliptic curve cryptography.
Ethereum has also supported research into quantum-resistant alternatives. The Ethereum Foundation's backing of ZKnox reflects efforts to make post-quantum cryptography more practical for blockchain applications.
Vitalik Buterin Says Users Should Not Rush to Move Funds
Buterin acknowledged that both quantum computing and AI-driven advances in mathematics deserve serious attention. However, he argued that the industry should distinguish between cryptographic systems with different security characteristics.
In particular, he emphasized the difference between elliptic curve-based cryptography and hash-based constructions. Elliptic curve signatures face a potentially severe threat from sufficiently advanced quantum computers because Shor's algorithm can solve the underlying mathematical problems efficiently.
Hash-based cryptographic systems, by contrast, are generally considered more resistant to known quantum attacks when appropriate security parameters are used. Buterin explained that the broader cryptographic community has already developed mathematical foundations supporting hash-based approaches, including constructions based on Merkle trees and hash-based signatures.
In a follow-up clarification, Buterin specifically addressed multisignature wallets. He suggested that an ideal protective strategy would involve changing signing keys after each operation, assuming a future attacker could recover a key after it becomes exposed but could not do so instantaneously.
He also recommended gathering signatures offchain where practical, reducing the interval between revealing a signature and retiring the corresponding signing key. These recommendations reflect an important distinction: minimizing key exposure can reduce certain risks, but it does not eliminate the need for stronger cryptographic systems.
As explained in EtherWorld's overview of account abstraction, smart contract-based accounts can introduce alternative transaction validation rules instead of relying exclusively on traditional ECDSA signatures. More recently, initiatives such as Kohaku have explored advanced wallet infrastructure, demonstrating how Ethereum's wallet architecture continues to evolve beyond conventional accounts.
Ethereum's Post-Quantum Roadmap Takes on Greater Urgency
Rather than viewing quantum computing as a distant theoretical concern, protocol researchers have increasingly incorporated quantum resistance into discussions about Ethereum's long-term architecture. Several existing components could eventually require cryptographic changes.
Correction: for multisigs the ideal "safe" rule is that you want each signer to change their key after each operation.
(This is making an implicit assumption that ECDSA might become weak, but not to the point where any crack of it would be literally instant, so you literally have to worry about eg. in-mempool frontrunning)
You definitely still want to gather sigs offchain if possible, to minimize the number of hours between "sig revealed" and "key no longer active"
But again: it's very easy to lose funds from a misconfigured rushed upgrade, so ... don't rush anything.
— vitalik.eth (@VitalikButerin) October 8, 2026
Ethereum's externally owned accounts use ECDSA signatures, while the consensus layer relies on BLS signatures for validator operations. The network also uses KZG commitments for blob data availability.
These systems rely on mathematical assumptions that could become vulnerable to sufficiently powerful quantum computers. Replacing them would require coordinated work across Ethereum clients, validators, wallets, applications, and supporting infrastructure.
Ethereum's Lean Ethereum vision already explores major architectural changes involving quantum-resistant cryptography, recursive STARK proofs, and more efficient verification systems. STARKs are particularly relevant because their security can rely on hash-based assumptions rather than the elliptic curve pairings used by some other proof systems.
However, STARK-based systems are not automatically immune to every future cryptographic threat. Their security still depends on the underlying hash functions, implementation choices, and proof parameters.
Another major challenge is ensuring that cryptographic upgrades do not significantly increase costs for users or validators. Post-quantum signatures can be substantially larger than conventional elliptic curve signatures, potentially increasing transaction sizes, storage demands, and verification overhead.
EtherWorld's coverage of Ethereum's next decade highlighted the growing importance of zero-knowledge technology in making Ethereum easier to verify while maintaining decentralization. The broader research ecosystem is also investigating new cryptographic primitives.
For example, Buterin's discussion of indistinguishability obfuscation explored how advanced cryptographic research could eventually transform privacy, verification, and trustless computing. Meanwhile, Ethereum's upgrade planning continues to evaluate how security-related proposals fit alongside other protocol priorities.
What This Means for Ethereum Users and the Blockchain Industry
For everyday Ethereum users, the immediate message from Buterin and Drake is relatively straightforward: quantum computing and AI-related cryptographic risks deserve attention, but there is no reason to panic based on these posts alone. Neither researcher presented evidence that existing Ethereum wallets had suddenly become vulnerable to practical quantum attacks.
Instead, their discussion focused on preparing for possible future capabilities and avoiding security mistakes during the transition. The challenge is significant because Ethereum cannot simply replace its cryptographic infrastructure overnight.
Millions of accounts, smart contracts, validators, and applications depend on the network's existing authentication and verification mechanisms. Any transition toward quantum-resistant cryptography would need to consider backward compatibility, user experience, security audits, and the risks associated with exposing existing public keys.
For Ethereum developers, the discussion reinforces the importance of designing systems that can evolve as cryptographic assumptions change. These concerns align with the Ethereum Foundation's broader emphasis on long-term resilience and self-sovereignty.
Ethereum's long-term security will depend not only on developing stronger cryptography but also on ensuring that new systems can be introduced safely across a decentralized network. As Ethereum moves toward more advanced verification systems and post-quantum research, the challenge will be turning those cryptographic ideas into reliable infrastructure without putting existing users and assets at unnecessary risk.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Researchers Crack Google’s Hidden Shor Optimization
- Ethereum’s Roadmap Just Changed. Here’s What’s Next
- Vitalik Buterin Outlines Ethereum's Lean Vision
- Vitalik’s Bitcoin-Inspired Plan for Ethereum
- Vitalik Buterin Explains Cryptography’s “Final Boss”
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.