AI math could hit post-quantum crypto within two years, Buterin says

- Vitalik Buterin warned that AI math could seriously weaken lattice-based cryptography within two years.
- He named ML-DSA and fully homomorphic encryption as the core new area of risk.
- Buterin still told holders not to scramble funds into new wallets, citing losses from botched migrations.
Ethereum co-founder Vitalik Buterin warned Wednesday that AI math could encroach on lattice cryptography, the leading post-quantum replacement, within two years.
He still cautioned holders against rushing funds into new wallets.
Lattice keys may need to grow 10 times for long-term safety
Buterin wrote on X that most planning assumes elliptic curves break, but hashes and lattices endure. “But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math,” he wrote.
He named ML-DSA, fully homomorphic encryption and lattices as the key new risk areas. Same pressure could see ECDSA, the signature scheme behind Bitcoin and Ethereum wallets, fall sooner than expected.
After decades of human labor, breaking RSA keys is now cheaper, and Buterin asks if bots will soon find similar shortcuts against curves and lattices.
If AI delivers 50 years of math in 2 years, lattices will necessitate much larger keys for the same safety, he wrote. His rule of thumb for long-term security is to multiply key sizes by a factor of 10.
Ethereum’s lean roadmap has been hash-only for the last year, with signatures on WOTS or SPHINCS- and no ML-DSA or Falcon.
A secp256k1 ECDSA signature is about 64 bytes in size, whereas NIST’s finalized ML-DSA-87 signature is around 4,627 bytes, according to Cryptopolitan.
Justin Drake’s bunker mode call followed OpenAI’s 722 manuscripts
Buterin was replying to Ethereum Foundation researcher Justin Drake. On Wednesday, Drake called on the industry to “calmly begin planning for ‘bunker mode,’” according to Cryptopolitan.
Drake said ECDSA could break before q-day, the day quantum computers crack public-key cryptography. Worst case, it’ll be months, not years.
His plan is to move funds to addresses that have never signed a transaction, beginning with the largest holders. Such addresses conceal the public key behind a hash until the first signature.
Buterin backed fresh addresses only where the switch is easy. “I don’t recommend anyone scramble to move their funds to new wallets today,” he wrote, adding that he’s lost more money in failed migrations than in all hacks combined.
Privacy protocols should keep encrypted notes off the chain and send them via a third party, he said. For multisig wallets, off-chain confirmations help keep signer signatures out of public view.
Drake tied his warning to OpenAI’s release Tuesday of 722 manuscripts from an unreleased internal model, grouped into 372 families. Most proofs are in Lean, so a computer can verify them.
In July, Anthropic said its Claude Mythos Preview model cut the key strength of HAWK, a post-quantum signature candidate submitted to NIST, by 50% in 60 hours. Anthropic said the outcome doesn’t bear on live systems because HAWK was never deployed.
Cryptopolitan reports that, as of May 2026, Europol cited an on-chain count of 6.04 million BTC, about 30.2% of the supply, with visible public keys.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
What did Vitalik Buterin actually recommend?
Avoid scrambling funds into new wallets, and move to fresh addresses only where the switch is easy.
Why do Buterin and Drake think AI is the trigger, not a quantum computer?
AI math could uncover shortcuts against elliptic curves and lattices that humans have not found, Buterin wrote.
How much Bitcoin is exposed to this risk?
About 6.04 million BTC, or 30.2% of supply, had visible public keys as of May 2026, per an on-chain count Europol cited.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















