Justin Drake urges ‘bunker mode’ after OpenAI math breakthroughs, flags ECDSA risk

security📉 Bearish

⏱ 3 min read

Drake contrasts a worst-case ‘months’ horizon with Ethereum’s post-quantum work targeting roughly 2029, and outlines who should move first.


On Oct. 7, Ethereum researcher Justin Drake urged the industry to enter “bunker mode” after OpenAI math breakthroughs the day before, advising a controlled migration of assets to never-used addresses and warning that, in a worst case, ECDSA could be broken “in months, not years.” His warning followed OpenAI’s Oct. 6 release of a broad collection of new mathematical results produced by an internal frontier model.

The company said it tested the model across thousands of problems, published many proofs with computer-checkable Lean formalizations and spent the equivalent of about three hours of ChatGPT Pro reasoning on the average result. The announcement does not report a practical attack on ECDSA or RSA. Drake’s timeline is a worst-case conjecture.

Why hidden public keys matter

Bitcoin and Ethereum rely on elliptic-curve cryptography to establish ownership and authorize transactions. Standard Ethereum externally owned accounts use ECDSA on the secp256k1 curve. Once an account sends a transaction, its public key can be reconstructed from onchain data. Anyone who could efficiently derive the corresponding private key could seize the assets. By contrast, Ethereum’s documentation notes that accounts whose public keys remain unexposed show only an address, which is a hash of the public key, adding a layer of protection.

Drake’s near-term stopgap builds on that asymmetry: move funds to addresses whose public keys have never been revealed and avoid unnecessary outgoing transactions. Address type matters. Bitcoin Taproot outputs expose a public key from the outset and use Schnorr signatures, though both Schnorr and ECDSA in these systems rely on the secp256k1 curve.

$BTC
▼ 2.74%
$83,199

$ETH
▼ 4.76%
$2,569

Prices as of 2026-10-07 23:03 UTC. Source: CoinGecko.

Interim steps and who should move first

Drake said large and sophisticated holders should move most assets to never-used addresses and, after any spend, sweep the remainder to a fresh address. He urged big custodians to lead these changes, naming Binance, Bitbank, Robinhood, Bitfinex and Tether. For critical infrastructure, such as oracles and layer-2 security councils, he suggested rotating ECDSA keys after signing messages or combining existing signatures with hash-based systems like SPHINCS. These measures are presented as interim defenses, not permanent fixes.

AI risk versus the quantum roadmap

The industry has long framed key recovery as a quantum-computing risk. Ethereum has a dedicated post-quantum program, with work on hash-based signatures, account abstraction and other replacements, and core infrastructure targeted for roughly 2029, subject to change. Drake challenges the premise that quantum will be first, arguing the pace of AI-driven mathematical discovery could uncover a classical algorithm that materially reduces the difficulty of recovering private keys. Whether such an algorithm exists remains unknown.

Europol separately warned that quantum computing could eventually undermine wallet cryptography and urged preparation before the threat becomes practical, noting that migration and coordination can take years. Drake cautioned against a rushed migration, saying hurried transfers can introduce new risks, but he also said Ethereum’s timelines should be revisited as AI shifts assumptions.

Ethereum’s second annual post-quantum research retreat is scheduled for Oct. 9 to Oct. 12, and Drake said he plans to address institutional participants in London next month on accelerating defensive preparations.


Source: CryptoSlate.
This article was written with AI assistance and reviewed by an editor.
This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

The tension between moving quickly to protect keys and avoiding risky rushed migrations highlights the need for clear signals to guide action. Advances in AI that reveal more efficient ways to recover private keys could shift the calculus, making faster key rotation urgent despite the risks. Until such breakthroughs occur, however, custodians face a delicate balance between operational safety and proactive defense. Monitoring progress in AI-driven cryptanalysis will be crucial for determining the right pace of migration and key management.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.