He named ML-DSA and fully homomorphic encryption as the new risk, and said Ethereum's lean roadmap has spent a year moving to hash-based schemes for that reason. His advice to holders was caution about migrating rather than haste: botched migrations have cost him more than every hack combined.
Vitalik Buterin told holders on Wednesday not to scramble to move funds to new wallets, then named the part of the stack he thinks is newly exposed: lattice-based cryptography, including ML-DSA and fully homomorphic encryption. Ethereum's co-founder posted about nine hours after Ethereum researcher Justin Drake called on the industry to plan for "bunker mode" and move large balances to addresses whose public keys are still hidden behind a hash. Buterin kept that advice and added a concern of his own.
"I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography," he wrote in a post published at 23:28 UTC on October 7. "The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices."
The two warnings point at different ends of the same migration. Drake's concern is ECDSA, the signature scheme Bitcoin and Ethereum use now. Buterin's is the family of schemes meant to replace it. ML-DSA is the module-lattice signature scheme NIST published as FIPS 204 in August 2024, and ML-KEM, the agency's lattice-based key-establishment standard, was published the same day. "So far most people have been in the mode of thinking 'elliptic curves broken, hashes safe, lattices safe'," Buterin wrote. "But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math."
His argument is an analogy rather than an attack. He wrote that "factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes)." "What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be?" He is not claiming a lattice break exists. He is claiming that two years of machine-assisted work could do to lattices what the number field sieve did to factoring, leaving them intact but needing far larger parameters for the same security.
Buterin presented Ethereum's existing direction as a response to the same reasoning. "This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the 'hash-only' direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc.," he wrote, adding that signatures in lean Ethereum are hash-based, either WOTS or SPHINCS+. That is his characterization of work already underway rather than an announcement. Ethereum set its post-quantum deadline in September, and Drake asked on Wednesday for those timelines to be revisited and accelerated. Hash-based signing also remains awkward in practice: the first quantum-safe bitcoin spend in August had to be mined directly because relay rules treated it as nonstandard.
The asymmetry Buterin draws is between signing and encrypting. "For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption." There is no hash-only escape there, he wrote, because "long-standing mathematical theorems" show public-key encryption cannot be built from hashes alone: it needs a trapdoor with some usable structure, whether group theory, lattices or codes, "but for anything that has structure, you should assume that AI will make at least some progress in breaking that structure." His suggested hedge for anything long-lived: "multiply the key sizes by 10." At those sizes, he argued, hash-based constructions win on efficiency wherever they are possible at all, and the problem reaches website access, secure messaging and Tor or VPN traffic, not just blockchains. For privacy protocols he recommended keeping encrypted notes off chain and sending them through a third-party mechanism instead.
Where Buterin agreed with Drake, he qualified the advice with his own losses. Keeping funds in addresses that have never signed a transaction is "a good idea" if it is not difficult, he wrote, before adding a warning: "But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined."
The multisig advice took two posts to settle. In the first, he argued that gathering confirmations off chain keeps signer public keys unexposed, so a wallet "gracefully degrades" to a one-of-one controlled by whoever collected the signatures rather than to "anyone can take the money." Just under four hours later, at 03:17 UTC on October 8, he corrected it: each signer should change their key after every operation. That assumes a weakened ECDSA rather than an instant one, he wrote, which is why in-mempool frontrunning is the thing to worry about, and off-chain collection still helps by shortening the gap between "sig revealed" and "key no longer active." His closing instruction was the same as his opening one. "It's very easy to lose funds from a misconfigured rushed upgrade, so ... don't rush anything."
Buterin stopped short of extending the warning to hashes themselves. He allowed that hashes could in theory be broken too, since P = NP would imply it, but said he thinks P = NP very unlikely. Neither post proposes padding hash output sizes yet; if the worry grows, he wrote, round counts would be increased before byte sizes. Neither post is a protocol decision, and neither announces a change to Ethereum's published post-quantum timeline.