Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

Buterin Says AI Math Could Weaken Lattice Cryptography in Two Years

He named ML-DSA and fully homomorphic encryption as the new risk, and said Ethereum's lean roadmap has spent a year moving to hash-based schemes for that reason. His advice to holders was caution about migrating rather than haste: botched migrations have cost him more than every hack combined.

By MiningPool Staff··4 min read
Buterin Says AI Math Could Weaken Lattice Cryptography in Two Years

Key Points

  • He named ML-DSA and fully homomorphic encryption as the new risk, and said Ethereum's lean roadmap has spent a year moving to hash-based schemes for that reason.
  • His advice to holders was caution about migrating rather than haste: botched migrations have cost him more than every hack combined.

Vitalik Buterin told holders on Wednesday not to scramble to move funds to new wallets, then named the part of the stack he thinks is newly exposed: lattice-based cryptography, including ML-DSA and fully homomorphic encryption. Ethereum's co-founder posted about nine hours after Ethereum researcher Justin Drake called on the industry to plan for "bunker mode" and move large balances to addresses whose public keys are still hidden behind a hash. Buterin kept that advice and added a concern of his own.

"I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography," he wrote in a post published at 23:28 UTC on October 7. "The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices."

The two warnings point at different ends of the same migration. Drake's concern is ECDSA, the signature scheme Bitcoin and Ethereum use now. Buterin's is the family of schemes meant to replace it. ML-DSA is the module-lattice signature scheme NIST published as FIPS 204 in August 2024, and ML-KEM, the agency's lattice-based key-establishment standard, was published the same day. "So far most people have been in the mode of thinking 'elliptic curves broken, hashes safe, lattices safe'," Buterin wrote. "But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math."

Advertisement

728×90

His argument is an analogy rather than an attack. He wrote that "factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes)." "What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be?" He is not claiming a lattice break exists. He is claiming that two years of machine-assisted work could do to lattices what the number field sieve did to factoring, leaving them intact but needing far larger parameters for the same security.

Buterin presented Ethereum's existing direction as a response to the same reasoning. "This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the 'hash-only' direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc.," he wrote, adding that signatures in lean Ethereum are hash-based, either WOTS or SPHINCS+. That is his characterization of work already underway rather than an announcement. Ethereum set its post-quantum deadline in September, and Drake asked on Wednesday for those timelines to be revisited and accelerated. Hash-based signing also remains awkward in practice: the first quantum-safe bitcoin spend in August had to be mined directly because relay rules treated it as nonstandard.

The asymmetry Buterin draws is between signing and encrypting. "For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption." There is no hash-only escape there, he wrote, because "long-standing mathematical theorems" show public-key encryption cannot be built from hashes alone: it needs a trapdoor with some usable structure, whether group theory, lattices or codes, "but for anything that has structure, you should assume that AI will make at least some progress in breaking that structure." His suggested hedge for anything long-lived: "multiply the key sizes by 10." At those sizes, he argued, hash-based constructions win on efficiency wherever they are possible at all, and the problem reaches website access, secure messaging and Tor or VPN traffic, not just blockchains. For privacy protocols he recommended keeping encrypted notes off chain and sending them through a third-party mechanism instead.

Where Buterin agreed with Drake, he qualified the advice with his own losses. Keeping funds in addresses that have never signed a transaction is "a good idea" if it is not difficult, he wrote, before adding a warning: "But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined."

The multisig advice took two posts to settle. In the first, he argued that gathering confirmations off chain keeps signer public keys unexposed, so a wallet "gracefully degrades" to a one-of-one controlled by whoever collected the signatures rather than to "anyone can take the money." Just under four hours later, at 03:17 UTC on October 8, he corrected it: each signer should change their key after every operation. That assumes a weakened ECDSA rather than an instant one, he wrote, which is why in-mempool frontrunning is the thing to worry about, and off-chain collection still helps by shortening the gap between "sig revealed" and "key no longer active." His closing instruction was the same as his opening one. "It's very easy to lose funds from a misconfigured rushed upgrade, so ... don't rush anything."

Buterin stopped short of extending the warning to hashes themselves. He allowed that hashes could in theory be broken too, since P = NP would imply it, but said he thinks P = NP very unlikely. Neither post proposes padding hash output sizes yet; if the worry grows, he wrote, round counts would be increased before byte sizes. Neither post is a protocol decision, and neither announces a change to Ethereum's published post-quantum timeline.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Cardano Put Issuer Freeze Powers Into the Ledger Without a Hard Fork
Tech

The Cardano Foundation says CIP-0113 is live on mainnet after independent audits, letting issuers of stablecoins and tokenized funds build identity checks, sanctions screening and seizure into the asset itself. The controls reach only tokens whose issuers adopt the standard, not ADA.

·MiningPool Staff
Igloo Is Closing Abstract on December 15 and Ruled Out a Token
Business

Luca Netz says the Pudgy Penguins parent lost eight figures on the Ethereum layer 2 over about two years and declined to fund it with a token sale. L2BEAT showed $47 million to $48 million still on the chain just before the announcement, and anything left after December 15 cannot be moved.

·MiningPool Staff
Sepolia Forked to 200 Million Gas, a Limit Validators Can Decline
Tech

Prysm shipped the Sepolia gas schedule about 16 hours before the fork; without it, validators on older builds would have kept proposing at 60 million. The 200 million figure is a target proposers signal rather than a value the protocol enforces, and it applies to Sepolia alone.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.