Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

Justin Drake Says ECDSA Could Break Before Quantum Computers Do

His stated trigger is an OpenAI release of machine-generated mathematics that the company itself describes as unevenly verified. In June he put the odds of a quantum break by 2032 at 50% and named 2029 as a good migration target.

By MiningPool Staff··4 min read
Justin Drake Says ECDSA Could Break Before Quantum Computers Do

Key Points

  • His stated trigger is an OpenAI release of machine-generated mathematics that the company itself describes as unevenly verified.
  • In June he put the odds of a quantum break by 2032 at 50% and named 2029 as a good migration target.

Justin Drake, an Ethereum researcher who has said most of his time goes to the network's post-quantum migration, asked the blockchain industry on Wednesday to begin planning for what he called "bunker mode." He said it is now reasonable to expect that ECDSA, the signature scheme behind Bitcoin and Ethereum transactions, could be broken before a quantum computer is able to do it. His recommendation is a controlled migration of large balances to addresses whose public keys are still hidden behind a hash.

"Today I call upon the blockchain industry to calmly begin planning for 'bunker mode,'" Drake wrote in a post published at 14:14 UTC. "My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash." Holders, "starting with large and sophisticated ones," should move the bulk of their funds to addresses that have never signed a transaction, and should move whatever remains to a new address once an address has signed one. He asked twice for restraint: "Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either."

The step turns on when a public key becomes visible. In the common case an address is a hash of the key that controls it, and the key itself only has to be revealed when its owner spends. An attacker who can recover a private key from a public key can therefore reach a balance that has already moved coins out at least once, and cannot reach one that has not. Drake described the migration as "a simple, preventative step which does not require new cryptography or new wallets."

Advertisement

728×90

What he means by a break is specific. "IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years," he wrote. "By 'break' I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster)." That is a classical attack on hardware that exists, a different threat from the one the industry has been planning around.

His stated reason is the pace of machine-assisted mathematics. He pointed to recently fallen results, naming the n log(n) bound for integer multiplication, the 3SUM conjecture and May's disproof of the Erdős unit distance conjecture, and to OpenAI's publication a day earlier of mathematical work produced by an unreleased model, which he said "made it clear that mathematical superintelligence is upon us." That release, according to The Latent, covered 722 manuscripts grouped into 372 families of related results, posted to a public repository with Lean formalizations of many of the proofs. OpenAI said the results sit at different stages of verification and warned that some of the work without formal proofs could contain errors. Drake read the same collection a second way, calling the "striking under-representation of cryptographic breakthroughs" in it a sign of intervention and writing that he has "witnessed first-hand the US government censoring academic quantum cryptanalysis results."

He also offered a structural argument for why signatures are the exposed part. "Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)" A classical counterpart to Shor's algorithm, he wrote, could break elliptic curves and RSA at once.

The timeline is the part that has moved. In June, writing after the publication of Google Quantum AI work on Shor's algorithm for elliptic curves that he says he co-authored, Drake put the odds of a quantum break by 2032 at 50% and by 2030 at 10%, and called 2029 "a good target date for migration," the date he said Google, Cloudflare and the Ethereum Foundation had each selected. Ethereum set that deadline for itself in September and treated it as fixed. His June advice was also to avoid rushing. What changed on Wednesday is not that estimate but the arrival of a second route to the same failure, which he now thinks could land first.

For holders who are not large, he put the threshold at 50 BTC, arguing that smaller wallets have partial cover from what he called "Satoshi's shield," roughly 20,000 exposed addresses holding 50 BTC each that an attacker would reach for first. He suggested that oracles and layer-2 security councils, which sign repeatedly by design, rotate keys with every signed message or add a hash-based scheme such as SPHINCS, and said Binance, Bitbank, Robinhood, Bitfinex and Tether could harden their cold storage.

None of this is a protocol decision, and Drake presented it as his own recommendation rather than a change of plan. He wrote that leaving bunker mode safely will require "post-AI cryptography," that his inclination is to avoid structured assumptions from curves, lattices and isogenies in favor of hashes, and that the published roadmap timelines "must now be revisited and accelerated." No revision has been announced. Ethereum moved its post-quantum work toward hashes in August, abandoning the Poseidon function for SHA or BLAKE, and the schedule Drake described then put a production-grade leanVM in 2027 with client deployments in 2028. The first quantum-safe bitcoin spend in August had to be mined directly because it was nonstandard under relay rules, and Ethereum's next scheduled fork carries no post-quantum code.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Cardano Put Issuer Freeze Powers Into the Ledger Without a Hard Fork
Tech

The Cardano Foundation says CIP-0113 is live on mainnet after independent audits, letting issuers of stablecoins and tokenized funds build identity checks, sanctions screening and seizure into the asset itself. The controls reach only tokens whose issuers adopt the standard, not ADA.

·MiningPool Staff
Igloo Is Closing Abstract on December 15 and Ruled Out a Token
Business

Luca Netz says the Pudgy Penguins parent lost eight figures on the Ethereum layer 2 over about two years and declined to fund it with a token sale. L2BEAT showed $47 million to $48 million still on the chain just before the announcement, and anything left after December 15 cannot be moved.

·MiningPool Staff
Sepolia Forked to 200 Million Gas, a Limit Validators Can Decline
Tech

Prysm shipped the Sepolia gas schedule about 16 hours before the fork; without it, validators on older builds would have kept proposing at 60 million. The 200 million figure is a target proposers signal rather than a value the protocol enforces, and it applies to Sepolia alone.

·MiningPool Staff
NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.