His stated trigger is an OpenAI release of machine-generated mathematics that the company itself describes as unevenly verified. In June he put the odds of a quantum break by 2032 at 50% and named 2029 as a good migration target.
Justin Drake, an Ethereum researcher who has said most of his time goes to the network's post-quantum migration, asked the blockchain industry on Wednesday to begin planning for what he called "bunker mode." He said it is now reasonable to expect that ECDSA, the signature scheme behind Bitcoin and Ethereum transactions, could be broken before a quantum computer is able to do it. His recommendation is a controlled migration of large balances to addresses whose public keys are still hidden behind a hash.
"Today I call upon the blockchain industry to calmly begin planning for 'bunker mode,'" Drake wrote in a post published at 14:14 UTC. "My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash." Holders, "starting with large and sophisticated ones," should move the bulk of their funds to addresses that have never signed a transaction, and should move whatever remains to a new address once an address has signed one. He asked twice for restraint: "Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either."
The step turns on when a public key becomes visible. In the common case an address is a hash of the key that controls it, and the key itself only has to be revealed when its owner spends. An attacker who can recover a private key from a public key can therefore reach a balance that has already moved coins out at least once, and cannot reach one that has not. Drake described the migration as "a simple, preventative step which does not require new cryptography or new wallets."
What he means by a break is specific. "IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years," he wrote. "By 'break' I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster)." That is a classical attack on hardware that exists, a different threat from the one the industry has been planning around.
His stated reason is the pace of machine-assisted mathematics. He pointed to recently fallen results, naming the n log(n) bound for integer multiplication, the 3SUM conjecture and May's disproof of the Erdős unit distance conjecture, and to OpenAI's publication a day earlier of mathematical work produced by an unreleased model, which he said "made it clear that mathematical superintelligence is upon us." That release, according to The Latent, covered 722 manuscripts grouped into 372 families of related results, posted to a public repository with Lean formalizations of many of the proofs. OpenAI said the results sit at different stages of verification and warned that some of the work without formal proofs could contain errors. Drake read the same collection a second way, calling the "striking under-representation of cryptographic breakthroughs" in it a sign of intervention and writing that he has "witnessed first-hand the US government censoring academic quantum cryptanalysis results."
He also offered a structural argument for why signatures are the exposed part. "Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)" A classical counterpart to Shor's algorithm, he wrote, could break elliptic curves and RSA at once.
The timeline is the part that has moved. In June, writing after the publication of Google Quantum AI work on Shor's algorithm for elliptic curves that he says he co-authored, Drake put the odds of a quantum break by 2032 at 50% and by 2030 at 10%, and called 2029 "a good target date for migration," the date he said Google, Cloudflare and the Ethereum Foundation had each selected. Ethereum set that deadline for itself in September and treated it as fixed. His June advice was also to avoid rushing. What changed on Wednesday is not that estimate but the arrival of a second route to the same failure, which he now thinks could land first.
For holders who are not large, he put the threshold at 50 BTC, arguing that smaller wallets have partial cover from what he called "Satoshi's shield," roughly 20,000 exposed addresses holding 50 BTC each that an attacker would reach for first. He suggested that oracles and layer-2 security councils, which sign repeatedly by design, rotate keys with every signed message or add a hash-based scheme such as SPHINCS, and said Binance, Bitbank, Robinhood, Bitfinex and Tether could harden their cold storage.
None of this is a protocol decision, and Drake presented it as his own recommendation rather than a change of plan. He wrote that leaving bunker mode safely will require "post-AI cryptography," that his inclination is to avoid structured assumptions from curves, lattices and isogenies in favor of hashes, and that the published roadmap timelines "must now be revisited and accelerated." No revision has been announced. Ethereum moved its post-quantum work toward hashes in August, abandoning the Poseidon function for SHA or BLAKE, and the schedule Drake described then put a production-grade leanVM in 2027 with client deployments in 2028. The first quantum-safe bitcoin spend in August had to be mined directly because it was nonstandard under relay rules, and Ethereum's next scheduled fork carries no post-quantum code.