Justin Drake, a researcher at the Ethereum Foundation, issued a stark warning: AI-assisted mathematical advances could theoretically break ECDSA, the signature algorithm securing many Bitcoin wallets, before quantum computers ever get close enough to matter.
The Warning
Drake described a worst-case scenario so severe he called it “bunker mode” territory, though no demonstrated attack exists to support that framing.
Drake defined a successful break as rapid private-key recovery, potentially within roughly one week, using a large GPU cluster. His stated timeline was “months, not years” in the worst case.
The trigger was a set of new AI-generated mathematical results published by OpenAI. Critically, that publication presented no attack on cryptography, elliptic curves, or ECDSA. Drake’s connection between those results and an imminent Bitcoin risk is his own extrapolation, not a conclusion OpenAI drew.
His practical recommendations were clear. Move funds to addresses that have never signed a transaction, which keeps your public key hidden behind Bitcoin’s address-hashing layer. After any signed transaction, send change to a fresh address.
Drake also added a notable caveat: a panicked, disorderly migration could create more risk than the hypothetical threat itself.
The Pushback
Leading cryptographers responded that Drake’s warning lacked any concrete evidence of weakness in the underlying mathematics.
Yehuda Lindell, Coinbase’s head of cryptography and a computer-science professor, said there was “no evidence whatsoever” that the hardness assumptions underlying elliptic-curve cryptography were anywhere near failing, according to Gizmodo. He argued that AI systems proving theorems or excelling at other difficult problems do not establish an efficient method for solving the specific mathematical problems on which ECDSA depends.
Lindell also identified a broader systemic concern. A genuine ECDSA break could have serious consequences across systems that rely on related public-key cryptography, including web certificates, banking infrastructure, and password vaults and software signing.
Adam Back, Blockstream co-founder, dismissed the warning as a “fud-burger.” Rob Hamilton similarly criticized the claim for pointing at no concrete degradation in the underlying mathematics.
Matthew Green, a cryptographer at Johns Hopkins, offered the most measured position. AI systems are outperforming humans on difficult mathematical problems, and that trajectory is worth watching. Green stopped well short of confirming Drake’s timeline, noting that no publicly disclosed result demonstrates an ECDSA-breaking capability.
What This Actually Means for You
No publicly disclosed classical attack can currently recover Bitcoin private keys from ECDSA public keys at the speed Drake described.
Avoiding address reuse is sound hygiene regardless of this debate. Rotating to fresh addresses after signing is a widely supported Bitcoin security practice, and it reduces exposure whether or not any AI-assisted threat ever materializes. Knowing how to stay safe across all your devices compounds the benefit of good wallet hygiene.
What Drake raised is a contingency argument: low on verified evidence but high on potential impact. That framing warrants serious planning consideration, not a conclusion that your wallet is under active threat. Whether this debate accelerates broader post-quantum migration planning across the industry remains to be seen. For now, measured awareness is the appropriate response.




























