Ethereum's Justin Drake Urges 'Bunker Mode' Planning as AI Math Advances Threaten ECDSA
Key Takeaways
- •Justin Drake advises moving assets, starting with large holders, into never-used addresses whose public keys stay hidden behind hashes, because signing a transaction permanently exposes a key on-chain.
- •Drake identifies AI-generated mathematics, exemplified by OpenAI's release of 722 manuscripts from an unreleased internal model, as a more immediate threat to elliptic-curve cryptography than quantum computing.
- •Anthropic reported that its Claude Mythos Preview model cut the key strength of the HAWK post-quantum signature candidate by 50% in 60 hours, though HAWK has not been deployed in production systems.
- •A Europol report found that 6.04 million BTC, approximately 30.2% of supply, had exposed public keys as of May 2026, and named pre-emptive wallet migration as the only solution.
- •Drake says exiting 'bunker mode' will require hash-based 'post-AI cryptography,' a direction already reflected in Ethereum's draft roadmap and NIST's 2024 post-quantum standards.

Justin Drake, a researcher at the Ethereum Foundation, is advising the crypto industry to begin quietly relocating funds into fresh wallets, warning that the signature scheme securing both Bitcoin and Ethereum could be broken before a quantum computer ever arrives.
In a post on X, Drake called on the industry to "calmly begin planning for 'bunker mode.'" The core of his recommendation is to move assets — large holders first — into addresses whose public keys remain hidden behind a hash because they have never signed a transaction.
The mechanics of the warning
The rationale rests on how the two largest blockchains authenticate transactions. Bitcoin and Ethereum both rely on the Elliptic Curve Digital Signature Algorithm, or ECDSA, to confirm that a transaction came from the actual holder of a key. Once an address signs anything, its public key becomes effectively visible on-chain, and Drake argues that any funds remaining at that address after a signature should be moved again. An exposed key cannot be re-hidden, whereas a never-used address reveals only a one-way hash of its key — the asymmetry that makes untouched addresses the safer destination he is pointing to.
He framed the relocation as a precaution rather than a reaction to an actual compromise. Drake stopped short of claiming that current cryptography has already fallen. Ethereum maintains that a quantum computer cannot break the network today and that its users do not need to worry. Drake, however, sees a breakthrough arriving in months, not years.
AI, not quantum, as the trigger
Most discussion has centered on "q-day," the anticipated moment a quantum computer breaks public-key cryptography.'s argument points elsewhere: to the rapid rise of AI-generated mathematics. As an example, he cited OpenAI's release of 722 mathematical manuscripts produced by an internal model that has yet to launch.
The results are arranged into 372 families in a public GitHub repository, and the majority carry proofs formalized in Lean, making them easy for a computer to verify. OpenAI says the model was given about 4,000 problems.
Drake's response was stark: "mathematical superintelligence is upon us," he wrote. His concern is that elliptic curves possess more mathematical structure than hash functions, which he believes leaves them exposed to a fresh discovery. He pointed to a possible future in which a new algorithm running on ordinary computers could break both elliptic-curve cryptography and RSA, without quantum hardware. The stakes of that hypothetical would reach well beyond crypto: elliptic-curve cryptography and RSA also secure the TLS connections behind everyday web traffic and much of the world's software signing.
Evidence that AI can already find cryptographic weaknesses
Drake is not alone in viewing AI as a cryptographic risk rather than just a cryptographic tool. In July, Anthropic said its Claude Mythos Preview model improved on the best-known attack on HAWK, cutting the scheme's key strength by 50% in 60 hours. HAWK is a post-quantum signature candidate submitted to NIST, the U.S. standards agency that finalized its first post-quantum cryptography standards in 2024 and continues to evaluate additional signature schemes. Anthropic said the finding has no bearing on production systems, because HAWK has not been deployed.
The quantum track is not slowing down, either. Based on research reports, future quantum computers could break the elliptic-curve cryptography protecting cryptocurrency with fewer qubits than previously thought, and a 2029 migration deadline was reiterated.
Where the exposed coins sit
A Europol report published this week concluded that blockchains cannot be hacked by quantum computing owing to the strength of the hash functions binding blocks together. Wallets, however, were deemed "the primary point of exposure," and pre-emptive migration was named the only solution — the same step Drake is urging.
Citing an on-chain count, Europol noted that 6.04 million BTC, approximately 30.2% of supply, had exposed public keys as of May 2026. Drake also pointed to Project Eleven's Bitcoin Risq List, which tracks more than 14 million addresses with exposed keys. About 20,000 of those exposed addresses hold under 50 BTC and could be raided by an attacker before smaller wallets — a grouping he called "Satoshi's shield."
Exiting "bunker mode," Drake said, will require "post-AI cryptography." He favors security built on hash functions, a direction Ethereum's draft roadmap already leans toward with hash-based schemes and formal verification. NIST's 2024 standards already include a hash-based signature option alongside lattice-based defaults, and the underlying evidence is publicly trackable: the exposed-key counts from Europol and Project Eleven, and any shifts of coins toward never-used addresses, can be observed on-chain while Ethereum's draft roadmap is still taking shape.