Vitalik Buterin Warns AI Could Break Lattice Cryptography Faster Than Expected
Key Takeaways
- •Vitalik Buterin warned in an October 7, 2026 post on X that AI-accelerated mathematics could seriously weaken lattice-based cryptography, including ML-DSA and fully homomorphic encryption, within two years.
- •He cautioned that ECDSA, the elliptic-curve signature scheme underpinning Bitcoin and Ethereum, could fall sooner than many expect, making addresses that have never sent a transaction safer for holding funds.
- •Ethereum's lean roadmap has already excluded lattices, ML-DSA, and Falcon, relying on hash-based signatures such as WOTS and SPHINCS+, which Buterin said can already cover signatures and proofs.
- •For public-key encryption, which cannot be constructed from hashes alone, Buterin recommended multiplying key sizes by ten to make it plausibly long-term secure.
- •He advised against hasty wallet migrations, saying he has personally lost more money in botched migrations than in all hacks combined, while voicing support for offchain multisig confirmations and encrypted privacy note delivery.

Ethereum co-founder Vitalik Buterin has urged the crypto community to take AI-driven threats to cryptography seriously, warning that lattice-based schemes such as ML-DSA and fully homomorphic encryption (FHE) face growing risk from accelerated mathematical research.
In a post on X published on October 7, 2026, Buterin advised users against rushing to move their funds into new wallets, while recommending that the industry reduce its exposure not only to quantum-vulnerable cryptography but also to cryptography that could prove vulnerable to AI. He added that ECDSA, the elliptic-curve signature scheme underpinning much of today's crypto infrastructure, including Bitcoin and Ethereum, could fall sooner than many expect — a scenario that would favor keeping funds in fresh addresses.
Why Lattice-Based Cryptography Faces New Scrutiny
Buterin outlined the concern in a post on X. He noted that many people assume elliptic curves are broken while hashes and lattices remain safe. In his words, “there is a good chance that the concrete security of lattices will take serious hits.” He tied that risk to AI-assisted mathematics over the next two years.
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.…
— vitalik.eth (@VitalikButerin) October 7, 2026
Buterin drew a parallel with integer factoring. Factoring naively takes 2^(n/2) time, but researchers later developed number field sieves that cut the complexity to 2^O(n^(1/3)). As a result, RSA keys and signatures require roughly 400 bytes rather than 64 bytes. “What if there are skeletons in the closet like that, both for elliptic curves and lattices?” Buterin asked. Humans may not be smart enough to discover such weaknesses, he said, “but bots soon will be.” He named ML-DSA, FHE, and lattices as the core new area of risk.
That last point reaches beyond Ethereum: ML-DSA is the lattice-based signature algorithm NIST standardized in FIPS 204 as a post-quantum replacement for elliptic-curve signatures, so the warning lands on the very constructions being deployed to carry the industry's quantum-safety migration.
He also laid out a conditional scenario: if AI compresses 50 years of mathematical progress into two years, lattice-based schemes would need far larger parameters to stay secure. At those sizes, hash-based constructions would outperform lattice-based ones on efficiency wherever they can be applied.
Hash-Based Alternatives and Practical Recommendations
Ethereum's lean roadmap has moved toward hash-only designs over the past year, excluding lattices, ML-DSA, Falcon, and lattice commitments inside ZK proofs. Signatures in lean Ethereum rely on hash-based schemes — either WOTS or SPHINCS+ — and Buterin said signatures and proofs can already go hash-only.
Public-key encryption presents a harder challenge. According to Buterin, theorems show it cannot be built from hashes alone; it requires a trapdoor object with usable structure, such as lattices or code-based systems. He expects AI to make some progress in breaking that structure, and his advice is to “multiply the key sizes by 10” to make public-key encryption plausibly long-term secure.
Buterin does not yet see a reason to pad the byte size of hashes; if concerns grow, he would increase round counts first. He acknowledged that P = NP would break hashes but called that outcome very unlikely. His summary: “Hash-based > lattice-based, in those situations where hash-based is possible at all.”
The post also listed practical steps. Buterin advised keeping funds in addresses that have not yet made a transaction, where easy to do so. The reasoning is mechanical: an address's public key only becomes visible once the address has sent a transaction, so funds in addresses that have never transacted leave an attacker little to target even if ECDSA falls. He cautioned against hasty wallet migrations, warning, “I personally have lost more money in botched migrations than I have lost in all hacks combined.”
He also expressed support for offchain multisig confirmations and offchain delivery of encrypted privacy notes.
Buterin's framing sets the markers to watch from here: whether AI-assisted mathematics produces concrete cryptanalytic results against lattice constructions within the two-year window he cited, and whether Ethereum's lean roadmap keeps extending hash-only signatures and proofs across more of the protocol.
Source: Blockonomi