Vitalik Buterin Warns AI-Accelerated Math Could Threaten Crypto Keys Before Quantum Computing Arrives
Key Takeaways
- •In a post on X dated October 7, 2026, Vitalik Buterin warned that AI-accelerated mathematics could break cryptographic schemes before quantum computers arrive as a practical threat.
- •Buterin flagged lattice-based constructions, including the NIST-selected ML-DSA scheme, and ECDSA as potentially vulnerable to AI-driven mathematical advances.
- •Ethereum's lean roadmap has favored hash-based signatures such as WOTS and SPHINCS- over the past year, avoiding lattices entirely.
- •Buterin recommended keeping funds in unused addresses, gathering multisig confirmations offchain, and sending encrypted notes through offchain mechanisms rather than onchain.
- •He cautioned against hasty wallet migrations, stating he has personally lost more money in botched migrations than in all hacks combined.

Ethereum co-founder Vitalik Buterin has warned that AI-accelerated mathematics could compromise the cryptography protecting digital assets and the wider internet — potentially before quantum computers ever arrive as a practical threat. In a post published on X on October 7, 2026, Buterin argued that the industry should minimize exposure not only to quantum-vulnerable cryptography, but also to schemes that could prove vulnerable to AI-driven mathematical advances, with lattice-based constructions and ECDSA among his chief concerns.
Buterin said he is not urging anyone to rush funds into new wallets today, but described the underlying risks as serious and worth acting on early.
"Take the Risks Seriously": The Full Post
Buterin's complete post, preserved below, lays out his threat model for AI-accelerated mathematics, explains Ethereum's hash-only "lean roadmap," and closes with a list of practical recommendations:
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be?
This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
- Hash-based > lattice-based, in those situations where hash-based is possible at all
- For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor /s …
- For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
- If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.
- For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than "anyone can take the money"
— vitalik.eth (@VitalikButerin) October 7, 2026
AI Could Expose Weaknesses in ECDSA and Lattice Cryptography
Buterin's concern is not limited to quantum computing. He argues that AI systems could accelerate mathematical discovery and find new ways of attacking structures that remain unbroken today, including elliptic curves and lattice-based cryptography.
ECDSA, the signature algorithm commonly used to secure crypto wallets, is based on the difficulty of the elliptic curve discrete logarithm problem. Buterin suggested that fast-evolving AI systems may eventually see through that mathematics and discover a shortcut. He directed the same caution at lattice-based schemes such as ML-DSA — one of the signature schemes the U.S. National Institute of Standards and Technology (NIST) has selected for its post-quantum cryptography standards — and at lattice problems like LWE and RLWE, among others.
Ethereum's Lean Roadmap Favors Hash-Based Cryptography
According to Buterin, this risk is one of the reasons Ethereum's lean roadmap has increasingly favored hash-based cryptography over the past year. The signature designs he cited avoid lattices entirely, using WOTS or SPHINCS-style constructions instead. Hash-based constructions like these derive their security from hash functions alone, with no dependence on the structured mathematical problems — elliptic curves or lattices — that Buterin worries could fall to AI-accelerated research.
In related commentary, Dominick posted on his Facebook page to explain why he believes hash functions offer less for attackers to exploit, while elliptic curves and lattices give up more because of their structural properties. That does not mean hashes cannot be broken, but Buterin considers them less likely to conceal a major design flaw.
Fresh Addresses Could Reduce Public-Key Exposure
Buterin also offered practical guidance for crypto asset holders. Keeping funds in addresses that have not yet been used to send a transaction can lower exposure, because the public key has not yet been published onchain — on Ethereum, a public key only becomes visible once the account sends its first transaction. That matters if ECDSA were ever compromised, since exposed public keys could become easier targets.
He cautioned against hasty migrations, however, noting that operational errors during wallet transfers can be even more dangerous than the theoretical cryptographic risks themselves. "But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined," he wrote.
Multisig and Privacy Designs May Need Changes
For multisig wallets, Buterin prefers gathering confirmations offchain where possible, so the signatures of signer wallets are not unnecessarily exposed to the public. If ECDSA were to fall to AI faster than expected, such a setup would at least "gracefully degrade" to a 1-of-1 controlled by whoever collected the signatures — a far better position, in his view, than leaving the funds reachable by anyone.
On privacy, he strongly advised against placing encrypted notes onchain when an offchain mechanism through a third party can accomplish the same task.
Planning for AI, Not Just Quantum
The broader message of Buterin's warning is that cryptographic security planning — in crypto and far beyond it — needs to account not only for quantum computers, but also for AI systems capable of vastly outpacing existing cryptanalysis and conducting mathematical research at unprecedented speed. The concern, he stressed, extends to website access, secure messaging, Tor, VPNs, and any system that relies on public-key encryption.
In his own framing, the next two years of AI-assisted mathematics are the period to watch — the window in which he believes the concrete security of lattice-based schemes could take serious hits, and the timeline against which his hash-only recommendations will likely be evaluated.
Source: Crypto Ninjas — Vitalik Warns AI Math Could Threaten Crypto Keys Before Quantum Computing Arrives