Vitalik Buterin avverte: la matematica accelerata dall'IA potrebbe minacciare le chiavi crittografiche prima dell'arrivo del computing quantistico
Punti chiave
- •In un post su X datato 7 ottobre 2026, Vitalik Buterin ha avvertito che la matematica accelerata dall'IA potrebbe violare gli schemi crittografici prima che i computer quantistici diventino una minaccia concreta.
- •Buterin ha segnalato le costruzioni basate su reticoli, incluso lo schema ML-DSA selezionato dal NIST, e ECDSA come potenzialmente vulnerabili ai progressi matematici guidati dall'IA.
- •La lean roadmap di Ethereum ha privilegiato nell'ultimo anno firme basate su funzioni hash come WOTS e SPHINCS-, evitando del tutto i reticoli.
- •Buterin ha raccomandato di mantenere i fondi su indirizzi inutilizzati, di raccogliere le conferme multisig offchain e di inviare le note crittografate tramite meccanismi offchain anziché onchain.
- •Ha sconsigliato le migrazioni frettolose dei wallet, affermando di aver perso personalmente più soldi in migrazioni mal riuscite che in tutti gli hack messi insieme.

Il co-fondatore di Ethereum Vitalik Buterin ha avvertito che la matematica accelerata dall'IA potrebbe compromettere la crittografia che protegge le risorse digitali e Internet in generale — potenzialmente prima ancora che i computer quantistici diventino una minaccia concreta. In un post pubblicato su X il 7 ottobre 2026, Buterin ha sostenuto che il settore dovrebbe ridurre al minimo l'esposizione non solo alla crittografia vulnerabile al quantum, ma anche agli schemi che potrebbero rivelarsi vulnerabili ai progressi matematici guidati dall'IA, con le costruzioni basate su reticoli e ECDSA tra le sue principali preoccupazioni.
Buterin ha detto di non invitare nessuno a trasferire frettolosamente i fondi in nuovi wallet oggi, ma ha descritto i rischi sottostanti come seri e degni di un'azione precoce.
"Prendere sul serio i rischi": il post completo
Il post integrale di Buterin, riportato di seguito, illustra il suo modello di minaccia per la matematica accelerata dall'IA, spiega la "lean roadmap" di Ethereum basata solo su funzioni hash e si conclude con un elenco di raccomandazioni pratiche:
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be?
This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for public-key encryption – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to breakattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
- Hash-based > lattice-based, in those situations where hash-based is possible at all
- For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor /s …
- For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
- If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.
- For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than "anyone can take the money"
— vitalik.eth (@VitalikButerin) October 7, 2026
L'IA potrebbe esporre le debolezze di ECDSA e della crittografia basata su reticoli
La preoccupazione di Buterin non si limita al computing quantistico. Egli sostiene che i sistemi di IA potrebbero accelerare la scoperta matematica e trovare nuovi modi di attaccare strutture che oggi restano inviolate, tra cui le curve ellittiche e la crittografia basata su reticoli.
ECDSA, l'algoritmo di firma comunemente usato per proteggere i wallet di criptovalute, si basa sulla difficoltà del problema del logaritmo discreto su curve ellittiche. Buterin ha suggerito che sistemi di IA in rapida evoluzione potrebbero alla fine vedere attraverso quella matematica e scoprire una scorciatoia. Ha rivolto la stessa cautela agli schemi basati su reticoli come ML-DSA — uno degli schemi di firma selezionati dal National Institute of Standards and Technology (NIST) statunitense per i suoi standard di crittografia post-quantum — e a problemi su reticoli come LWE e RLWE, tra gli altri.
La lean roadmap di Ethereum privilegia la crittografia basata su funzioni hash
Secondo Buterin, questo rischio è uno dei motivi per cui la lean roadmap di Ethereum ha privilegiato sempre più, nell'ultimo anno, la crittografia basata su funzioni hash. I progetti di firma che ha citato evitano del tutto i reticoli, utilizzando invece costruzioni in stile WOTS o SPHINCS. Costruzioni basate su hash come queste derivano la loro sicurezza esclusivamente dalle funzioni hash, senza dipendere dai problemi matematici strutturati — curve ellittiche o reticoli — che, secondo Buterin, potrebbero cadere sotto la spinta della ricerca accelerata dall'IA.
In un commento correlato, Dominick ha pubblicato sulla sua pagina Facebook una spiegazione del motivo per cui ritiene che le funzioni hash offrano meno elementi sfruttabili agli attaccanti, mentre le curve ellittiche e i reticoli ne cedono di più a causa delle loro proprietà strutturali. Questo non significa che gli hash non possano essere violati, ma Buterin li considera meno propensi a nascondere un difetto di progetto importante.
Gli indirizzi freschi potrebbero ridurre l'esposizione della chiave pubblica
Buterin ha anche offerto indicazioni pratiche per i detentori di asset crittografici. Mantenere i fondi su indirizzi non ancora utilizzati per inviare una transazione può ridurre l'esposizione, perché la chiave pubblica non è ancora pubblicata onchain — su Ethereum, una chiave pubblica diventa visibile solo quando l'account invia la sua prima transazione. Questo è rilevante nel caso ECDSA venisse mai compromesso, poiché le chiavi pubbliche esposte potrebbero diventare bersagli più facili.
Ha tuttavia sconsigliato le migrazioni frettolose, osservando che gli errori operativi durante i trasferimenti di wallet possono essere persino più pericolosi degli stessi rischi crittografici teorici. "Ma fate attenzione alle migrazioni; personalmente ho perso più soldi in migrazioni mal riuscite che in tutti gli hack messi insieme", ha scritto.
I design multisig e privacy potrebbero richiedere modifiche
Per i wallet multisig, Buterin preferisce raccogliere le conferme offchain quando possibile, in modo che le firme dei wallet firmatari non vengano inutilmente esposte al pubblico. Se ECDSA cadesse per colpa dell'IA più rapidamente del previsto, una configurazione del genere si "degraderebbe gracefully" quantomeno a un 1-di-1 controllato da chi ha raccolto le firme — una posizione molto migliore, a suo avviso, rispetto a lasciare i fondi accessibili a chiunque.
Sulla privacy, ha sconsigliato vivamente di collocare note crittografate onchain quando un meccanismo offchain tramite terze parti può compiere lo stesso compito.
Pianificare per l'IA, non solo per il quantum
Il messaggio più ampio dell'avvertimento di Buterin è che la pianificazione della sicurezza crittografica — nel mondo crypto e ben oltre — deve tenere conto non solo dei computer quantistici, ma anche dei sistemi di IA capaci di superare di gran lunga la crittoanalisi esistente e di condurre ricerca matematica a una velocità senza precedenti. La preoccupazione, ha sottolineato, si estende all'accesso ai siti web, alla messaggistica sicura, a Tor, alle VPN e a qualsiasi sistema che si basi sulla crittografia a chiave pubblica.
Secondo la sua stessa impostazione, i prossimi due anni di matematica assistita dall'IA sono il periodo da tenere d'occhio — la finestra in cui, secondo lui, la sicurezza concreta degli schemi basati su reticoli potrebbe subire colpi gravi, e la cronologia rispetto alla quale le sue raccomandazioni basate solo su funzioni hash saranno probabilmente valutate.
Fonte: Crypto Ninjas — Vitalik Warns AI Math Could Threaten Crypto Keys Before Quantum Computing Arrives