Jameson Lopp Dismisses AI Threat to Bitcoin (BTC) After Months Battling AI Hackers
Jameson Lopp says AI cannot crack Bitcoin's ECDSA cryptography, urging focus on AI-driven bug hunting as Justin Drake's warning splits the industry.
AI SummaryAI
- Jameson Lopp dismissed AI cryptographic-break fears for Bitcoin (BTC) on October 8, 2026.
- Justin Drake claimed new Anthropic and OpenAI models could crack ECDSA signatures in months.
- Claude Mythos Preview uncovered a HAWK algorithm vulnerability in 60 hours, per Drake.
- Google Threat Intelligence data shows monthly disclosed software vulnerabilities nearly doubled in a year.
The “Months, Not Years” Claim
Veteran
Bitcoin (BTC) developer and Casa co-founder Jameson Lopp has pushed back against the loudest claim in this week's security debate, arguing that fears of artificial intelligence breaking Bitcoin (BTC) cryptography are premature and have pulled attention away from real attacks. The exchange of views picked up pace on Thursday, October 8, 2026, and did nothing to steady the tape: the Bitcoin price slipped 3.1% over the past 24 hours while the argument ran on. Lopp was responding to a warning from Ethereum Foundation researcher Justin Drake, with endorsement from Haseeb Qureshi of Dragonfly, that new models from Anthropic and OpenAI could crack the basic ECDSA signature algorithm “in months, not years.” ECDSA is the elliptic-curve signature scheme that proves ownership of every unspent Bitcoin output, and it has never been broken against a live key; the dispute is whether frontier AI is about to change that. Drake built his case on the Claude Mythos Preview neural network, which uncovered a vulnerability in the post-quantum HAWK algorithm in 60 hours, and urged investors to prepare urgently for what he called “bunker mode.” Lopp, who says he has spent the past several months battling AI acceleration of vulnerability discovery against
Bitcoin (BTC) infrastructure, calls that framing backwards. In a post published on X, he wrote that worrying about cryptographic breaks is “getting ahead of ourselves” because the industry has “much more pressing actual issues to deal with,” adding that “theoretical future problems can wait.” The stakes are practical rather than academic. While theorists model a hypothetical collapse of the mathematical foundations of encryption, attackers are already putting AI to more mundane work, automatically scanning application code and wallet firmware for ordinary human bugs. That distinction decides where defensive budgets belong, whether a holder follows HODL discipline in cold storage or trades actively, and it has split Bitcoin security discussions across the industry.
@lopp · X post
A post published on X.
View on X
Google Data and Coldcard Flaws
Support for Lopp's position comes from figures he cites rather than from theory alone. Google Threat Intelligence statistics cited in the debate show the monthly number of disclosed software vulnerabilities has nearly doubled over the past year, and neural networks have become efficient scanners of that expanding surface, surfacing implementation flaws in minutes. One example carried particular weight: machine analysis exposed weaknesses in seed phrase generation in Coldcard wallets, a class of flaw that would have taken human auditors weeks to find. Lopp's argument is that concentrating effort on breaking ECDSA is counterproductive while AI effortlessly exposes badly written software. The practical advice that followed matches that reading: collect multisig signatures off-chain, and avoid sending transactions from savings addresses so their public keys stay hidden, a practice institutional desks and the Best Crypto Exchanges already follow. The original warning came from Ethereum research circles, where Drake works, but the cryptography it targets is shared across chains. The same signatures secure every movement of value on the base chain, from mining payouts to institutional settlement, which is why the argument reaches well beyond a single protocol. Ethereum co-founder Vitalik Buterin also joined the debate, and his contribution narrowed the gap between the camps. While acknowledging that AI poses long-term risks to cryptography, he agreed that premature action can be more dangerous than the threat itself, and he made the point with a joke: he personally lost more money to botched wallet updates than to all hacker attacks combined. No documented instance exists of a live ECDSA key ever having been cracked, the quiet factual baseline beneath the entire dispute, and it supports his call to prioritize operations over theory. In Lopp's telling, the race rewards teams that harden live software today over those bracing for a hypothetical future super-intelligence.
Our reading of the exchange starts from the primary record: Lopp's post makes a narrow, testable claim rather than a forecast. He does not argue that AI can never threaten cryptography; he argues the ordering is wrong, with documented, AI-accelerated discovery of implementation flaws arriving before any hypothetical mathematical break. Operational history supports that ordering: no documented case exists of a live ECDSA key on
Bitcoin (BTC) having been cracked, which is why the panic case remains speculative while the cleanup race is measurable today. Applications layered on the base chain, from custody stacks to Bitcoin DeFi positions, inherit that record. Price levels tracked in our Bitcoin technical analysis coverage are secondary; the reading breaks only if a live key is verified as broken, so the debate stays open-ended.
Primary sources
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

