Justin Drake Warns Bitcoin (BTC) ECDSA Could Break “in Months,” Urges Bunker Mode Migration
Justin Drake urges Bitcoin holders to prepare a bunker mode migration to fresh addresses, warning ECDSA signatures could break within months.
AI SummaryAI
- Justin Drake called for “bunker mode” migration to fresh addresses on October 7, 2026.
- Drake says ECDSA could break, worst case, in months rather than years.
- OpenAI published 722 mathematical results that Drake tied to mathematical superintelligence.
- Drake named Binance, Bitbank, Robinhood, Bitfinex and Tether to harden cold storage.
Ethereum researcher Ethereum figure Justin Drake issued a public call to the blockchain industry on October 7, 2026, urging it to begin planning for what he terms “bunker mode.” The trigger is cryptographic rather than market-driven: the Bitcoin (BTC) price plays no part in a warning that the signatures securing the network could someday be forged. In a post published on X, Drake urges the industry to set in motion a mass migration of assets into fresh addresses, meaning addresses whose public keys remain hidden behind a hash. Holders, beginning with the largest and most sophisticated, crypto whales first among them, should move most of their funds to addresses that have never produced a signature, then sweep whatever remains to a new address each time they sign one. His core claim is bounded: he judges it sensible to prepare for the possibility that ECDSA fails before qday, with the worst case arriving in months rather than years. By failure he means fast private-key recovery, roughly within a week, on hardware such as a large GPU cluster. The reasoning rests on a run of mathematical upsets: long-held hypotheses, including the n log(n) bound for integer multiplication and the 3SUM conjecture, have fallen in recent days, and May’s unexpected disproof of the Erdős unit distance conjecture was, in hindsight, the warning shot. The release of 722 mathematical results from OpenAI the day before convinced him that mathematical superintelligence is near, and that elliptic curves, rich in structure, are more exposed than hashes, which are built to minimize algebraic structure. The caveat matters as much as the warning. OpenAI’s publication reported no practical attack on ECDSA or RSA, no such algorithm is known to exist, and Drake himself says a rushed migration would do more harm than good. Moving coins to protected addresses requires no new cryptography and no new wallets, so holders who intend to HODL long term can act without panic.
Cold Storage and Satoshi’s Shield
Drake named five venues he wants leading the hardening: Binance, Bitbank, Robinhood, Bitfinex and Tether have an opportunity, he wrote, to strengthen their cold storage. For measuring the problem he points to Project11’s risq list, a public tracker of exposed
Bitcoin (BTC) public keys. Small holders get partial cover from what he calls Satoshi’s shield: wallets holding under 50 BTC are protected in part by his own roughly 20,000 exposed addresses, each of them holding 50 BTC. Load-bearing signers receive more specific advice: oracles and layer-2 security councils should consider rotating ECDSA public keys with every signed message, or multi-signing with a hash-based scheme such as SPHINCS. Exiting bunker mode safely, he writes, will require post-AI cryptography, and his inclination is to go all-in on hash-based schemes from the SHA or BLAKE families, avoiding structured mathematical assumptions from curves, lattices or isogenies altogether. Hashes, the primitive behind proof of work, minimize exactly the structure he worries about in curves. A second, subtler risk sits behind the headline: as researcher Ewin Tang’s work suggests, an efficient quantum algorithm can foreshadow an efficient classical one, so Drake leaves open a classical counterpart to Shor that breaks elliptic curves and RSA at once. His own ecosystem is already moving: the Ethereum roadmap, laid out on strawmap.org, embraces hash-based cryptography with end-to-end formal verification against the quantum threat, and timelines set for around 2029 must now be revisited and accelerated, with Drake pledging to push for maximum defensive acceleration. Next month he is due to address institutions in London in a live question-and-answer session. He also flags what he calls a striking under-representation of cryptographic breakthroughs among OpenAI’s 722 results, and, having witnessed United States government censorship of academic quantum cryptanalysis firsthand, names backroom interventionism as his base case.
What the Worst Case Does Not Cover
Our reading is that the security boundary in Drake’s scenario is the signature, not the balance. A public key hidden behind a hash stays safe until its first signature exposes it, which is why he asks large holders to migrate before they transact, not after. The protection his post quantifies is narrow: Satoshi’s shield covers wallets under 50
Bitcoin (BTC), resting on about 20,000 addresses of 50 BTC each, while whales, exchange cold wallets and strategic Bitcoin reserve treasuries sit outside it, and a tracker such as the risq list can only count keys that are already public. The months-long worst case assumes an algorithm nobody has demonstrated; OpenAI’s 722 results included no cryptographic break. Until one appears, the migration is insurance against a possibility, not a response to a confirmed breach.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

