Vitalik Buterin Warns AI Could Break Ethereum (ETH) Key Security Within Two Years
Vitalik Buterin says AI could break lattice cryptography and ECDSA within two years, and Ethereum's Lean roadmap now leans on pure hash signatures.
AI SummaryAI
- Vitalik Buterin warned on October 8 that AI-driven math research could break lattice cryptography within two years.
- Buterin cited the GNFS algorithm, which cut RSA factoring complexity and forced keys from 64 to 400 bytes.
- Ethereum's Lean roadmap dropped ML-DSA and Falcon, moving signatures to hash schemes WOTS or SPHINCS-.
- Buterin advised keeping funds in addresses that have never signed a transaction, leaving public keys unexposed.
Vitalik’s Two-Year Lattice Warning
Ethereum (ETH) co-founder Vitalik Buterin warned on Thursday, October 8 that AI-accelerated mathematical research could severely damage the practical security of lattice-based cryptography within the next two years, a family of schemes covering ML-DSA and fully homomorphic encryption (FHE) and, in his estimate, potentially exposing ECDSA to a break earlier than planned. Nothing in the post claims a lattice scheme is broken today; the timeline is tied to research velocity, not to an announced result. In the October 8 post on X, he argued AI could compress the equivalent of 50 years of mathematical progress into two, and that the Ethereum Lean roadmap has already repositioned in response. The concern is not quantum computing itself but the mathematics underneath it. Buterin compared lattice schemes to the history of RSA and elliptic curves: RSA’s designers once treated brute-force factoring at 2^(n/2) as the ceiling, yet decades of human work produced the general number field sieve (GNFS), a smarter algorithm that cut the complexity to roughly 2^O(n^(1/3)) and pushed RSA key sizes from 64 bytes to about 400 bytes. His inference is that lattice problems may still carry undiscovered structural weaknesses that humans have simply not been clever enough to find, and that AI is the tool most likely to locate a smarter mathematical path into them. Two years, on his reading, is enough time for machine-assisted discovery to outrun the standards cycle. The warning also reframes why exposed keys matter. Every signature a wallet has ever produced is public on-chain, so a sudden cryptographic break turns historical exposure into a live target rather than a theoretical one. The debate over Ethereum price and protocol security has, in other words, shifted from distant quantum hardware toward a nearer, software-driven variable.
Lean Roadmap Bets on Hash Signatures
The answer he points to is Ethereum’s Lean roadmap, which over the past year has dropped its dependence on lattice cryptography: no ML-DSA, no Falcon, and no lattice-based commitments in zero-knowledge proofs. Signatures move to pure hash-based schemes such as WOTS or SPHINCS-, meaning every validator message in the network’s proof-of-stake design, along with its staking credentials, would eventually rest on them. His stated position is that wherever hash signatures are viable, pure hash beats lattice. He concedes a proof that P equals NP would break hash functions too, but rates that probability extremely low. Signatures, in this framing, are the solvable half; public-key encryption is the real bottleneck. Longstanding results show public-key encryption cannot be built from hashes alone; it needs a structured trapdoor, whether group theory, lattices, code-based encryption, or something not yet imagined. For long-term security he advises enlarging key lengths by a factor of 10: lattice schemes would survive on the two-year assumption, but only with far larger parameters, where pure hash then wins on efficiency. His advice for holders is deliberately unheroic. Keep funds, where convenient, in addresses that have never signed a transaction: a fast ECDSA break makes every exposed public key a target, while a never-used address has revealed nothing on-chain. He explicitly warns against rushing to migrate, noting he has personally lost more funds through botched migrations than to every hack combined. For multisig wallets, typically deployed as a smart contract, he recommends off-chain signature confirmation; if ECDSA fell quickly, such a wallet would degrade gracefully into a 1-of-1 controlled by the signature collector, far better than open access to the funds. The warning did not land alone. A Europol report some 24 hours earlier likewise named crypto wallets the main quantum risk, judging the hash functions that link blocks broadly quantum-resistant and the signature layer the weak point. Justin Drake had already urged a “bunker mode” posture against an AI break of ECDSA keys, and the Lean pivot continues the roadmap tradition behind the Ethereum 2.0 upgrade, alongside nearer-term items such as the Glamsterdam upgrade.
The Precondition: A Structural Breakthrough
The two-year horizon is conditional on a genuine mathematical event, not on hardware arriving on schedule. Nothing published today breaks ML-DSA or ECDSA; what has changed is the search speed for a GNFS-class weakness, and Buterin’s own framing treats that as a probability to insure against rather than a fact. The immediate, actionable half of the post is operational: fresh addresses, off-chain confirmation for multisigs, and restraint on migration, which he ranks above exploits as a realized source of loss. For the risk to arrive, someone, human or machine, first has to publish a structural weakness in lattice problems; until that paper exists, the Lean roadmap’s hash pivot is insurance against an uncertain deadline.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

