A new warning from a prominent Ethereum researcher has set crypto on edge. Justin Drake of the Ethereum Foundation says artificial intelligence, not quantum computers, may be the first real threat to the cryptography protecting Bitcoin and Ethereum wallets, and in the worst case, he argues, a break could come "in months, not years." He's urging the industry to calmly prepare for "bunker mode." But there's a crucial caveat: no actual attack has been demonstrated, and the industry is sharply divided, with Coinbase's head of cryptography flatly calling it "FUD." Here's exactly what Drake warned, why it matters, and how seriously to take it.

To be clear up front, because the headline sounds alarming: this is a worst-case conjecture, not a demonstrated capability. As of now, no practical attack on Bitcoin or Ethereum's wallet keys exists, and none appeared in the research reviewed by major outlets. What Drake is proposing is early, precautionary planning against a risk he believes is being underestimated, not a claim that anyone's coins are about to be stolen. Understanding that distinction is the whole story.

What Justin Drake actually said

On October 7, Drake posted on X that the Elliptic Curve Digital Signature Algorithm (ECDSA), the signature scheme Bitcoin and Ethereum use to prove a transaction was authorized by the rightful owner, could potentially be broken by advances in classical mathematics, accelerated by AI, before "Q-Day" (the point at which quantum computers become powerful enough to break today's encryption). "Elliptic curves feel especially vulnerable to superintelligence," he wrote, arguing their tidy mathematical patterns are exactly the kind of structure a powerful enough AI could learn to exploit.

His recommended response is deliberately calm: holders should gradually and in a controlled way move funds to fresh addresses whose public keys have never been exposed on-chain, what he calls "bunker mode." Crucially, this requires no new cryptography or new wallets; it's a behavioral change available today.

Why a "fresh address" protects you (the key mechanic)

Here's the plain-English version of why Drake's advice works. On Bitcoin (non-Taproot) and Ethereum, your address is a hash of your public key, not the public key itself. As long as you've never signed a transaction from an address, an attacker only sees the hash, and hashes can't be efficiently reversed by AI or quantum computers. But the moment you sign anything, your public key is revealed on-chain permanently, and from that point your security rests entirely on ECDSA holding up.

There's an important detail most coverage misses: a "signature" isn't only a transaction. It includes token approvals, dapp logins, and trading orders, too. That means the average active crypto user has essentially zero truly "unexposed" addresses, which is part of why Drake is raising the alarm now. (It's also worth noting Solana is structurally more exposed: a Solana address is the public key, with no hash layer, so "bunker mode" isn't possible there in the same way.)

The industry is sharply split

This is where honest reporting matters, because credible experts strongly disagree.

  • Coinbase says it's FUD. Yehuda Lindell, Coinbase's Head of Cryptography, said there is "no evidence whatsoever" that the decades-old hardness assumptions behind elliptic-curve cryptography have weakened, calling Drake's warning "the very definition of FUD" and noting AI's recent math achievements are no evidence against ECDSA.
  • Dragonfly calls it sober. Haseeb Qureshi, managing partner at Dragonfly, called it "a very sober call," agreeing the real risk isn't quantum but AI-assisted mathematical breakthroughs undermining the assumptions crypto relies on.
  • Vitalik Buterin urges caution without panic. Ethereum's co-founder backed taking the risk seriously, writing that the industry should "minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography", while cautioning against rushing.

The disagreement is genuine and goes to the heart of a hard question: how much weight to give an expert's extrapolation and intuition when there's no proof of a break, only the accelerating pace of AI-driven math as circumstantial reason for concern.

How seriously should you take it?

A measured read, grounded in what's confirmed:

  • No attack exists today. This is a forward-looking risk assessment, not a live threat. Nobody's wallet is in danger right now.
  • The "months" figure is a worst case, not a prediction. Drake himself frames it as a conjecture, the tail risk to prepare against, not the expected outcome.
  • The fix is low-cost and available now. Using fresh, unexposed addresses and avoiding unnecessary key exposure is good hygiene regardless of whether Drake is right, so there's little downside to the cautious version of his advice.
  • The real work is long-term. Both Bitcoin and Ethereum would eventually need to migrate to new, "AI-resistant" cryptography (Drake favors hash-based schemes, which have less exploitable structure). The Ethereum Foundation already targets December 2029 for quantum-resistant cryptography; Drake's warning is essentially an argument to move faster.

Why it matters

Whether or not Drake turns out to be right, his warning reframes a debate the entire industry has been having. For years, quantum computing was treated as crypto's distant cryptographic threat, with "Q-Day" comfortably years or decades away. Drake's argument is that AI could get there first, by helping humans discover a classical mathematical shortcut, and that the timeline is therefore more uncertain than assumed. That's a genuinely important idea, even if his worst-case months-long timeline proves far too aggressive. For everyday holders, the takeaway is not to panic or make rushed moves (rushing is its own risk), but to adopt sound key hygiene and watch how the major chains respond. For the industry, it's a prompt to take post-quantum, and now post-AI, cryptography seriously and plan the migration carefully rather than reactively. The most credible voices disagree on the timeline, but they increasingly agree on the direction: the cryptography securing trillions of dollars won't stay static forever, and the networks that prepare early, without panicking, will be the ones still standing when the math finally catches up.