Ethereum co-founder Vitalik Buterin warned Wednesday that AI math could encroach on lattice cryptography, the leading post-quantum replacement, within two years.
He still cautioned holders against rushing funds into new wallets.
Buterin wrote on X that most planning assumes elliptic curves break, but hashes and lattices endure.
He named ML-DSA, fully homomorphic encryption and lattices as the key new risk areas. Same pressure could see ECDSA, the signature scheme behind Bitcoin and Ethereum wallets, fall sooner than expected.
After decades of human labor, breaking RSA keys is now cheaper, and Buterin asks if bots will soon find similar shortcuts against curves and lattices.
If AI delivers 50 years of math in 2 years, lattices will necessitate much larger keys for the same safety, he wrote. His rule of thumb for long-term security is to multiply key sizes by a factor of 10.
Ethereum’s lean roadmap has been hash-only for the last year, with signatures on WOTS or SPHINCS- and no ML-DSA or Falcon.
A secp256k1 ECDSA signature is about 64 bytes in size, whereas NIST’s finalized ML-DSA-87 signature is around 4,627 bytes.
Buterin was replying to Ethereum Foundation researcher Justin Drake. On Wednesday, Drake called on the industry to “calmly begin planning for ‘bunker mode.’”
Drake said ECDSA could break before q-day, the day quantum computers crack public-key cryptography. Worst case, it’ll be months, not years.
His plan is to move funds to addresses that have never signed a transaction, beginning with the largest holders. Such addresses conceal the public key behind a hash until the first signature.
Buterin backed fresh addresses only where the switch is easy. “I don’t recommend anyone scramble to move their funds to new wallets today,” he wrote, adding that he’s lost more money in failed migrations than in all hacks combined.
Privacy protocols should keep encrypted notes off the chain and send them via a third party, he said. For multisig wallets, off-chain confirmations help keep signer signatures out of public view.
Drake tied his warning to OpenAI’s release Tuesday of 722 manuscripts from an unreleased internal model, grouped into 372 families. Most proofs are in Lean, so a computer can verify them.
In July, Anthropic said its Claude Mythos Preview model cut the key strength of HAWK, a post-quantum signature candidate submitted to NIST, by 50% in 60 hours. Anthropic said the outcome doesn’t bear on live systems because HAWK was never deployed.
Cryptopolitan reports that, as of May 2026, Europol cited an on-chain count of 6.04 million BTC, about 30.2% of the supply, with visible public keys.