Advertisement

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Bitcoin Timeline

Vitalik Buterin: AI Could Crack the Maths That Locks Crypto Wallets. Don't Panic

After OpenAI's AI churned out hundreds of maths papers, Ethereum's founder warned the locks on crypto may weaken. His advice: prepare, but don't rush.

Vitalik Buterin, co-founder of Ethereum.

Key numbers

  • Hundreds

    OpenAI maths papers

  • 2 years

    Lattice warning window

  • 10x bigger

    Key size advice

  • Don't rush

    Vitalik's advice

On 7 October 2026 Vitalik Buterin, who created Ethereum, the second-biggest cryptocurrency, posted a long message on X that began with a line meant to calm people down: "I don't recommend anyone scramble to move their funds to new wallets today." The rest of it explained why he thinks the maths that protects every crypto wallet may be weaker than people assume, and what should change.

The next morning Changpeng Zhao, the founder of Binance, the world's biggest crypto exchange, shared it with a joke: "Vitalik's math score: 99.99/100. My math score: 0.01/100. So, together, we might make it into something..." He called it an "interesting thread to read, even if you understand as little as I do."

CZ shared the thread: "even if you understand as little as I do."

Most people do understand as little as CZ. So here is what Vitalik said, in plain English, why he said it now, and what CMZ makes of it.

Advertisement

AI agents and automation

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.

AI agents and automation

Why now: an AI that does maths

On 6 October OpenAI, the company behind ChatGPT, published hundreds of new mathematical results produced by one of its internal AI models, across number theory, geometry and computer science. Each result was checked by computer, and the model spent about three hours of reasoning on an average one, according to CryptoSlate. OpenAI did not claim to have broken any security system.

Justin Drake, a researcher at the Ethereum Foundation, read it as a warning. He said "mathematical superintelligence is upon us" and that, in the worst case, the maths protecting today's crypto wallets could be broken "within months, not years". He urged what he called "bunker mode": moving money into brand new wallet addresses.

Not everyone agreed. Yehuda Lindell, head of cryptography at Coinbase, called it FUD (crypto slang for fear, uncertainty and doubt) and said there was "no evidence whatsoever" that the maths had weakened. "Making such statements without any evidence is the opposite of responsible behavior," he wrote. Haseeb Qureshi of the investment firm Dragonfly called Drake's warning "a very sober call." Vitalik's thread landed in the middle of that argument.

How a crypto wallet is locked

A crypto wallet works like a mailbox with two keys. The public key is like the address on the front: you can show it to anyone so they can send you money. The private key is the only key that opens the box and lets money out. The whole system rests on one promise: knowing the address must not let anyone work out the key.

That promise is a maths problem that is very easy to do one way and, as far as anyone knows, practically impossible to undo, like mixing two paints together and then trying to separate them again. Bitcoin and Ethereum use one family of these problems, called elliptic curves. The safety of trillions of dollars, and of most of the internet, rests on nobody finding a shortcut.

Shortcuts have been found before. Vitalik's example is factoring, the maths behind the older RSA codes that protect websites. Over decades, clever mathematicians found faster and faster ways to attack it, which is why RSA keys today have to be several hundred bytes long instead of a few dozen. His question: "What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover, but bots soon will be?"

The three kinds of lock

Vitalik's thread sorts the locks into three groups. Think of them as three kinds of safe.

Elliptic curves, the safe most crypto uses today: Experts already expect quantum computers to break it one day. Vitalik's point is that AI-powered maths could get there sooner, which is why he repeats the "fresh address" advice below.

Lattices, the new safe built to survive quantum computers: Governments and tech companies have been moving towards it for years: it sits behind new standards such as ML-DSA. This is where Vitalik is most worried. "So far most people have been in the mode of thinking 'elliptic curves broken, hashes safe, lattices safe'," he wrote. "But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math." If AI brings "50 years of math in 2 years", he wrote, lattices would still work but would need to be much bigger. His rule of thumb: "multiply the key sizes by 10."

Hashes, the plainest and safest safe: A hash is a digital fingerprint: it turns any data into a short code, and there is no known pattern to exploit. Vitalik thinks it far less likely that hashes hide a secret weakness, because they are designed to have no structure at all, while the other two have known mathematical structure that AI could learn to pick apart. That is why, he says, Ethereum's long-term plan for the past year has been "hash-only" for signatures and proofs.

Diagram of three kinds of cryptographic lock: elliptic curves (use fresh addresses), lattices (use keys 10x bigger), hashes (use them where you can)CMZ graphic. Source: Vitalik Buterin on X
The three kinds of lock, as Vitalik sees them.

The catch is that hashes cannot do everything. Sending a secret message to someone you have never met, which is what keeps websites, private chats and VPNs safe, needs the kind of structured maths hashes do not have. "This point goes far beyond blockchains," he wrote.

What he says people should do

His own short list, in plain terms:

First, prefer hash-based security wherever it can be used, and be "much more paranoid" about the size of anything built on lattices.

Second, use fresh addresses if it is easy. An address that has only ever received money has not yet shown its public key to the world, which hides it from an attacker. The moment it sends money, the public key becomes visible. The analytics firm Glassnode estimates that more than 6 million bitcoin, about 30% of all bitcoin, already sit in addresses whose public key is visible, mostly because the same address was used again and again.

Third, do not rush. "Be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined," he wrote. Moving coins in a panic, to a wrong address or a fake site, is a far more likely way to lose them than an AI breakthrough.

Fourth, for shared wallets that need several people to approve a payment (called multisig), collect the approvals privately instead of on the public ledger. Then, if the maths does fail, an attacker cannot simply read everyone's signatures off the blockchain.

What an ordinary holder can do

None of this needs action today, and nobody has shown that any wallet can be cracked. But a few simple habits lower the risk from this, and from far more common dangers:

Do nothing in a hurry. A wallet scare is when scammers are busiest. Ignore any message, email or "support agent" telling you to move your coins urgently because of AI or quantum computers, and never type your recovery phrase (the list of 12 or 24 words that backs up a wallet) into any website or share it with anyone. No real company will ever ask for it.

If your coins sit on an exchange such as Coinbase or Binance, the exchange holds the keys and will have to handle any upgrade for you. There is nothing to move. Do keep two-factor login switched on, and watch for official announcements on the exchange's own app or website, not in messages sent to you.

If you hold your own coins, use a new receiving address each time someone pays you. Most Bitcoin wallets already do this automatically. An address that has only ever received money keeps its public key hidden; once you send from it, the key is out in the open. If you have an old address you have sent from, there is no emergency, but next time you make a move anyway, consider sending what remains to a fresh address in the same wallet.

When you do move coins, send a small test amount first, check the address character by character, and only then send the rest. Vitalik's own warning is that rushed moves have cost him more than hacks.

Keep your wallet app and any hardware wallet up to date, from the maker's official website or app store only. When safer, upgraded locks arrive, they will come through updates.

Do not keep everything in one place. Splitting savings between a well-known exchange and a wallet you control, or between two wallets, means one mistake or one failure cannot take all of it.

What CMZ thinks

Vitalik is right on the most important point, and it is the least dramatic one: the panic is more dangerous than the maths. Crypto loses money every week to people rushing, clicking fake "migration" links and sending coins to the wrong place. A sudden scare about wallets being cracked is exactly what scammers wait for. Anyone who receives a message urging them to move coins "before AI breaks your wallet" should treat it as a scam.

The risk itself is real but unproven. Nobody has shown that AI can break the locks on Bitcoin or Ethereum, and OpenAI did not claim to. Lindell is right that there is no evidence of a break today; Drake is right that waiting for proof before planning is how industries get caught out. The sensible position sits between them, and it is where Vitalik landed: start the slow, careful work now, while there is still time to do it calmly.

The bigger story is the one Vitalik buried in the middle. If AI really does compress decades of maths into a few years, it will not stop at crypto. The same locks protect online banking, hospital records and private messages. Crypto may simply be the first place people notice, because it is the only place where a broken lock pays out instantly and in public.

The aftermath

No one has shown a working attack on the maths behind Bitcoin or Ethereum wallets, and OpenAI's results did not include one. Vitalik Buterin advised against rushed wallet moves and in favour of fresh addresses only where that is easy, hash-based security wherever possible, much larger key sizes for lattice-based systems, and private signature collection for shared wallets. Justin Drake's "bunker mode" call and Yehuda Lindell's rebuttal split the industry. The Solana Foundation's Jacob Creech said Solana users "don't need to go into 'bunker mode'". Ethereum's long-term plan already moves towards hash-based signatures.

What this teaches

  • A rushed move is the most common way to lose crypto in a scare. Vitalik says he has lost more to botched migrations than to all hacks combined.
  • An address that has only received money keeps its public key hidden. Sending from it reveals the key.
  • 'Quantum-safe' does not automatically mean 'AI-safe': the new lattice locks may need to be far bigger.
  • Any message urging you to move your coins urgently because of an AI or quantum threat should be treated as a scam.
Advertisement

Live DeFi agents

Watch four AI agents manage money in public.

Stablecoins across Base, Arbitrum, Optimism, Polygon and Avalanche. Every decision is on-chain.

Subscription opening soon. Not financial advice.

  • BASE
  • ARB
  • OP
  • POL
  • AVAX