Ethereum Wallet Security: AI Math Sparks 'Bunker Mode' Call

Ethereum Wallet Security: AI Math Sparks 'Bunker Mode' Call

Crypto has long had a short list of threats that could undermine its basic security model. Quantum computers usually top that list. Two well-known Ethereum researchers are now pointing to a different and possibly faster risk: AI systems that are getting better at advanced mathematics.

In the worst case, they warn, AI-assisted math could break the signature system that protects crypto wallets within months. No one has done this yet. The fact that the people who build and maintain Ethereum are discussing it openly is still worth noting.

The warning from Justin Drake

Justin Drake, a prominent Ethereum researcher, posted on X calling on the blockchain industry to prepare what he called a "bunker mode." His proposal is a defensive posture to use if the cryptography behind wallet signatures starts to look shaky.

His main recommendation is simple. Users should move funds to addresses that have never signed a transaction.

The reason has to do with how wallet addresses work. When a wallet signs a transaction, it reveals its public key. In theory, an attacker could use that public key to work out the matching private key, which is the secret that controls the funds. Anyone holding the private key can move the money.

An address that has never signed anything only exposes a hash of its public key. A hash is a one-way transformation, so the key cannot be recovered from it. If the signature math were broken, funds sitting behind an unrevealed public key would still be protected. Funds in addresses that have already signed would not.

Buterin agrees, with a caveat

Ethereum co-founder Vitalik Buterin replied to Drake's post and largely agreed with the concern. He also urged caution about moving too quickly.

His reasoning comes from experience. Buterin said he has lost more money to botched migrations than to hacks. Shifting funds between addresses, contracts or systems carries real operational risk: wrong addresses, buggy tooling, missed steps. A rushed migration done out of fear could cause more damage than the attack it is meant to prevent.

Not even "quantum-safe" is safe enough

Buterin's longer-term view goes further than the immediate wallet question. He argues for a system architecture that relies as much as possible on hash functions alone.

This matters because the industry's usual answer to future cryptographic threats has been to move toward lattice-based schemes, which are often described as quantum-safe. Buterin's point is that these schemes are built to resist quantum computers, not mathematical progress in general. If AI can speed up the discovery of new mathematical attacks, lattice-based cryptography could also be weakened. Hash functions, in his view, are the more durable foundation.

Where things actually stand

The current signature scheme, ECDSA, has not been broken in practice. The debate is about how fast the risk could arrive, not about an attack that has already happened.

That is why the two positions fit together. Drake is focused on preparation and what users can do if things go wrong quickly. Buterin agrees with the direction but wants to avoid creating a self-inflicted crisis through hasty moves.

Our Take

This exchange suggests a change in how security people think about AI. Most AI security talk so far has been about models writing malware, finding software bugs or helping attackers work faster. There are recent examples of AI hacking tools helping a single attacker do work that once needed a team. Drake and Buterin are describing something different: AI attacking the mathematical assumptions under a system, not the code on top of it.

That concern did not appear from nowhere. AI models have been producing more serious mathematical work, including a batch of AI-generated proofs published by OpenAI. If models keep improving at this kind of reasoning, it seems reasonable for cryptographers to ask which "hard problems" are as hard as they assumed.

For readers who hold crypto, the practical lesson is mixed. Drake's advice about never-signed addresses is easy to understand. Buterin's warning about migration mistakes is just as relevant. Panic moves carry their own risk.

It is worth watching whether other blockchain projects take up the "bunker mode" idea, whether Ethereum's roadmap moves more clearly toward hash-based designs, and whether any credible research shows AI making real progress against ECDSA or lattice schemes. For now, this is a warning about a possible risk, not evidence that one has arrived.