Skip to content

InvestNot yet confirmed elsewhere1 publisher2 min readPublished

Ava Labs puts an internal team on hash-based backups for Avalanche's ECDSA signatures

Ava Labs has an internal group studying hash-based signatures as a fallback for Avalanche's ECDSA, CEO Emin Gun Sirer said on October 9. Nothing is scheduled for the protocol, so the effort is a hedge against a failure Sirer ranks behind ordinary code bugs.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Ava Labs puts an internal team on hash-based backups for Avalanche's ECDSA signatures
Generated illustration

What happened

  • Ava Labs is also weighing Haseeb Qureshi's proposal for a "cryptographic recovery mode", an alternative cryptosystem Avalanche could integrate if ECDSA fails.
  • Sirer places the nearer danger in the blockchain software, libraries and wallets built on top of ECDSA, with the signature algorithm itself a lesser worry.
  • Avalanche, launched in 2020, authorizes transactions mainly with ECDSA on secp256k1, a curve configuration widely used across the industry.

Why it matters

  • cost Ava Labs is spending engineering time on a failure its own CEO ranks second, before any exploit has been confirmed.
  • exposure A credible break in secp256k1 would reach well past Avalanche, so its fallback work bears on every chain signing with the same curve.
  • decision If Sirer is right, the bigger security spend belongs on wallets, libraries and node software, where a new signature scheme offers no protection.

A recovery mode only helps if it cannot fail for the same reason as the scheme it backs up. Hash-based schemes get their security from hash functions instead of elliptic curve math, so a break in one would not automatically doom the other [5]. Avalanche has authorized transactions mainly through ECDSA on the secp256k1 curve since its 2020 launch [7], about six years on the same curve [14]. Qureshi's proposal would keep an alternative cryptosystem ready to integrate, to protect users if ECDSA fails [3].

So far the commitment is staff time on research. The protocol is untouched. Sirer said no immediate changes are coming to Avalanche, and no timeline or implementation details were offered for any upgrade [12]. Crypto Briefing did not report the group's size.

Calling this post-quantum planning fits only half the record. Sirer noted that talk about Avalanche's signature security has traditionally centered on long-term quantum resistance [9]. The hash-based group, though, is described as a precaution against vulnerabilities AI might exploit [4]. The debate behind his comments followed AI-driven mathematical advances and research from Ethereum's Justin Drake on AI speeding up breakthroughs against ECDSA [8]. In this account the risk being hedged is AI, and the work on both fronts is a fallback that would sit beside ECDSA until the day it fails [3][4]. One chain's internal research is also thin evidence of what large chains in general are doing.

If ECDSA holds, the research stays internal and its cost is the group's time. If a credible break arrives, coordination becomes the limit. Swapping the cryptography under a live chain needs developers, validators, wallet providers and users to move together [11]. Because secp256k1 sits under a large share of the crypto ecosystem, according to Crypto Briefing, Avalanche would be one of many chains trying that at once [10].

The third outcome is Sirer's own forecast. "We will see AI exploiting system-level bugs long before ECDSA goes away," he said [2]. In that case the losses come through the blockchain software, libraries and wallets built on top of the signatures [13].

I think Sirer has the order right on what is known. He noted there have been no confirmed exploits [6]. The case against him is lead time. A signature migration needs that four-way coordination [11], and a fix still at the research stage on the day of a break would arrive late. The view is wrong if a credible AI-assisted attack on secp256k1 is published before a major AI-found exploit hits wallet or node software.

What to watch

  • Whether Ava Labs publishes details of Qureshi's recovery mode, including how users would move to the alternative cryptosystem.
  • Whether the internal hash-based research turns into a protocol proposal with a date attached.
  • Whether other networks that rely on ECDSA begin openly studying similar fallbacks.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence35
Adoption
Insufficient
Hype gap0
Incentives55
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Emin Gun Sirer, founder and CEO of Ava Labs, the company behind the Avalanche blockchain, said on October 9, 2026 that AI is far more likely to exploit buggy software than to break ECDSA, and revealed Avalanche is exploring backup cryptography options.

    ReportedSupportedSource: Crypto Briefing reporting Sirer's remarksView cited source
  2. [2]

    "We will see AI exploiting system-level bugs long before ECDSA goes away."

    ReportedSupportedSource: Emin Gun Sirer, quoted by Crypto BriefingView cited source
  3. [3]

    Ava Labs is weighing a proposal from Haseeb Qureshi for a "cryptographic recovery mode", a backup crypto proposal envisioning an alternative cryptosystem that could be integrated into Avalanche to protect users if ECDSA ever fails.

    ReportedSupportedSource: Crypto BriefingView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cryptobriefing.com

    1 article · October 9, 2026

    Ava Labs explores backup cryptography as Sirer flags AI security risks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Hash-Based SignaturesFollow
  • Blockchain cryptography securityFollow
  • AI cybersecurity riskFollow
Loading related stories