InvestNot yet confirmed elsewhere1 publisher2 min readPublished Updated
Buterin gives AI-driven maths a good chance of weakening ML-DSA within two years
Vitalik Buterin says AI-driven maths research has a "good chance" of significantly weakening lattice signatures such as ML-DSA within two years. His fixes put the cost on key sizes and multisig signing routines while steering holders away from mass fund migrations.
The Investor · Invest desk

What happened
- Buterin also flagged added risk for ECDSA, the widely used elliptic curve signature algorithm.
- Where lattice schemes stay in use, he suggested conservative parameters, including keys ten times larger where applicable.
- Ethereum's direction, as he described it, moves away from lattice cryptography toward pure hash-based signatures such as WOTS and SPHINCS+.
- No immediate price reaction or protocol exploit was reported after the warning.
Why it matters
- cost Protocols that keep lattice schemes on Buterin's terms carry ten times the key data per key, a storage and bandwidth bill they pay whether or not the attack ever comes.
- constraint Privacy features built on FHE lose the option of posting ciphertext on chain, since a weakening found later would expose data that can never be deleted.
- decision Treasuries, DAOs and custodians have to absorb a key rotation after every multisig operation instead of moving funds, so the cost falls on signer time and process.
- contradiction Lattice schemes were meant to be the quantum-safe destination, so a post-quantum plan built on ML-DSA may end up needing a second migration.
Two years is a short horizon for anyone holding keys, and the obvious response would be to move funds now. Buterin discouraged that, saying large-scale migrations carry their own risks [7]. The rest of his list puts the work into signing procedure. Multisig signers should switch to new keys after each operation and collect signatures offchain where possible [5], because a public key exposed on-chain gives a future attacker something to work with [9]. WOTS, one of the hash-based schemes he named, is built so that each key signs only once [11].
The case for hashes comes down to assumptions. Hash-based signatures lean on hash functions for their security [12], so progress against the geometry of lattices does not reach them. Lattice schemes were the field's main candidates for resisting quantum attacks [18]. If AI-driven maths erodes them first, protocols would be retreating from the tools they had been moving toward. Crypto Briefing cast the warning as a threat that might arrive before quantum computers do [17]. Buterin's own horizon, as reported, is two years, and the odds he gave were a "good chance" [1].
If AI-assisted cryptanalysis produces nothing material against lattice problems by October 2028 [16], protocols that kept lattice schemes at tenfold key sizes [3] will have carried ten times the key data [15] for protection they did not need. If the weakening arrives on his schedule, the teams that kept encrypted data off-chain are the ones whose privacy survives, since anything posted to a chain stays there permanently [4]. If the added risk he flagged for ECDSA [2] also materialises, a new parameter set does nothing for funds behind public keys already on chain [9].
Buterin was more optimistic a month earlier. In September 2026 he projected that AI-assisted formal verification could benefit cybersecurity [19]. Crypto Briefing wrote that AI which helps prove code correct may also help prove that certain encryption is weaker than advertised [20].
I think moving Ethereum toward hashes is the right hedge. It removes an assumption, and the multisig changes cost signer time without requiring any funds to move. The counter-case is that a "good chance" is one person's estimate, and the report cites no specific attack behind it. Tenfold keys and a roadmap change are real engineering spend against a risk that may not land. Buterin keeps the majority of his net worth in crypto assets [13], so his own money rides on the estimate. The thesis fails if October 2028 [16] arrives with no significant published result against lattice schemes such as ML-DSA [6].
What to watch
- Any published cryptanalysis, AI-assisted or not, that cuts the security margin of ML-DSA or other lattice schemes before October 2028.
- Whether Ethereum's roadmap commits to WOTS or SPHINCS+ for account signatures, and on what timeline.
- Whether large multisig treasuries and custodians adopt per-operation key rotation and offchain signature collection.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives35
- Confidence30
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On October 7, 2026, Buterin warned that AI-accelerated mathematical research has a "good chance" of significantly weakening lattice-based cryptography within two years.
- [2]
Buterin also flagged added risk for ECDSA, the widely used elliptic curve signature algorithm.
- [3]
Where lattice schemes are still used, Buterin suggested conservative settings, including a 10-fold increase in key sizes where applicable.
- [4]
Buterin advised against storing encrypted data directly on-chain; data posted to a blockchain stays there permanently, so if the encryption protecting it weakens later the privacy is gone for good.
- [5]
Buterin said multisig signers should switch to new keys after each operation and that multisigs should collect signatures offchain where possible.
- [6]
The lattice-based family Buterin warned about includes ML-DSA, a lattice-based signature scheme, and fully homomorphic encryption (FHE).
- [7]
Buterin discouraged large-scale migrations of funds, which carry their own risks.
- [8]
Buterin described a move away from depending on lattice cryptography and toward pure hash-based signature schemes, naming WOTS and SPHINCS+.
- [9]
Exposing a public key on-chain gives future attackers something to work with, and that exposure becomes more of a liability as AI and cryptanalysis techniques advance.
- [10]
No immediate price reactions or protocol exploits were reported after the warning.
- [11]
WOTS, the Winternitz one-time signature, is designed so that each key signs only once.
- [12]
Hash-based signatures rest on a simpler foundation, with security leaning on hash functions and fewer exotic math assumptions.
- [13]
Buterin keeps the majority of his net worth in crypto assets.
- [14]
For multisig operators such as treasuries, DAOs and custody setups, the advice is operational: rotate keys after each use, gather signatures offchain, minimize how often public keys hit the chain.
- [15]
A tenfold increase in lattice key sizes means each key carries ten times the data of the current parameter set.
- [16]
Two years from Buterin's October 7, 2026 warning is October 2028.
- [17]
Crypto Briefing framed AI that is very good at math as a threat that might show up sooner than quantum computers, on which most crypto security debates fixate.
- [18]
Lattice schemes have been widely discussed as candidates for resisting quantum attacks.
- [19]
In September 2026, Buterin projected that AI-assisted formal verification could benefit cybersecurity.
- [20]
AI that helps prove code is correct may also help prove that certain encryption is weaker than advertised.
Sources
1 independent publisher whose own reporting we read for this story.
- cryptobriefing.comVitalik Buterin warns AI could weaken the math behind crypto security
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.