Science3 publishersAlso reported elsewhere2 min readPublished
Vitalik Buterin warns AI mathematics could weaken lattice cryptography within two years
Vitalik Buterin said AI-driven mathematics has a good chance of seriously weakening lattice cryptography within two years. He offered no demonstrated attack, and for teams adopting post-quantum schemes the forecast argues for lattice deployments built to be replaced.
The Scientist · Science desk

What happened
- Buterin was responding to Ethereum Foundation researcher Justin Drake, who had called on the industry to start planning for what he called "bunker mode."
- Buterin singled out ML-DSA, fully homomorphic encryption and other lattice systems, which developers had treated as safe while elliptic curves were expected to face serious quantum problems.
- Ethereum's lean roadmap avoids the lattice signature schemes ML-DSA and Falcon where possible and uses the hash-based schemes WOTS and SPHINCS- instead.
- An address that has never signed a transaction keeps its public key hidden, and both Buterin and Drake see value in holding funds at such addresses.
Compiled by The ScientistSomething wrong?How this is made
Why it matters
- constraint Teams moving public-key encryption to post-quantum schemes cannot copy Ethereum's hash-only route, so they carry the lattice risk Buterin describes without that fallback.
- exposure Funds in addresses that have already signed a transaction have public keys on view, so those holdings are the ones within reach if attacks on elliptic curves improve, from quantum machines or AI-found shortcuts.
- decision Large holders face a planning decision with no deadline attached, since Buterin and Drake both favour fresh addresses and both want any move to be controlled.
"There is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math," Buterin said in a post on X on October 8 [15][1]. He said the industry needs to take AI-accelerated attacks on cryptography more seriously, alongside the older threat from quantum computing [3]. The cryptotimes.io report is explicit that he is not claiming these systems have already been broken. His concern is that AI could help researchers find mathematical shortcuts that have stayed hidden from humans [16].
His case rests on precedent. Over several decades, researchers developed more and more efficient methods for attacking factoring problems, and he said similar discoveries could be waiting for elliptic curves and lattices [7]. The factoring record shows that attacks on a structured problem can keep improving for a long time. The thing it doesn't tell you is how large the hits to lattices would be, or when they would come. The report does not include an estimate of lost security for any scheme, or an example of an attack found by an AI system.
Ethereum has been acting on the worry for a year. "This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the 'hash-only' direction," he wrote [8]. The approach uses hash-based constructions wherever they can do the required job, so the system depends less on mathematical structures that could contain weaknesses nobody has found yet [10]. It has a hard limit. Hashes cannot replace every form of cryptography, and public-key encryption, used in secure communications and privacy systems, needs some mathematical structure [11].
I think the evidence supports treating a lattice deployment as provisional, chosen with a plan to replace it if the cryptanalysis moves. It does not show that any lattice scheme in use today needs replacing. Buterin's own forecast is phrased as a chance [15].
His wallet advice also favours preparation over haste. "I don't recommend anyone scramble to move their funds to new wallets today," Buterin wrote [2]. He added: "If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea" [13]. Drake, whose proposal came before the post, had suggested that large holders consider moving funds to fresh addresses, and he warned that the process should be controlled [14][4].
What to watch
- Published cryptanalysis, AI-assisted or not, that lowers the security estimates for ML-DSA, Falcon or other lattice parameter sets.
- Whether Drake's "bunker mode" turns into a scheduled Ethereum plan for moving funds to fresh addresses.
- Whether other projects follow Ethereum in choosing hash-based signatures such as SPHINCS- over lattice schemes where they can.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence28
- Adoption20
- Hype gap+30
- Incentives45
- Confidence35
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Buterin made the comments in a post on X on October 8, urging crypto users not to panic over the possibility that AI could accelerate mathematical breakthroughs that challenge today's cryptographic systems.
- [2]
"I don't recommend anyone scramble to move their funds to new wallets today," Buterin wrote.
- [3]
Buterin said the crypto industry needs to think more seriously about the possibility of AI-accelerated attacks on cryptography, alongside the longer-standing threat posed by quantum computing.
- [4]
Buterin's comments came after Ethereum Foundation researcher Justin Drake called for the industry to begin planning for what he described as "bunker mode," including a controlled migration of funds to fresh addresses.
- [5]
Buterin specifically mentioned ML-DSA, fully homomorphic encryption and other lattice-based systems, and said developers have generally been comfortable with the idea that elliptic curves could eventually face serious problems from quantum computers while lattice-based cryptography would remain safer.
- [6]
Lattice-based cryptography has been widely considered a promising approach for systems designed to withstand quantum attacks.
- [7]
Buterin pointed to the history of factoring, where over several decades researchers developed increasingly efficient methods for attacking factoring problems, and said there could be similar discoveries waiting to be found for elliptic curves and lattices.
- [8]
"This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the 'hash-only' direction," Buterin wrote.
- [9]
Buterin said Ethereum's roadmap avoids lattice-based systems such as ML-DSA and Falcon where possible and uses hash-based signature schemes including WOTS and SPHINCS-.
- [10]
The hash-only approach seeks to rely more heavily on hash-based cryptographic constructions where they can perform the required function, reducing dependence on mathematical structures that could contain weaknesses not yet discovered.
- [11]
Hashes cannot replace every form of cryptography; public-key encryption, used in secure communications and privacy systems, requires some form of mathematical structure, so the challenge extends beyond Ethereum and the crypto industry.
- [12]
Keeping funds in unused addresses has a benefit because the public key remains hidden until the address is used to sign a transaction.
- [13]
"If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea," Buterin wrote.
- [14]
Drake suggested that large holders consider moving funds to fresh addresses whose public keys have not been exposed through previous transactions, and warned that the process should be controlled rather than rushed.
- [15]
"There is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math," Buterin said.
- [16]
Buterin's concern is not that lattice systems have already been broken; rather, AI could help researchers find mathematical shortcuts that have remained hidden from humans.
Sources
3 independent publishers whose own reporting we read for this story.
- cointelegraph.comVitalik Buterin says “we should take the risks to cryptography from AI-accelerated math seriously”, backing a “bunker mode” call for the blockchain industry
1 article · October 7, 2026
- cryptoslate.comVitalik Buterin urges calm as AI raises new fears over Bitcoin and Ethereum cryptography security
1 article · October 8, 2026
- cryptotimes.ioVitalik Buterin Warns Against Rushed Wallet Moves as AI Raises Crypto Risks
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Lattice-based cryptographyFollow
- AI for MathematicsFollow
- Hash-Based SignaturesFollow
- Post-Quantum CryptographyFollow