Skip to content

Invest2 publishersAlso reported elsewhere3 min readPublished

Justin Drake tells large crypto holders to move to fresh addresses before AI can break ECDSA

Ethereum Foundation researcher Justin Drake says AI could break ECDSA in "months not years" and wants large holders on fresh addresses now. Custodians would bear most of the cost, and his evidence is a single AI math result.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Justin Drake tells large crypto holders to move to fresh addresses before AI can break ECDSA
Generated illustration

What happened

  • He called on Binance, Bitfinex and Tether to lead, with large holders moving first in a calm, deliberate order.
  • For signers securing large value or critical infrastructure, he recommended frequent key rotation and hash-based multi-signing schemes such as SPHINCS.
  • On bitcoin, he pointed to Project11's risq list for tracking exposed public keys and said wallets under roughly 50 BTC have partial protection.
  • Traders and exchanges showed little visible concern after the October 7 post on X, according to Crypto Briefing.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Frequent key rotation is a recurring operating expense for custodians, unlike a one-time address move, and it is being requested against a threat no one has demonstrated.
  • exposure Coins in reused or long-active addresses, whose public keys are already on-chain, are the ones a break would reach first.
  • decision The named exchanges now have to choose between spending on migration now and staying on the quantum timetable the industry had been planning around.

Drake's case for a short clock rests on one exhibit. He cited OpenAI's recent mathematical work, including a disproof of the Erdos unit distance conjecture [4]. From it he said AI-powered reasoning could break ECDSA "months not years" before qday, the industry's name for the arrival of a quantum computer strong enough to do it [15][3]. The exhibit is a result on a different problem. Drake framed the outcome as a potential crisis, and no one has announced that ECDSA is broken [16].

On the day, the market priced the warning at roughly zero, judging by the lack of any immediate reaction reported by Crypto Briefing [12]. Whether that is the right value depends on the odds of a break within months, and the account of Drake's post does not include an estimate of them.

The cost of acting is uneven. A holder whose coins already sit in an address that has never signed pays nothing extra, because the public key an attacker would need is not visible [5]. Exposure concentrates in reused addresses and long-active wallets [13], and in custodians, whom Drake wants rotating keys frequently and moving to hash-based multi-signing such as SPHINCS [7]. A migration is one transaction. Frequent rotation is a standing line in an operations budget, paid every period whether or not the attack comes.

If no AI result against ECDSA arrives, early movers have paid early for work the quantum transition needs anyway. Hash-based cryptography is already part of Ethereum's long-term roadmap discussions, and Drake has argued for years for moving off traditional cryptographic assumptions [11]. If a break lands inside his window, the losses fall on coins whose public keys are already on-chain [13]. In the slower version, AI progress shortens the timetable for classical and quantum attacks alike, both of which Drake said recent AI gains should push the industry to discuss faster [14], and there is no single day on which anything breaks.

I think the market's zero is defensible on the evidence Drake cited, and the individual move is cheap enough to make anyway. The open question is whether custodians will take on a recurring cost on the strength of one demonstration. The counter-case is that the first public sign of an AI break could be a theft instead of a paper. By then the calm, ordered migration Drake asked for, largest holders first [6], is no longer on offer.

A published AI-assisted method that cuts the work of deriving a private key from a public key, the assumption ECDSA rests on [3], would show the market wrong. Binance, Bitfinex or Tether starting the migration Drake asked them to lead [8] would show it changing its mind.

What to watch

  • Whether Drake or another Ethereum Foundation researcher attaches a probability or a dated estimate to the AI-break scenario.
  • Project11's risq list: a falling count of exposed bitcoin public keys would show large holders acting on the advice.
  • Whether Ethereum's long-term roadmap brings forward its move to hash-based signatures.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories