Ethereum Researcher Justin Drake Urges “Bunker Mode” as AI Raises New ECDSA Risk
Ethereum Foundation researcher Justin Drake has urged the blockchain industry to begin calmly preparing for what he calls “bunker mode,” a preventative migration of crypto assets to fresh addresses whose public keys remain hidden.
In a post on X on Oct. 7, Drake warned that rapid advances in AI-driven mathematics could, in a worst-case scenario, accelerate attacks against ECDSA cryptography before the arrival of sufficiently powerful quantum computers.
His assessment does not claim that ECDSA has been broken. Instead, Drake argues that the possibility of a classical break occurring sooner than previously expected is now serious enough to warrant preparation.
His suggested response is deliberately measured: do not panic or rush a mass migration, but begin planning for one.
Drake’s “Bunker Mode” Proposal
The basic idea is to move assets from addresses whose public keys have already been exposed to fresh addresses where the public key remains hidden behind a cryptographic hash.
For large holders, exchanges and custodians, Drake recommends taking the lead in a controlled migration.
One practical approach he outlines is to move remaining funds to a new address after an address has been used to sign a transaction. The new address can be derived from the same seed phrase, meaning the precaution does not necessarily require new wallets or new cryptographic infrastructure.
The emphasis, however, is on preparation rather than evacuation.
Drake specifically cautions against rushing the process, arguing that a poorly executed migration could create more immediate risks than the cryptographic threat it is intended to mitigate.
That distinction is important because his warning is based on a worst-case scenario, not a claim that ECDSA is about to fail.
Why Public-Key Exposure Matters
ECDSA underpins the digital signatures used to authorize transactions across major blockchain networks, including Bitcoin and Ethereum.
For address types where the public key is revealed when an address signs a transaction, that key remains visible on-chain. If an attacker were eventually able to efficiently solve the underlying discrete-logarithm problem, the exposed public key could potentially be used to derive the corresponding private key.
Fresh, unused addresses provide a degree of protection because their public keys remain hidden behind a hash until the address is used.
That is the basis of Drake’s “bunker mode” recommendation.
The concern is therefore not simply whether a cryptographic algorithm is theoretically vulnerable. It is also which assets are already sitting behind publicly exposed keys and which remain shielded by the structure of the address.
Project Eleven’s Bitcoin Risq List tracks Bitcoin addresses with exposed public keys, highlighting the scale of assets that could potentially be affected by a future breakthrough in cryptanalysis.
AI Changes the Timeline Drake Is Worried About
Drake’s warning is tied to a development that would be separate from the quantum-computing threat that has traditionally dominated discussions around ECDSA.
Around Oct. 6–7, OpenAI released a large batch of AI-generated mathematical results, widely reported as numbering roughly 722 results.
The significance, in Drake’s argument, is not that those results have broken cryptography.
Rather, they demonstrate how quickly AI systems are beginning to contribute to mathematical research.
That raises a different possibility: that sufficiently advanced AI could discover mathematical techniques capable of attacking cryptographic assumptions using conventional computing hardware.
Drake describes the potential timeline in deliberately stark terms. In his worst-case assessment, a break could occur in months rather than years, potentially before the industry reaches the point commonly referred to as “Q-Day,” when quantum computers become capable of threatening widely used public-key cryptography.
No such break has been demonstrated.
The timeline is Drake’s own worst-case assessment, and the mathematical results that prompted his concern still require independent scrutiny and verification.
Why Elliptic Curves Are a Particular Concern
Drake’s argument also rests on the mathematical structure underlying different cryptographic systems.
Elliptic-curve cryptography contains substantial algebraic structure, while cryptographic hash functions are designed around properties that make their internal structure harder to exploit in the same way.
That distinction is one reason Drake has long favored moving toward hash-based cryptography for systems that can accommodate it.
His longer-term position is therefore not simply to protect existing ECDSA keys.
It is to accelerate the development and deployment of cryptographic systems designed to remain robust in a world where both AI and quantum computing can change the assumptions behind today’s security models.
For Ethereum, that includes accelerating work on hash-based signatures and formal verification.
Exchanges and Large Holders Are the First Line of Preparation
Drake’s recommendation is not aimed equally at every wallet.
He specifically argues that large and sophisticated holders should lead any controlled migration, including exchanges and custodians that manage substantial amounts of digital assets.
Load-bearing signers such as oracles and Layer 2 security councils also warrant particular attention because compromising their keys could affect systems beyond an individual wallet.
Drake suggests that these entities consider rotating keys or adding hash-based schemes such as SPHINCS where appropriate.
Smaller holders may have some additional protection from what has been described in the Bitcoin community as “Satoshi’s shield”: a large number of dormant holdings whose public keys have not been exposed in the same way.
Early Bitcoin holdings attributed to Satoshi Nakamoto are frequently cited in this context. Those coins remain unmoved, however, and their inclusion in the discussion does not mean they are currently being targeted or are under an active cryptographic attack.
Vitalik Buterin Agrees on the Risk, but Warns Against Panic
Ethereum co-founder Vitalik Buterin has also treated the possibility of AI-accelerated cryptographic advances as a risk worth taking seriously.
Buterin agreed that keeping funds in unused addresses can be sensible where doing so is straightforward, while warning against a rushed migration.
His caution reflects a more immediate operational risk: moving large amounts of cryptocurrency incorrectly can itself result in permanent losses.
Buterin has pointed to personal losses from botched transactions as an example of why hurried migrations can be dangerous.
He has also raised the possibility that AI advances could affect cryptographic systems beyond elliptic curves, including lattice-based approaches, reinforcing the argument for broader post-AI cryptographic planning rather than simply swapping one algorithm for another.
The Industry Is Not Facing an ECDSA Break Today
The most important qualification to Drake’s warning is also the simplest:
ECDSA has not been broken.
There is no demonstrated attack showing that an attacker can currently recover private keys from exposed Bitcoin or Ethereum public keys at practical speed using conventional hardware.
Drake is instead asking the industry to prepare for a scenario in which that assumption changes rapidly.
That is different from declaring an imminent cryptographic emergency.
His own language reflects that distinction. He calls for the industry to “calmly” begin planning, warns participants not to rush, and frames the proposed migration as preventative hygiene rather than an emergency evacuation.
The difference matters because a migration intended to protect funds can introduce its own operational vulnerabilities if carried out carelessly.
From Quantum Preparation to Post-AI Cryptography
For years, the blockchain industry’s cryptographic risk discussions have largely centered on quantum computing.
The basic concern has been that sufficiently powerful quantum computers could eventually undermine public-key systems that are secure against conventional computers.
Drake’s warning adds another variable to that equation: the possibility that advances in AI could accelerate mathematical breakthroughs before quantum computers reach that capability.
That does not make quantum risk irrelevant.
Instead, it broadens the timeline that developers and asset holders may need to consider.
The longer-term answer Drake advocates is a transition toward cryptographic systems that do not depend on assumptions he believes could become increasingly vulnerable as mathematical capabilities improve.
For Ethereum, that means continuing work on hash-based cryptography, formal verification and related post-quantum and post-AI security measures.
For asset holders, his immediate recommendation is considerably simpler: understand which keys are already exposed, avoid unnecessary reuse of those addresses, and prepare for a controlled migration rather than waiting for a cryptographic emergency.
The warning, ultimately, is not that blockchain cryptography has failed.
It is that the assumptions behind today’s security may change faster than the industry expects—and preparing before that happens is considerably easier than trying to migrate after it does.




