Ethereum co-founder Vitalik Buterin has backed the precautionary logic behind researcher Justin Drake’s call for the crypto industry to prepare for “bunker mode,” while warning against hurried wallet migrations. In an October 7 post, Drake urged large holders to begin planning controlled moves toward fresh addresses whose public keys have not been exposed. The proposal responds to a hypothetical AI-assisted cryptographic breakthrough, not evidence that ECDSA or production blockchain keys have already been compromised.
Drake’s warning followed OpenAI’s October 6 release of a broad collection of new mathematical results produced by an internal frontier model. OpenAI said many proofs were accompanied by Lean formalizations that can be checked computationally, while the average result consumed compute roughly equivalent to three hours of ChatGPT Pro thinking. Drake interpreted the rapid progress as reason to reconsider how long classical cryptographic assumptions can safely be treated as untouchable, describing a worst-case ECDSA break as potentially arriving in “months, not years.” That timeline is his assessment rather than an independently demonstrated capability.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Holders, starting with large…
— Justin Drake (@drakefjustin) October 7, 2026
Fresh Addresses Reduce One Potential Attack Surface
Drake’s proposed defensive measure centers on addresses that have never signed transactions. On Ethereum, an externally owned account that has only received assets exposes its address, which is derived from a hash of its public key, rather than publishing enough signature information to recover the public key. Once an account signs a transaction, that additional protection disappears, making an exposed public key theoretically more useful to an attacker if the underlying elliptic-curve problem were ever broken. Ethereum’s own post-quantum documentation describes the same distinction.
The situation is more nuanced on Bitcoin because different address types use different signature and key-exposure structures, including ECDSA and Schnorr-based Taproot. Drake nevertheless urged sophisticated holders and custodians to inventory exposed keys and consider fresh addresses where appropriate. That operational problem has already emerged in Bitcoin post-quantum planning for custodians and treasuries and in research tracking millions of BTC associated with already exposed public keys. Hiding a public key can reduce exposure to one hypothetical attack path, but it does not make an address permanently post-quantum or “AI-proof.”
Buterin supported taking AI-accelerated mathematics seriously but pushed against emergency action. In his response to Drake, he said keeping funds in unused addresses can make sense when doing so is straightforward, while emphasizing the danger of migration mistakes. His position is effectively risk balancing: reducing cryptographic exposure is useful only when the migration itself does not create a larger operational vulnerability.
Now, the quantum resistance roadmap.
Today, four things in Ethereum are quantum-vulnerable:
* consensus-layer BLS signatures
* data availability (KZG commitments+proofs)
* EOA signatures (ECDSA)
* Application-layer ZK proofs (KZG or groth16)We can tackle these step by step:…
— vitalik.eth (@VitalikButerin) February 26, 2026
AI Concerns Reinforce Ethereum’s Hash-Based Direction
Buterin also widened the discussion beyond elliptic curves. He argued that future AI-driven mathematical discoveries could potentially weaken the concrete security assumptions behind lattice problems such as LWE and RLWE, despite lattices forming the basis of several post-quantum standards. That is a warning about unknown mathematical shortcuts, not evidence that lattice cryptography has been broken. His preference remains hash-based constructions where practical because they deliberately minimize exploitable algebraic structure.
That preference already aligns with Ethereum’s longer-term roadmap. The network has a dedicated Post-Quantum Security team and is developing hash-based validator signatures, proof aggregation and cryptographic agility for accounts, with core post-quantum infrastructure targeted around 2029. The shift has also influenced Ethereum research decisions such as moving Layer 1 cryptography away from Poseidon toward established hash families and a broader roadmap covering post-quantum security, privacy and AI verification. Drake’s warning argues for accelerating an existing engineering program rather than inventing an emergency replacement for Ethereum’s cryptography.
For multisig systems, Buterin suggested that collecting signer confirmations offchain can reduce public exposure of individual signing keys. Drake similarly mentioned key rotation and pairing ECDSA with hash-based signatures for security-critical infrastructure such as oracles and Layer 2 councils. These are defensive architecture proposals, not evidence that ordinary wallets face an active key-recovery attack today.
The practical shift is therefore one of planning horizon. AI systems are demonstrating substantially stronger mathematical capabilities, while no public result currently shows a classical attack capable of recovering production Ethereum or Bitcoin private keys from exposed public keys. “Bunker mode” is best understood as a call for cryptographic agility, key inventory and controlled migration planning under uncertainty, not as an instruction for users to immediately move their assets.
