Technology & Security

Charles Hoskinson Challenges Vitalik Buterin’s AI Cryptography Warning

Cardano founder Charles Hoskinson disputes Ethereum co-founder Vitalik Buterin’s AI cryptography warning, saying delays to post-quantum migration could weaken internet security.

Charles Hoskinson Challenges Vitalik Buterin’s AI Cryptography Warning
Charles Hoskinson, pictured at Web Summit 2022, disputes Buterin’s assessment of AI risks and warns against delaying post-quantum migration. Photo: Piaras Ó Mídheach / Web Summit via Sportsfile

Key Notes

  • Hoskinson challenged Buterin’s case against lattice-based cryptography, calling for specific attacks and measurable costs to guide security recommendations.
  • Buterin’s original warning addressed possible AI-assisted breakthroughs while explicitly cautioning users against rushed wallet migrations.
  • NIST continues to recommend its finalized post-quantum standards, distinguishing them from a separate candidate weakened by AI research.

Cardano founder Charles Hoskinson has challenged Vitalik Buterin’s warning about AI-assisted attacks on cryptography, arguing that discouraging the use of established post-quantum systems could leave internet communications exposed for longer.

In an October 9 response on X, Hoskinson disputed the Ethereum co-founder’s case for favoring hash-based constructions over lattice-based alternatives. He called for specific attacks and measurable costs to underpin security recommendations.

The exchange concerns how engineers should prepare for possible mathematical breakthroughs. Neither post presents a demonstrated attack that recovers private keys from ordinary Bitcoin or Ethereum wallets.

Hoskinson Pushes Back on the Case Against Lattices

Hoskinson argued that known lattice attacks already inform the parameters of standardized systems. He rejected Buterin’s analogy with historical improvements in integer factoring as insufficient evidence that comparable shortcuts will emerge against lattices.

He also challenged a suggested tenfold increase in key sizes, saying adjustments should follow the complexity and cost of an identified attack. He accepted a role for hash-based signatures while disputing the idea that hash-based designs are free of mathematical assumptions.

His broader criticism was about research priorities. He accused Buterin’s public interventions of steering engineers away from useful work, citing Plasma, Ethereum 2.0 and Casper. Those examples are Hoskinson’s assessment of Ethereum’s development history.

Buterin Warned Against Rushed Wallet Moves

Buterin’s original post argued that AI could accelerate mathematical discoveries enough to reduce the security margins of lattice-based cryptography over the next two years. His concern included ML-DSA signatures, fully homomorphic encryption and, separately, the elliptic-curve mathematics behind conventional wallet signatures.

He favored hash-based constructions where feasible and more conservative parameters elsewhere. He connected that preference to the lean Ethereum research roadmap, rather than announcing that Ethereum mainnet had already replaced its cryptographic systems.

Buterin also explicitly advised against scrambling to move funds. As CoinScreamer’s earlier migration coverage explained, he supported reducing public-key exposure where practical but warned that mistakes during hurried transfers can themselves cause losses. His warning therefore combined a speculative threat assessment with an operational caution.

What the Existing Standards Actually Do

The dispute brings together systems that serve different purposes. NIST’s August 2024 standards announcement distinguishes key establishment from digital signatures.

ML-KEM lets two parties establish a shared secret over a public channel. That secret can then support encrypted communication. ML-DSA authenticates signed information and detects unauthorized changes. Both use lattice-based mathematics, but a signature system is not interchangeable with a key-establishment mechanism.

NIST also standardized SLH-DSA, a hash-based signature scheme derived from SPHINCS+. Its inclusion illustrates that post-quantum preparation already involves more than one mathematical approach. Choosing a signature family does not, by itself, settle how a website or messaging service should establish encryption keys.

The agency’s current guidance continues to encourage deployment of its finalized standards. It separately describes an AI-discovered weakness in HAWK, a candidate signature algorithm withdrawn from consideration, and says that finding does not affect ML-KEM or ML-DSA. A failure in one candidate therefore cannot be treated as proof that every lattice-based construction has failed.

Why the Debate Extends Beyond Crypto Wallets

The internet-security concern centers on data that can be intercepted today and decrypted later if an attacker eventually gains a sufficiently powerful technique or quantum computer. Long-lived confidential information can remain valuable long after the original connection ends.

Cloudflare’s technical review explains why key agreement and signatures require separate migrations. It describes deployed hybrid connections combining the conventional X25519 algorithm with ML-KEM, retaining protection from different cryptographic assumptions.

In that model, combining two systems is a hedge against weaknesses in either approach. Cloudflare also notes the practical limits of larger keys and signatures: additional data and processing can complicate deployment, while compatibility failures can slow adoption.

That context gives the argument a concrete engineering dimension. A theoretical improvement in safety has to be assessed alongside whether a proposed change works across browsers, servers and applications. The company’s review documents adoption and trade-offs; it does not resolve predictions about what AI will discover next.

Predictions Still Need Evidence

CoinScreamer’s recent Glassnode analysis likewise separated visible public keys from a demonstrated ability to compromise them. Measuring exposure, forecasting an attack and proving that an attack works are different steps.

For developers, the unresolved issue is how much additional safety margin to build into systems while continuing migration and research. Hoskinson’s response disputes the evidence behind Buterin’s recommendations; it supplies neither a guarantee that today’s designs will remain secure indefinitely nor a reason to treat wallets as already broken.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security