Technology & Security

Justin Drake Warns AI Could Threaten Wallet Keys Within Months

Ethereum’s Justin Drake urges calm preparation for possible AI-driven attacks on wallet signatures, without presenting a demonstrated key-recovery attack.

Justin Drake Warns AI Could Threaten Wallet Keys Within Months
Ethereum researcher Justin Drake, pictured at TechCrunch Disrupt Berlin in 2019, is urging the crypto industry to prepare for possible AI-driven advances against wallet signatures. Photo: Noam Galai / Getty Images for TechCrunch

Key Notes

  • Justin Drake urges calm preparation for a hypothetical AI-assisted breakthrough against wallet signatures, with months as his worst-case timeline.
  • Fresh addresses can limit public-key exposure in some designs, but Bitcoin Taproot shows why address rotation is not a universal solution.
  • His warning presents no demonstrated key-recovery attack and calls for preparations beyond Ethereum’s existing quantum-resilience roadmap.

Ethereum Foundation researcher Justin Drake is urging the crypto industry to prepare for a worst-case scenario in which AI-assisted mathematical advances threaten wallet signatures within months. His warning concerns the possibility of recovering private keys from public keys, rather than an attack he has demonstrated.

In an October 7 post, Drake called for calm planning around what he termed “bunker mode.” He defined the feared breakthrough as recovering a private key in roughly a week on available hardware, such as a large GPU cluster. That example describes a hypothetical attack threshold, not a published performance result.

A Warning About the Mathematics Behind Wallet Keys

Many crypto wallets rely on elliptic-curve cryptography to authorize transactions. A private key creates a signature, while a corresponding public key allows others to verify it. The security assumption is that knowing the public key does not make calculating the private key practical.

Drake’s concern is that AI could help researchers discover mathematical shortcuts that undermine that assumption. His post does not provide a working key-recovery algorithm, reproducible benchmarks or evidence that a wallet was compromised through such a breakthrough.

The distinction matters when comparing his warning with quantum computing. Shor’s algorithm addresses factoring and discrete logarithms using a quantum computer. It is not an existing technique that can simply be moved onto a conventional GPU cluster. A classical counterpart capable of the attack Drake describes would require a different mathematical advance.

This is also a different threat from AI making phishing messages more convincing or helping attackers find software bugs. Those attacks can compromise a wallet without defeating its underlying cryptography. Drake’s scenario instead challenges the mathematical protection separating a public key from the secret needed to spend funds.

Why an Address Is Not Always a Public Key

Ethereum’s account documentation explains that a conventional externally owned account has a public and private key, while its address is derived from a hash of the public key. An address therefore does not directly disclose the complete public key. Transaction and message signatures can reveal enough information to recover that public key.

This explains the reasoning behind Drake’s proposed precaution: a fresh address that has never signed anything can retain an additional barrier if its public key has not been exposed elsewhere. A fresh address is not equivalent to a new signature algorithm, however, and an address’s transaction history alone does not describe every possible exposure.

Bitcoin requires another distinction. The Taproot specification places a public key directly in the transaction output and uses Schnorr signatures. For that design, an address does not need to have spent funds before a public key is visible. The value of address rotation consequently depends on the asset and output type; it is not a universal shield for every wallet.

What Drake Means by Bunker Mode

Drake favors a controlled migration, beginning with sophisticated holders, toward appropriate addresses whose public keys remain hidden. He also advocates moving remaining funds after signing and notes that fresh addresses can come from the same seed phrase. He explicitly cautions against rushing, arguing that a hurried migration could do more harm than good.

His post names Binance, Bitbank, Robinhood, Bitfinex and Tether as large holders that could strengthen cold-storage defenses. It does not establish that these companies have suffered this kind of compromise or that they have adopted his recommendations.

The operational question is broader than generating another address. A custody process must account for which signing systems it uses, how public keys become visible and whether changing addresses actually changes that exposure. Ethereum contract accounts also follow their code rather than possessing a private key of their own, making a single address-rotation recipe an incomplete description of wallet security.

Hash-Based Signatures Provide an Established Research Path

Alternative signature systems are already part of formal cryptographic standards. In August 2024, the U.S. National Institute of Standards and Technology finalized SLH-DSA, a stateless hash-based digital signature standard based on SPHINCS+. Drake favors a longer-term direction built around hash-based cryptography.

NIST also standardized ML-DSA, which uses module lattices. That broader standards work is important context: Drake’s preference for hashes should not be read as a consensus finding that every other approach has failed. Nor does a post-quantum designation prove immunity to every future AI-assisted discovery.

Replacing a blockchain’s signature system is a separate undertaking from moving balances between addresses. Address rotation can change what information is exposed; changing the cryptography changes the security assumptions themselves.

A More Urgent Scenario Than Ethereum’s Existing Roadmap

The Ethereum Foundation’s September protocol priorities set a December 2029 target for quantum resilience across Layer 1 execution, consensus and data. That quantum roadmap uses a conservative planning assumption rather than a prediction that existing cryptography will fail on a particular date.

Drake also sits on the quantum-computing advisory board that Coinbase established in January. The company’s announcement described work to assess the threat and guide preparations. That initiative addresses quantum risk; it does not independently validate the AI timeline outlined in his latest post.

Drake is now arguing for faster preparation against a possible mathematical surprise. His warning does not announce an approved Ethereum deadline change. The unresolved questions remain whether such a breakthrough will occur, how quickly it could become practical and which cryptographic systems it would actually affect.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security