Buterin Warns AI Could Weaken Cryptography, Urges Calm
Vitalik Buterin, pictured at TechCrunch Disrupt SF 2017, urges preparation for AI-driven advances in cryptanalysis while cautioning against hurried wallet migrations. Photo: Steve Jennings / Getty Images for TechCrunch
Technology & Security

Buterin Warns AI Could Weaken Cryptography, Urges Calm

Vitalik Buterin warns that AI-driven mathematical advances could weaken cryptography, but says rushed wallet migrations can create risks of their own.

Make us preferred on Google

Key Notes

  • Vitalik Buterin warns AI-assisted mathematical advances could weaken lattice-based cryptography within two years, without claiming that a practical break has occurred.
  • He favors hash-based signatures and proofs while acknowledging that public-key encryption needs other mathematical assumptions.
  • He supports limiting avoidable public-key exposure, but cautions that rushed wallet migrations can introduce losses of their own.

Ethereum co-founder Vitalik Buterin says AI-assisted mathematical discoveries could weaken the cryptography protecting digital assets sooner than expected, but he is advising users against a hurried move to new wallets.

In a post on X, Buterin argued that preparation should address possible breakthroughs from AI as well as quantum computing. He sees a meaningful possibility that advances over the next two years will substantially reduce the security margins of lattice-based cryptography, rather than claiming that a practical attack has already been demonstrated.

His comments respond to Ethereum Foundation researcher Justin Drake’s warning about a worst-case scenario for wallet signatures. Buterin shares the concern about the underlying mathematics while emphasizing that an uncontrolled migration can create its own losses.

AI Creates a Different Route to Cryptographic Weakness

The concern is not simply that a larger AI system can guess every private key. It is that AI could help discover more efficient mathematical methods for attacking the problems on which a signature or encryption system relies.

That differs from waiting for a sufficiently powerful quantum computer. An AI-assisted advance could improve an algorithm running on conventional hardware. Whether such an advance will occur, and whether it would make an attack affordable, remain open questions.

Buterin identified ECDSA, the elliptic-curve signature scheme used by conventional Ethereum accounts, as another system that could face pressure sooner than anticipated. His post does not introduce a working method for recovering wallet private keys or establish a date when ECDSA will fail.

The distinction also separates this debate from AI-assisted phishing and software exploitation. Those attacks can steal funds without solving the mathematical problem behind a digital signature.

Lattice-Based Standards Face a Separate Question

Buterin’s particular concern extends to ML-DSA and fully homomorphic encryption, alongside lattice-based constructions more broadly. He questions the assumption that replacing elliptic curves with lattices necessarily provides a durable answer to every emerging threat.

ML-DSA is the module-lattice digital signature system specified in NIST’s FIPS 204, finalized in August 2024. NIST describes it as believed secure even against an adversary with a large-scale quantum computer. That assessment does not amount to a guarantee against every future mathematical discovery.

Homomorphic encryption serves a different purpose: it allows computation on encrypted information without first decrypting it, as Microsoft’s SEAL project explains. A digital signature authenticates an action; encryption protects the information being processed or exchanged.

Buterin’s two-year scenario concerns potentially significant improvements in attacks on the underlying mathematics. It does not mean that every lattice-based scheme would become unusable. His argument includes the possibility that larger parameters would be needed to maintain comparable protection, changing the efficiency trade-offs between cryptographic designs.

Ethereum’s Research Direction Favors Hash-Based Signatures

Buterin links those concerns to the lean Ethereum roadmap’s preference for hash-based signatures and proofs. Hash functions are intended to avoid the kinds of exploitable mathematical structure that make algebraic systems attractive targets for new algorithms.

Hash-based signatures are already an established standards category. NIST’s FIPS 205, also finalized in August 2024, specifies SLH-DSA, a stateless hash-based signature algorithm derived from SPHINCS+.

The Ethereum Foundation’s research roadmap describes work on hash-based validator signatures and proof-based aggregation, alongside ways for users to adopt post-quantum authentication. It presents the transition as a coordinated migration across protocol layers, subject to research and Ethereum’s governance process.

That work should not be confused with an announcement that Ethereum mainnet has already replaced its existing signature systems. Nor does Buterin argue that hashes are unconditionally immune to future discoveries.

He also draws a limit around the approach: signatures and proofs can be built around hashes, but public-key encryption still requires additional mathematical assumptions. The broader problem reaches secure communications and privacy services, well beyond blockchain wallets.

Fresh Addresses and Offchain Confirmations

For holders, Buterin favors reducing avoidable public-key exposure where doing so is straightforward. Ethereum’s account documentation explains that an externally owned account’s address is derived from a hash of its public key. Transaction signatures can expose information from which that public key is recovered.

Keeping funds at an address that has not signed transactions can therefore preserve an additional barrier, provided its public key has not been disclosed elsewhere. This depends on the wallet and blockchain design; an unused address is not a universal guarantee that a public key is hidden.

Buterin also prefers collecting multisig confirmations offchain, avoiding public disclosure of all participating signers’ signatures. In the failure scenario he outlines, the signature collector could still become a point of unilateral control. The proposal reduces one form of public exposure; it does not eliminate every trust or cryptographic risk.

Preparation Without a Scramble

His strongest operational caveat is about moving funds in haste. “I personally have lost more money in botched migrations than I have lost in all hacks combined,” he wrote.

Buterin’s recent AI outlook similarly described both stronger defensive tools and higher security demands. The latest statement adds a warning about the mathematical foundations themselves, while leaving the timing and practical reach of any breakthrough uncertain.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security