Skip to content

AI Is Breaching the Mathematical Fortress: Is Cryptocurrency's "Mathematical Doomsday" Just Unfounded Fear?

Oct 9, 19:15·Original author: hosseeb, Partner at Dragonfly·Translated by: AididiaoJP, Foresight News
AI Is Breaching the Mathematical Fortress: Is Cryptocurrency's "Mathematical Doomsday" Just Unfounded Fear?

Two days ago, OpenAI released 722 mathematical manuscripts in one go, calling it "the most important moment in mathematical history." Foundational problems that have plagued mathematicians for over a century were successively solved, with each problem taking only 3 hours of compute time. Mathematicians are stunned—they can no longer predict what will happen next.

It now appears that cryptography might be the next target.

Scott Aaronson stated that OpenAI has set its sights on breaking cryptography.

It's time for the crypto industry to seriously face the "mathematical doomsday"—what happens when superintelligence AI clusters turn their attention to foundational cryptography?

On October 8, Matthew Green replied to @kmad and @matthew_pines saying, "I think we might lose public-key cryptography."

Let's be clear upfront: we're not talking about AI accelerating the development of quantum computing. That's certainly possible, but quantum computing requires massive physical engineering; AI cannot solve it overnight. This process takes time and is publicly visible. Preparing for the quantum era is crucial, but the path is relatively clear.

We are talking about an unexpected mathematical breakthrough—something that overturns the foundational assumptions of classical cryptography, enabling ordinary computers to compute discrete logarithms and thereby break modern public-key cryptography.

This would be a survival-level catastrophe.

On October 7, Justin Drake said, "Today I urge the blockchain industry to calmly begin planning for 'bunker mode.' My personal advice is to launch a controlled mass migration of assets to new addresses—that is, addresses where the public key remains hidden behind a hash."

In his wildly circulated "bunker mode" post, what Justin advocates for is essentially: save yourself, protect your token assets. The disaster may strike others, but at least you know you are safe.

This is cryptographic doomsday theory. It amounts to saying: since you know the end of the world is coming, start stockpiling supplies.

The problem with doomsday theory lies not in its core judgment. There is undoubtedly a tail risk of some catastrophic failure. You cannot simply claim the risk is zero.

The problem with doomsday theory lies in its prescribed response: if this is true, what should we do?

We cannot determine how probable it is that public-key cryptography has some fundamental flaw. It may be low, but it is not zero. For discussion purposes, let's assume this probability is 5%. That means there is a 95% chance everything will remain normal. We'd write blog posts about this, hesitate back and forth, and ultimately nothing bad would happen.

In fact, in that 95% scenario, AI would likely just confirm our original belief: public-key cryptography is secure.

But if I told you right now that I had a cryptographic scheme with a 95% probability of protecting your funds, you definitely wouldn't fully trust it. Cryptographers measure security risk against a failure probability on the order of 2^-128, meaning "almost impossible to fail," not "highly unlikely to fail."

Some might say: True, but if ECDSA is broken, the problems society faces will be far greater than those in blockchain! Think about banks, TLS, certificate authorities—blockchain would actually be the area you have the least to worry about.

But you shouldn't take that as comfort. Banks can recover, TLS can recover, certificate authorities can recover. They can redo KYC, switch to new cryptographic standards.

The crypto industry cannot. Once public-key cryptography fails, blockchain cannot recover. In the worst case, anyone can compute someone else's private key, which means anyone can steal anyone else's money. We won't know who owns what, and there will be no way to prove anything. It will no longer be cryptocurrency, but a graffiti wall where we have to start from scratch.

Therefore, we must insure against this failure. We cannot guarantee that cryptography won't collapse, but we can guarantee it won't destroy blockchain. This "optimization" must occur simultaneously at the protocol and societal levels, requiring immediate action and coordination.

The common phrase is "this is not a drill." But in reality, this is absolutely necessary drill.

We are like countries that must conscript everyone and teach everyone how to shoot. War may come, and you most likely won't be sent to the front lines. But if you are, we need you to be able to become a real soldier instantly.

The opposite of doomsday theory is a decisive action plan. Don't retreat, but prepare to withstand the potential disaster, which means we must start making changes now.

Why Governance Must Change

Historically, our confidence in cryptography was built on a social process.

Cryptographers spend years trying to attack a system. If it isn't broken, we say it's probably fine. Survive ten years, and we say it's almost certainly fine, generating absolute trust in production environments. But nearly all cryptographic schemes are slowly broken over time—as attack methods advance and safety margins shrink, we eventually have to switch to better schemes.

This pace hasn't been particularly fast for blockchain: migrations can take years, and social consensus keeps pace with cryptographic changes.

But this premise is crumbling. We are about to face cryptanalyzers stronger than any human, which will review these schemes with unprecedented rigor. There are only a few thousand truly qualified cryptanalysts in the world right now, and this number is about to explode by several orders of magnitude.

All of humanity's accumulated achievements in cryptanalysis over the past 40 years may pale in comparison to what AI will accomplish next. Work that once took a decade could be done in months. Or even overnight.

The rhythm that blockchain governance has always been accustomed to simply cannot work under those conditions.

We are now in a cryptographic wartime period, and peacetime norms no longer apply. We must be capable of acting extremely quickly because things can change extremely fast. If social consensus can no longer keep up with the speed of technological and cryptographic changes, then social consensus must be adjusted immediately.

Won't This Incite Panic?

On October 8, Vitalik said, "I don't advise anyone to rush to move funds to a new wallet today. But we should take seriously the risks AI-accelerated mathematics poses to cryptography, and minimize our exposure not only to quantum-vulnerable cryptography but also potentially AI-vulnerable cryptography."

Panic is not the answer either. I agree with Vitalik: encouraging panic makes people more likely to suffer losses in rushed migrations, which is worse than the actual risk of ECDSA keys being compromised.

The so-called "bunker mode" is not a real solution. You moving your key to a new address alone might make you safe. But what then? The catch of bunker mode is: your coins become illiquid. As long as you don't move them, they are protected. But if the entire chain collapses, what good is your personal safety? If everyone's coins are being stolen and dumped, yours will be worthless too. What does it matter if your address remains intact?

No, the solution must be systemic. Encouraging people to fight their own battles will not solve the problem.

Meanwhile, the claim that "the most important thing is for everyone not to panic" is becoming increasingly untenable. We should honestly and directly state the risks, get people to take it seriously, and push them to take action.

This constantly reminds me of the Cold War. During that era, Western societies were repeatedly told: nuclear war could break out. To most people, civil defense drills seemed useless—you couldn't block a nuclear bomb by hiding under a table. But precisely because everyone participated in the drills, the entire society truly grasped the severity of the risk. Political sentiment shifted toward avoiding war at all costs, while bomb shelters were built as a precaution. In reality, we did come close to nuclear war multiple times. We got lucky. The Cuban Missile Crisis and the story of Stanislav Petrov both prove that the probability is not zero.

We might get lucky with cryptography. It's highly likely, but we should prepare just in case luck runs out on our side.

So, how must governance be changed?

1) In a crisis, speed is more important than decentralization. Chains that can coordinate quickly will have the advantage. Decentralized social consensus naturally clashes in pace with hyper-fast technological changes. Governance mechanisms must be adjusted as soon as possible. Even if it means relaxing decision-making rules, or giving validators more power, it's worth it. Potential crises require swift and decisive responses.

2) The entire ecosystem must mobilize as one. Not just protocol developers, but wallets, exchanges, RPC providers, applications, asset issuers, and end users must act in unison, with the whole ecosystem responding together.

3) Plans must be prepared in advance. If things have already collapsed and there is no plan, it will be too late.

The market will watch which chains take this seriously. I've already received inquiries from major investors who understand why this is concerning and want to know if our entire industry has an answer.

So, let's provide an answer.

Cryptographic Recovery Mode

I propose that every major blockchain roll out a mechanism as soon as possible, which I call "cryptographic recovery mode." This is a nuclear-level contingency plan that would only be activated in a worst-case scenario.

The rough idea is as follows:

In the next protocol upgrade, integrate an entirely new, extremely simple hash-based public key system. (Hash-based signatures typically rely on the fewest cryptographic assumptions.) This amounts to Cold War-level minimalist cryptography. This scheme is slow, expensive, and incredibly cumbersome to use. We don't want to touch it at all—if we have any other choice, almost anything is better than it. But if we actually have to use it, the chain will crawl like a snail, and DeFi will be basically paralyzed.

But it works. Technically usable is infinitely better than having nothing.

Everyone would use this thoroughly terrible signature scheme to create a backup key. All users would be guided to link their standard addresses with this hash-based backup key. Initially optional, it becomes mandatory after a few months. Once enforced, you cannot sign new transactions with an ECDSA key until you have set up the hash-based backup key. Without a backup key, transactions will fail outright.

Every exchange would also begin generating backup keys for their addresses. Coinbase, MetaMask, Ledger, etc., would prompt you to create one before signing if they detect you lack a backup key. This way, everyone has a fallback. Of course, we continue using ECDSA as usual in normal times.

We preset an emergency toggle. If disaster strikes and AI discovers a vulnerability in ECDSA, validators can reach consensus to activate the emergency protocol and enter crisis mode. No protocol upgrade is needed; a vote can flip the switch solely through validator consensus.

Once flipped, all addresses enter cryptographic recovery mode. At this point, ECDSA is completely defunct. Completely offline.

What Happens Next?

By then, the chain will be in complete disarray. Nothing will run smoothly, and it will be nearly unusable—but technically, it will still function. Developers will need to figure things out: how severe the damage is, which cryptographic primitives remain intact, and how to transition to a new chain to restore acceptable performance. At the very least, everyone's balances will remain secure, and there will be a way to recover.

What about those who didn't manage to migrate in time? It's almost certain that a significant portion of addresses will be left behind.

Those who still hold their seed phrases can generate hash-based zero-knowledge proofs for their seed phrases at any time (similar to @VitalikButerin's 2024 proposal), assigning themselves a new hash-based address. If their address never signed any transactions (the so-called "bunker mode"), recovering via zero-knowledge proof is straightforward.

But many simply cannot. For them, the countdown has begun. To recover, they must follow this path: generate an ECDSA signature AND solve a proof-of-work hash puzzle to unlock the address and transfer assets. The difficulty of this puzzle scales with the amount of native tokens held in the address. Meaning, if you hold 100 ETH, the difficulty is 100N.

But N grows exponentially. After 1 day it's 100N, after 2 days it's 200N, then 400N, then 800N. Validators can vote to cap N or limit its growth rate based on the nature of the vulnerability and their risk modeling. We might have months, or maybe just hours.

To be clear: in a real attack scenario, this turns into a race. If someone actually finds an efficient method to crack ECDSA keys, the sole advantage legitimate owners have is that attackers must first crack the key and then do the proof-of-work, whereas legitimate owners only need to do the proof-of-work, making their speeds faster. This makes large-scale theft difficult to execute. Once large-scale theft is detected, validators can drastically accelerate the difficulty growth rate to stop further capital flight (or if things spiral completely out of control, raise the difficulty to infinity to permanently freeze all vulnerable tokens).

I've undoubtedly missed many critical details. This is merely a proposal; I am neither a cryptographer nor a protocol designer. But the overarching principle is: similar mechanisms should be implemented on every blockchain as quickly as possible.

The market will demand this shortly. Given the shifts occurring in mathematics, every blockchain needs a fallback recovery plan, and consensus must be reached in advance—so that when the moment truly arrives, no one is still debating how the transition should proceed.

In a crisis, speed is everything.

Under these circumstances, perfection shouldn't delay necessary action. If OpenAI is actively pursuing this right now, we don't know how long until an unexpected cryptographic breakthrough occurs. The first iteration of cryptographic recovery mode can be crude (and probably should be), but once a baseline is established, it can be refined incrementally. (Note: this mechanism applies equally if a sudden quantum breakthrough happens. But its primary purpose is to handle fundamental breaks in underlying cryptography.)

The key is that we stop merely debating and trading barbs on Twitter, and actually start doing the work.

Nothing Is Ever Set in Stone

A few weeks ago, I wrote an article arguing that Zcash should complete its post-quantum migration and then leave it unchanged.

I now retract that statement. When the mathematical foundations beneath us are this shaky, nothing is ever permanent.

Perhaps in a few years, we will feel more confident about cryptographic foundations. But right now, everything is still in flux.

This demands that we react faster, trust protocol teams' judgments more, and face the trade-offs ahead more honestly. Ultimately, it means safeguarding the security foundation of the entire crypto industry amid rapidly shifting technology.

The cryptographic "mathematical doomsday" is approaching, and we must be ready.

I want to make one thing perfectly clear: most likely, nothing will happen, and everything will be fine. AI will deploy massive compute power and ultimately conclude that all cryptography is sufficiently secure.

But we must ensure one thing: even in the worst-case scenario, blockchain remains secure.

Join the official Coincamps community:

X: https://x.com/coincamps

Telegram: https://t.me/coin_camps

Recommended

Intel: OpenAI’s Actual Revenue Is $20 Billion Lower Than Rumored, SpaceX Plans to Borrow $40 Billion to Purchase NVIDIA Chips and Enter the US Carrier Market

Oct 9, 21:09
Intel: OpenAI’s Actual Revenue Is $20 Billion Lower Than Rumored, SpaceX Plans to Borrow $40 Billion to Purchase NVIDIA Chips and Enter the US Carrier Market

Recent Market Analysis: BTC's Short-Term 7% Pullback Is Driven by Far More Than Just "The U.S. Government Selling Crypto"

Oct 9, 20:26
Recent Market Analysis: BTC's Short-Term 7% Pullback Is Driven by Far More Than Just "The U.S. Government Selling Crypto"

K33 Weekly Report: US Government Transfers 17,700 BTC On-Chain, More Like Custody Than a Sell-Off

Oct 9, 19:36
K33 Weekly Report: US Government Transfers 17,700 BTC On-Chain, More Like Custody Than a Sell-Off

Podcast Notes | CZ: Bitcoin Doesn't Need 25 Years to Reach $1 Million, Next Bull Run Could Surpass Gold

Oct 9, 18:54
Podcast Notes | CZ: Bitcoin Doesn't Need 25 Years to Reach $1 Million, Next Bull Run Could Surpass Gold

Trump's August securities trading volume reached hundreds of millions of dollars?

Oct 9, 18:22
Trump's August securities trading volume reached hundreds of millions of dollars?

Nearing 5% Position Limit, BitMine’s Ethereum Treasury Strategy May Conclude Within Six Weeks

Oct 9, 18:20
Nearing 5% Position Limit, BitMine’s Ethereum Treasury Strategy May Conclude Within Six Weeks