Saturday, 10 October 2026 12 calls on file SearchSubscribe
Crypto and finance news. On the record.
Breaking
Crypto · The long read10 min read

Crypto Bunker Mode Debate Tests Wallets, Zcash and Ethereum

A warning that AI-accelerated mathematics could break the signatures protecting bitcoin and ether wallets has split the industry, with Zcash setting a January target for quantum-resistant payments and Dragonfly pushing a protocol-level recovery plan.

Crypto Bunker Mode Debate Tests Wallets, Zcash and Ethereum
Illustration: Called It

The crypto bunker mode debate began with a single post and, within three days, had pulled in Ethereum's co-founder, a top venture investor, on-chain analysts and the developers of a major privacy coin. On Wednesday, October 7, Ethereum Foundation researcher Justin Drake asked the blockchain industry to "calmly start planning for 'bunker mode,'" warning that artificial intelligence could, in the worst case, find a shortcut through the mathematics guarding bitcoin and ether wallets "in months, not years," CoinDesk reported. By Friday, Zcash developers had set a January target for quantum-resistant payments, and Dragonfly's Haseeb Qureshi had dismissed the warning as "cryptographic doomerism" while proposing his own fix.

No practical attack on bitcoin or Ethereum wallet keys has been demonstrated, and CoinDesk said none appeared in the research it reviewed. The argument is about timing, preparation and who bears the cost if the industry guesses wrong.

What happened

The warning

Drake's case rests on how wallets work. A private key authorizes spending; a related public key lets the network verify that authorization. Deriving the public key from the private one is easy, while working backward is meant to require an impractical amount of computing. Bitcoin and ether wallets rely on elliptic-curve signatures, known in their most common form as ECDSA. "It is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case, in months, not years," Drake wrote, according to Cointelegraph. "Q-day" is industry shorthand for the moment a quantum computer can break today's encryption.

His trigger was OpenAI's release on Tuesday, October 6, of 722 mathematical manuscripts produced by an unreleased model that had been tested on roughly 4,000 research problems. OpenAI said some findings came with computer-checkable proofs while others remained unverified and could contain errors. Within a day, an outside researcher reran the computer check on one result, a new limit on how fast computers can multiply large grids of numbers, and found that it held, CoinDesk reported; mathematicians have worked on that question since 1969. The manuscripts came from the same model OpenAI said in September had solved the Navier–Stokes problem, one of the seven Millennium Prize challenges, and each result used on average computing power roughly equal to three hours of ChatGPT Pro reasoning, according to the company. We covered that release and the verification dispute it set off in our report on OpenAI's 722 math papers.

Drake argued that elliptic curves follow orderly patterns that a capable enough AI might learn to exploit, whereas hash functions, which turn data into fixed-length fingerprints, are built to scramble information with as little structure as possible. His practical recommendation was that large holders gradually move funds to fresh addresses whose public keys have never appeared on-chain. Withholding the public key withholds the starting point such an attack would need. The scenario he sketched requires no quantum hardware at all: an attacker who found the shortcut could recover keys and spend coins on ordinary computers, CoinDesk explained.

The pushback

Vitalik Buterin agreed the risk deserved attention but widened it in an uncomfortable direction. "There is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math," he wrote on X, as quoted by Decrypt. "If AI will bring us 50 years of math in two years, then that 50 years of math may very plausibly include a [...] level of improvement to our ability to break lattices," he added. Lattice-based cryptography is one of the main candidates for quantum resistance and underlies a digital-signature standard approved by the U.S. National Institute of Standards and Technology, CoinDesk noted. Decrypt reported that Cardano is among the projects that have considered lattice-based designs. Buterin said hash-based cryptography looks like a better route, while conceding that AI-driven mathematics could in theory weaken hashes too, and argued that any lattice-based schemes should significantly increase in size to stay safe. He also cautioned against panic: "I don't recommend anyone scramble to move their funds to new wallets today." Mistakes during a migration can cause losses of their own, he warned, adding, as quoted by CoinDesk: "I personally have lost more money in botched migrations than I have lost in all hacks combined." The tone marked a shift: Decrypt noted that only a month earlier Buterin had argued AI would not doom crypto security because defenses would keep pace.

Qureshi went further. Moving coins to a fresh address protects them only until they move again, he wrote, and such coins would be "worthless if all of the other coins are being hacked and mass-sold," Cointelegraph reported. He proposed a "Cryptographic Recovery Mode": users would register hash-based backup signatures mapped to their addresses, and validators could force a recovery path if elliptic-curve signatures were ever broken. The appeal of that design is that it would not depend on every holder acting in time; the catch is that each network would have to agree on it and deploy it before any break occurs.

The Zcash response

On Friday, Zakura, one of the programs used to run the Zcash network, published an engineering post. "Our team plans for post-quantum signature opcodes to land in Zcash in January," Roman Akhtariev wrote, according to CoinDesk. The new instructions would let the network verify hash-based signatures. January is a target rather than a confirmed network activation date.

The plan covers Zcash's transparent payments, which work much like bitcoin's, with visible addresses and amounts. About 11.96 million of the 16.98 million ZEC issued sat in the transparent pool on Thursday, roughly seven in ten coins, by CoinDesk's calculation from ZecStats data. Shielded payments, by contrast, conceal the sender, recipient and amount.

A standard transparent address initially hides its public key behind a hash; spending reveals the key, and moving leftover funds to a fresh address puts them behind a new, undisclosed one. Under the January plan, spending would be approved with a hash-based signature, so a breakthrough against today's wallet keys would not automatically defeat the replacement, CoinDesk explained. Fresh addresses create a different problem, though. Someone who spreads savings across 10 addresses still needs to check their balances, and a typical wallet asks a server for those records, giving it a way to link addresses that look unrelated on the blockchain.

Zakura has also built a balance-lookup tool based on private information retrieval, which lets a wallet query a server without revealing which addresses it is asking about. An experimental version is available through a "Private queries" setting in the Vizor wallet. ZEC ended Thursday around $1,185, down about 11% over the preceding week, after Drake's post spread on X.

Why it matters

The crypto bunker mode argument matters because of how much value already sits behind exposed keys. Glassnode co-founder Rafael Schultze-Kraft wrote that 6.26 million BTC, more than 31% of supply, sit in addresses whose public keys are visible, according to Cointelegraph. About 4.33 million BTC are exposed through address reuse, which a move to a fresh address would cure; another 1.94 million are exposed by their address format. Nearly 1.8 million of the exposed coins are held on exchanges, and 57% of all exchange balances are exposed. On Ethereum, any account that has ever sent a transaction has revealed its key, and the stablecoins and tokenized funds issued on the network depend on the same signature system, CoinDesk noted.

AI is already finding real bugs

Even without a mathematical break, AI is reshaping crypto security. CoinDesk listed a run of cases. Last December, Anthropic researchers showed frontier models could write working exploits against simulated copies of real DeFi contracts. In late July, a volunteer group called the Bitcoin Red Team used AI models to sweep 390 Bitcoin software projects in about 27 hours, logging nearly 5,000 possible flaws, 85 of them rated critical. From July 30, an attacker drained Coldcard hardware wallets through a five-year-old firmware bug, taking at least 1,367 BTC; maker Coinkite said it suspected AI helped find the flaw. BTCPay Server later confirmed thefts from merchants' Lightning nodes through a flaw first surfaced in an AI-assisted audit, and on August 27, Core Lightning developers issued an emergency warning after AI-generated bug reports turned up real vulnerabilities. CoinDesk also reported in September that researchers had used AI coding agents to improve a calculation inside a future quantum attack, though that work still required quantum hardware and covered only part of the attack.

The timelines do not line up

The Ethereum Foundation's target for moving the network onto quantum-resistant cryptography is December 2029. Drake's worst case puts a classical break years earlier. If he is wrong, a rushed migration carries its own risks: CoinDesk noted Buterin's warning that hasty wallet moves can cause losses. If he is right, a 2029 schedule is too slow.

Buterin's lattice point complicates the menu of fixes. "Potential breaks in cryptography by quantum computers were generally thought to be contained to Elliptic curve cryptography and RSA," Isabel Foxen Duke, head of Mara Foundation and a co-author of Bitcoin's BIP-360 proposal, told Decrypt. Classical breaks of the kind AI might produce could reach schemes considered quantum-safe, she said, so "we have to be even more conservative." Ananda Banerjee, founder of analytics firm Charlie Quant Lab, told Decrypt he would not treat Buterin's two-year scenario as a deadline and would "prepare carefully rather than rush to move funds."

What the standards and Bitcoin's draft fix cover

Standards bodies already hedge against the scenario Buterin described. When NIST finalized its first three post-quantum standards on August 13, 2024, it made FIPS 204, built on the lattice-based ML-DSA algorithm, the primary standard for digital signatures. FIPS 205, based on the hash-based SLH-DSA algorithm, uses a different mathematical approach and is intended as a backup in case ML-DSA proves vulnerable, the agency said. The hash-based route Buterin now favors was, in other words, designed from the start as the fallback if lattices disappoint.

Bitcoin's most concrete proposal is narrower than its reputation. BIP-360, co-authored by Foxen Duke, is still a draft. It would add a new output type, Pay-to-Merkle-Root, through a soft fork; the output works much like today's Taproot outputs but removes the key-path spend, so no public key is left exposed while coins sit unspent. The authors say this resists "long exposure" attacks on keys that stay visible for long periods, as well as future cryptanalytic approaches that may compromise Bitcoin's elliptic-curve cryptography, which is close to the threat Drake described. It does not stop a "short exposure" attack on a public key revealed in the mempool while a transaction awaits confirmation; the draft says that may require post-quantum signatures, to be offered in a separate proposal. Spending from the new outputs also takes more block space than a Taproot key-path spend. The draft points to outside pressure as well, noting that under NIST IR 8547 elliptic-curve cryptography is planned to be disallowed within the U.S. federal government after 2035, with an exception for hybrid schemes.

Money is already moving toward the problem

Bitcoin's institutional holders began funding the issue before this week. In July, a consortium led by Strategy and including BlackRock, Coinbase, Fidelity Digital Assets and Galaxy pledged $15 million over three years to developers working on quantum security, Cointelegraph reported. Other founding members include Anchorage Digital, ARK Invest, Block and Blockstream, and the day-to-day work is coordinated by Mike Schmidt, executive director of Brink, a non-profit that supports Bitcoin open-source developers. A day before the launch, Galaxy Digital pledged up to $5 million in grants of its own. Views on timing remain far apart: Blockstream CEO Adam Back said in November 2025 that bitcoin faces no meaningful quantum threat for at least 20 to 40 years, while an April report from Bernstein gave the network three to five years to prepare.

For holders, the debate has also hit prices at the margin. Our report on the bitcoin rebound to $82,000 noted that "bunker mode" talk was one of several pressures in this week's billion-dollar liquidation flush.

What's next

Three tracks are worth watching. First, Zcash: whether the hash-based signature opcodes actually land in January and receive a network activation date, and how developers handle the shielded pool. Zcash's own quantum recovery design warns that an attacker holding a recipient's address could store encrypted payment records today and attempt to decrypt them after a future breakthrough, CoinDesk reported, so the transparent-side fix is only half the job.

Second, Ethereum and Bitcoin governance. Proposals such as Qureshi's recovery mode would require broad agreement among client teams, validators and miners, and any accelerated schedule would collide with the Ethereum Foundation's 2029 plan and with Bitcoin's slower upgrade culture. The choice between lattice-based and hash-based signatures, which Buterin has now reopened, will shape how large and costly the eventual migration is. For Bitcoin, BIP-360 is the nearest test: whether the draft gathers enough support to move toward activation will show how seriously the network takes the crypto bunker mode warning.

Third, the mathematics itself. The crypto bunker mode scenario depends on AI systems producing results against elliptic curves that hold up under verification, and so far the evidence consists of rapid progress in other areas of mathematics rather than any demonstrated attack on wallet keys. Independent checks of OpenAI's manuscripts, and any similar releases from other labs, will be the clearest signal of whether Drake's worst case is drifting closer or receding.

Until then, the industry's practical consensus, to the extent one exists, sits between Drake and his critics: take the risk seriously, avoid reusing addresses, fund quantum-resistant tooling, and do not stampede. Readers should treat the debate as a security and governance story rather than a trading signal; nothing here is investment advice.

This article is for information only and is not investment advice.

More from Crypto

All crypto

The Morning Call.

The day's crypto and finance news, one call and one chart. Weekdays at 7am ET.