Partner · Blockchain Life 2026 — Dubai, December 1–2 · 15,000+ attendees from 130+ countriesGet tickets →
LIVE
BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—
—▲0.0%
Blockchain

'Bunker Mode': Ethereum Researchers Weigh an Early Move Off ECDSA

8 Oct 2026by CryptoJazz Admin1 min read13 views
'Bunker Mode': Ethereum Researchers Weigh an Early Move Off ECDSA

A call to move coins and a warning against hurrying arrived a day apart. Justin Drake, a researcher at the Ethereum Foundation, posted on X on Wednesday that the industry should begin planning for what he called "bunker mode," a controlled migration of funds into addresses that have never signed a transaction. His argument is that AI-driven progress in mathematics could yield a classical attack on ECDSA, the signature scheme proving ownership of most bitcoin and ether balances, before quantum computers get near it. In the worst case, he wrote, that arrives "in months not years." Vitalik Buterin replied the same Wednesday, and his advice was to slow down.

What Drake is asking holders to do

The mechanics are ordinary. An address that has never sent a transaction shows only a hash of its public key; once it signs, the key can be rebuilt from onchain data, and anyone who could derive the private key from it would control the funds. Drake wants balances shifted into fresh addresses, largest holders first, using existing wallets. He named Binance, Bitbank, Robinhood, Bitfinex and Tether as firms with room to harden cold storage. Neither Decrypt nor CryptoSlate reports any of the five acting. He called the whole exercise a precaution, not a fix.

"Today I call upon the blockchain industry to calmly begin planning for 'bunker mode,'" Drake wrote, in Decrypt's rendering.

U.Today renders the same sentence with "start" for "begin"; neither reproduces the post in full. By "break" Drake means recovering a private key in about a week on hardware already available. He also told holders not to panic. Where the safe line sits is less clear: Decrypt alone reports his claim that wallets under 50 BTC have partial cover, because about 20,000 exposed addresses tied to Bitcoin's creator each hold 50 BTC.

The OpenAI release, and three counts of it

Drake's trigger was a body of mathematical results OpenAI published on Tuesday, shipped with proofs in Lean, a language machines can verify. How much was published is reported three ways. Decrypt says 722 results, tied to a GitHub repository. The Block calls it "hundreds of mathematical manuscripts." CryptoSlate gives no total at all. Those accounts do not reconcile. What none of them reports is an attack: OpenAI claimed nothing against ECDSA.

Buterin's answer points at a different weakness

Buterin's post, which The Block dates only to Wednesday, accepts the precaution and rejects the hurry. "very easy to lose funds from a misconfigured rushed upgrade, so ... don't rush anything," he wrote, with The Block's ellipsis. He said botched migrations have cost him more than hacks have. His worry sits elsewhere in the stack. The assumption everyone plans against, he wrote, is "elliptic curves broken, hashes safe, lattices safe," and he thinks lattice security "will take serious hits from the next two years of AI math." He wants tighter lattice parameters and encrypted notes kept off the chain. The two are not in open disagreement. One is writing about ECDSA, the other about what replaces it.

What the police agency put in front of the same question

Europol's European Cybercrime Centre published Quantum Computing and Cryptocurrencies on Wednesday, with the flattest line of the week: "Cryptocurrencies will not collapse due to quantum computing." Its finding is that wallets, not chains, hold the exposure: the hash functions protecting chain history hold up far better than the cryptography protecting balances. On how much bitcoin sits at exposed addresses the accounts split. CoinDesk reports about 6.9 million BTC. Crypto Briefing gives roughly 6 to 6.9 million and puts it near 30% of supply.

Europol set no date for when an attack becomes possible and asked for a phased migration to begin now. On a 2024 study it cited, converting every bitcoin output would take at least 76 days of cumulative block space. EU supervisors had already flagged the same risk in an autumn report, and the arithmetic keeps moving: one attack estimate for secp256k1 fell 86% earlier this year. The Foundation's own post-quantum work is still pencilled in for about 2029. Neither Drake nor Buterin named a holder who has moved anything.

Read also: Ethereum Draft Would Let Validator Deposits Carry 8,192-Byte Keys

← All news