Yehuda Lindell, head of cryptography at Coinbase, called Justin Drake's call for a mass migration of crypto assets to fresh addresses “the very definition of FUD” in a thread posted Wednesday night, the sharpest of dozens of responses that have divided cryptographers, founders and investors since Drake posted the warning Wednesday morning.
The argument is not about whether artificial intelligence is doing hard mathematics. Both sides accept that it is. The split is over what follows from the absence of any published cryptanalytic result against elliptic curves — whether that absence is reassurance, or a reason to assume the work is happening out of view.
Drake, an Ethereum Foundation researcher, wrote that it is “now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years,” referring to the Elliptic Curve Digital Signature Algorithm that secures Bitcoin and Ethereum accounts, and to the day a quantum computer breaks it. He recommended holders move funds to addresses that have never signed a transaction, so that their public keys stay hidden behind a hash. The post has drawn 5.5 million views, 15,000 likes and 1,400 replies. The Defiant reported on the post and Ledger's response on Wednesday.
Ether fell 3.9% over the 24 hours to Thursday afternoon, against a 2.0% decline in Bitcoin, CoinGecko data shows. Ether trades at $2,471 and Bitcoin at $81,664.
The Very Definition Of FUD
Lindell, who is also a professor of computer science at Bar-Ilan University on leave, opened by saying he had not planned to respond. “I wasn't going to comment since this is a really bad take IMO, but since it's taken off I feel the need to. To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.”
He argued that proving theorems is a different activity from breaking assumptions. “The fact that AI can prove theorems that have been hard does not indicate in any way that problems assumed to be hard are not,” he wrote. “Our assumptions on hard problems are not based merely on human fallibility but on a belief that inherent hardness exists.”
Lindell also took on Drake's claim that elliptic curves are more exposed than hash functions. “There's also zero evidence that elliptic curve hardness is more vulnerable than hash function hardness,” he wrote. “In fact historically hash functions have been more broken than elliptic curves. So this is also based on conjecture rather than any evidence.”
His conclusion: “Making such statements without any evidence is the opposite of responsible behavior. It is the very definition of FUD — it cannot be proven wrong but there's also no evidence whatsoever of it being true.” FUD stands for fear, uncertainty and doubt.
Pressed on Thursday about Coinbase's own preparations, Lindell said the exchange “is indeed getting ready to support hash-based signatures for the potential quantum era. But there is no basis to say that AI will break ECC more than hashes, and there are actually very good reasons to say the opposite.”
Two days before Drake's post, Lindell had flagged a cryptanalytic result of a different kind: a paper by researchers at UC San Diego and INRIA Nancy forging 1024-bit RSA signatures using about 1,380 CPU core-years of precomputation and access to a signing oracle. The attack does not recover the key, and the authors are human.
Buterin Points At Lattices
Vitalik Buterin split the difference Wednesday evening, accepting the threat model while rejecting the urgency and redirecting the target.
“I don't recommend anyone scramble to move their funds to new wallets today,” the Ethereum co-founder wrote. “But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.”
His warning lands on the schemes the industry has been migrating toward. “The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices,” he wrote, naming the Module-Lattice-Based Digital Signature Algorithm standardized by the National Institute of Standards and Technology, fully homomorphic encryption, and the lattice problems both rest on. “So far most people have been in the mode of thinking ‘elliptic curves broken, hashes safe, lattices safe’. But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.”
Buterin framed the risk through the history of factoring, where decades of human work cut the cost of attacking RSA. “What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover — but bots soon will be?”
He tied it to Ethereum's lean roadmap, which has been hash-only for the past year: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside zero-knowledge proofs. Signatures in lean Ethereum use WOTS or SPHINCS+.
On Drake's actual recommendation, Buterin endorsed it with a caveat drawn from his own record. “If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined.”
He followed up Thursday morning with a correction on multisig wallets, writing that the ideal rule is for each signer to change their key after each operation.
Zero Either Way
Dankrad Feist, a researcher at Tempo and formerly at the Ethereum Foundation, attacked the remedy rather than the premise.
“If elliptic curves are broken so that any exposed public key leads to compromise, and it's not by white hat hackers who save everyone's assets first, your coins are going to zero,” he wrote. “Having them in bunker mode is not going to help you. They are still worth zero.” The post drew 154,000 views.
Charles Guillemet, Ledger's chief technology officer, made the same point about scope in his response Wednesday. A working private-key recovery attack on secp256k1, the curve Bitcoin and Ethereum use, “would not stay confined to Bitcoin and Ethereum,” he wrote. “It would compromise TLS, code signing, most banking systems, and a large fraction of deployed public-key infrastructure at once.” TLS is Transport Layer Security, the protocol behind encrypted web traffic.
Lindell made the same argument in his thread, then used it against Drake: if breaking elliptic curve cryptography lets an attacker forge certificates, impersonate bank websites and sign malicious operating system updates, “this is fear mongering since there's zero evidence to this capability existing.”
We Might Lose Public Key Cryptography
Matthew Green, who teaches cryptography at Johns Hopkins University, took the other side. “I think we might lose public key cryptography,” he posted Wednesday evening. The seven-word post has 1.4 million views and 4,500 likes.
In a thread Thursday afternoon he set out what he meant. Losing public-key encryption “does not mean cryptography or encryption is impossible,” he wrote. “It does mean that we imminently see new cryptanalytic results that substantially improve our ability to attack standardized schemes” — leaving schemes rated at a 128-bit security level at 96 or 108 bits instead.
Green's argument turns on who has been doing the analysis. The underlying problems “have been extensively analyzed by humans. We felt good that the best known attacks were the best attacks. But we're learning that human mathematical analysis isn't the gold standard,” he wrote.
He addressed the absence of cryptanalysis in OpenAI's release directly. “As others have observed: there are no major cryptanalysis results in the big dump coming from OpenAI. If you think the frontier labs aren't paying cryptanalysts to work on these results with their internal models, you're very wrong. So… they're achieving nothing? Maybe.”
His closing line: “I can't see the future. Nobody can. But so far, betting against models and in favor of human intelligence being the limit has not worked well for any of us. I think it's an especially poor choice now, being made by normally-cautious security pros.”
Lindell replied to Green that improvements on factoring are likely but bounded. “For EC, nothing has been found over generic algs for 30 years so no I don't think AI will change that.”
Haseeb Qureshi, managing partner at Dragonfly, backed Drake within two hours of the original post. “Doomerism has now hit cryptography,” he wrote. “Unfortunately, on reflection, I think this is a very sober call. No reason to be taking unnecessary risk with all of the rapid progress happening in mathematics. The risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions.”
Not Our Curve
Two rival chains used the thread to position their own cryptography.
Jacob Creech, vice president of technology at the Solana Foundation, wrote that “unlike many networks, Solana users don't need to go into ‘bunker mode.’” Solana uses Ed25519, where each signing key is derived by hashing a secret seed that never appears onchain. Breaking the curve would expose the derived key but not the seed, he wrote, and a one-time network upgrade would let owners prove knowledge of the seed with a hash-based proof and move to a new signature scheme. Anza has published a proof of concept.
Illia Polosukhin, $NEAR's co-founder, called the framing itself the problem. “Doomerism approach is never a helpful framing, even if it starts with ‘calmly’ and with best intentions,” he wrote Thursday. “Going ‘bunker mode’ is not practical nor a safe approach given how complex it is in operations.”
His alternative is key rotation at the account level. $NEAR accounts can add, remove and rotate keys, and the chain “already supports post-quantum ML-DSA,” he wrote, with hash-based cryptography planned. That is the scheme Buterin named as the new risk area a day earlier. Polosukhin's conclusion: “Upgrading cryptography should be a routine operation, not a crisis response.”
Address Reuse, Reframed
Bitcoin developers read the recommendation as a description of practice they already follow.
“Only an Ethereum developer would think that not reusing addresses is ‘Bunker mode,’” wrote Juan Galt, a reporter at Bitcoin Magazine.
Adam Back, the Blockstream chief executive who invented hashcash, replied to the post with “fud-burger.” He elaborated Thursday on the account model behind the advice: Ethereum users “store their entire transaction history with an architecture of static reused address, and to top it off they get a .eth address with their handle to self-dox.”
Bitcoin's Taproot addresses use Schnorr signatures and keep public keys hidden until a spend, a point Drake made in the original post. The Defiant has covered the quantum exposure of Bitcoin's older address formats.
What Set It Off
Drake posted a day after OpenAI published a set of new mathematical results produced by an unreleased internal model, with Lean formalizations of many of the proofs, on Oct. 6. The company says the average result used roughly three hours of ChatGPT Pro-equivalent compute. None of the published results concern cryptanalysis.
Drake cited three recent results as evidence that mathematical intuition is failing: the fall of the n log(n) bound for integer multiplication, the 3SUM conjecture, and May's disproof of the Erdős unit distance conjecture, which he called “our warning shot.”
He has not posted publicly since, and had not replied to any of the critics as of Thursday afternoon New York time. Drake framed the recommendation as personal rather than institutional, and said he will address institutions at a live Q&A in London next month.
The Ethereum Foundation set out a post-quantum key registry as the first concrete migration step earlier this year, and launched a post-quantum research hub before that. Drake's post asked for those timelines to be “revisited and accelerated.”