Concerns are mounting over the potential for artificial intelligence and future quantum computing to compromise the cryptographic signatures that protect cryptocurrency. Ethereum researcher Justin Drake has renewed urgency around this threat, suggesting that the elliptic curve digital signature algorithm (ECDSA), which secures many crypto wallets, could be broken within months, not years.
Drake’s warning stems from recent advancements in AI, particularly in mathematics, as highlighted in an OpenAI report. He advocates for users to gradually move funds to fresh wallets to avoid exposed public keys. However, Dragonfly managing partner Haseeb Qureshi argues that simply relocating funds is insufficient if the broader network ecosystem remains vulnerable. Qureshi proposes network-level safeguards, including a “Cryptographic Recovery Mode” to help validators recover funds if signatures are compromised.
ECDSA Vulnerability and AI Advancements
Drake’s comments, posted on X, emphasize that the “worst case” scenario for ECDSA failure could be within months. He cited an OpenAI report detailing AI’s progress in mathematics as a key reason for the heightened concern. Drake recommended a practical user action: moving funds to new wallets to prevent public key exposure. This approach reflects a risk model where signature security might degrade faster than typical long-term migration plans can accommodate, especially with AI accelerating relevant computations.

Vitalik Buterin acknowledged the seriousness of AI-accelerated mathematics but did not endorse an immediate rush for users to relocate funds. This divergence highlights a tension between immediate user actions and the development of protocol-level and infrastructure solutions.
Qureshi Critiques “Bunker Mode”
Qureshi pushed back against what he termed “bunker mode,” a strategy focused on individual investor protection through moving funds to new addresses. He argued that this approach is a limited fix and will not prevent mass compromise if the underlying network remains exposed. Qureshi’s primary concern is systemic, warning that if cryptographic failures spread, even funds in newly generated addresses could become functionally worthless due to mass theft and selling.
He stated that protecting individual keys does not solve the broader issue if the underlying signature scheme becomes unreliable across the entire network. Qureshi believes that network-wide safeguards are essential to address the systemic risk posed by potential cryptographic vulnerabilities.
Millions of Bitcoin Exposed
Data from Glassnode, cited by Qureshi, suggests that over 31% of the Bitcoin supply may face some form of exposure, totaling 6.26 million BTC in vulnerable addresses. According to Glassnode co-founder Rafael Schultze-Kraft, approximately 4.33 million BTC are exposed due to address reuse. Moving these funds to a fresh address would mitigate this specific risk.
An additional 1.94 million BTC are exposed through address format, a different vector not solved by simply generating a new address. Schultze-Kraft also noted that nearly 1.8 million BTC of these exposed holdings are held on cryptocurrency exchanges, with 57% of all exchange balances currently exposed. This concentration on exchanges is significant, as these platforms are central to custody and liquidation, potentially becoming focal points for risk management if signature compromise becomes a live threat.
Proposed “Cryptographic Recovery Mode”
Qureshi proposed a “Cryptographic Recovery Mode” as a proactive, network-level defense against compromised cryptographic signatures. This mode would involve a hash-based backup signature plan that users could map to their addresses. As outlined by Qureshi, this mechanism would allow validators to force recovery if cryptographic signatures are compromised.
The goal is to create a path to regain control even when normal signature verification fails. This approach shifts some security responsibility from time-dependent user actions to a contingency structure at the validation layer. While Drake’s recommendation focuses on reducing exposed public keys, Qureshi’s proposal relies on the design and adoption of a recovery process executable by validators. The market impact of either approach will depend on the development of compatible standards across wallets, exchanges, and validation infrastructure.

The “months, not years” warning has reframed the urgency around cryptographic resilience. The industry’s next actionable step may involve clearer specifications for how wallets and networks should handle exposure, particularly for the substantial portion of Bitcoin held by exchanges. Further developments will likely focus on translating recovery concepts into implementable protocol changes and guidance on practical migration strategies that minimize operational risk.





