AI-accelerated math could break public-key cryptography — and crypto is going 'bunker mode'
Key Points
- Ethereum founder Vitalik Buterin and cryptography experts warn AI advances could break public-key cryptography securing blockchains, prompting the industry to enter defensive "bunker mode."
- A six-month gap between closed-source and open-source AI capabilities mirrors a recent cyberattack by a Chinese developer using open-source AI agents, suggesting the threat window is compressed.
- The crypto industry faces a paradox: the AI safety solution of government compute regulation conflicts with the libertarian ethos that drew participants to crypto in the first place.
Summary
Crypto's Cryptographic Reckoning
Ethereum founder Vitalik Buterin and others in the crypto industry are sounding an alarm that AI-driven advances in mathematics could undermine the public-key cryptography that secures blockchains. The industry is responding by entering what participants call "bunker mode."
The concern centers on a specific asymmetry: AI has demonstrated impressive progress solving mathematical proofs—from abstract problems like Navier-Stokes equations to fluid dynamics challenges—but cryptography has been noticeably absent from the wave of published breakthroughs. Matthew Green, a cryptography professor at Johns Hopkins, has stated plainly that "we might lose public key cryptography," a remarkable declaration from a domain expert that signals how seriously the threat is being considered.
The missing cryptography papers could mean one of three things. AI agent swarms tasked with solving math problems may have been explicitly barred from cryptographic problems. They may have discovered breakthroughs but are withholding publication. Or the cryptography is simply too robust to crack—though the industry remains skeptical of that last possibility.
The time window is narrow. A six-month gap typically separates closed-source model capabilities from open-source model capabilities. That timeline maps cleanly to recent events: Anthropic released Claude in early April 2026. On October 7 of the same year—roughly six months later—a 26-year-old in China deployed an open-source AI agent to execute cyberattacks against South Korean banks, according to reporting by CrowdStrike. The incident breached client data including names, addresses, and phone numbers from tens of thousands of accounts, though the attackers did not drain funds or compromise the full customer base.
The cryptographic threat differs fundamentally from quantum computing, the other existential risk to blockchains that the industry has been preparing for since the formulation of Shor's algorithm. With quantum, the mathematical problem was known decades in advance. With AI-driven cryptanalysis, the shape of the threat remains undefined. A rogue algorithm running on commodity hardware could emerge without warning.
Buterin recommends against panic but calls for urgency. He advises against immediate wallet migrations but argues the industry should "minimize our exposure to not just quantum vulnerable cryptography, but also AI vulnerable cryptography." He highlights lattice-based algorithms, MLDSA, and FAQF as particularly at risk, and suggests ECDSA (elliptic-curve cryptography) may fail faster than previously expected.
The game theory cuts both ways. If an attacker broke all Bitcoin keys and drained wallets en masse, the currency would become worthless—eliminating the incentive for a rational actor. But a "jokerified" AI agent operating without profit motive, or an actor seeking to sow chaos rather than steal, could cause financial damage regardless. Some observers note the closed-source/open-source gap creates different pressures: a US-based AI lab has no commercial interest in destroying financial infrastructure, but open-source developers face no such constraints.
The crypto industry has historically relied on hodl—the "hold on for dear life" strategy of staying invested through headwinds. That approach will not work here. The threat is not to investor conviction but to the underlying security layer itself.
Paradoxically, the solution favored by the AI safety community—government regulation of large compute clusters, data centers, and inference activity—sits uneasily with libertarian-aligned crypto participants who entered the space to escape state oversight. Locking down open-source AI development could prevent cryptanalytic attacks but would require the very government control many crypto advocates have rejected.
The market, so far, is unconvinced by the urgency. Bitcoin was down 3% on the day the alarm intensified but up 3% for the month, suggesting investors are either discounting the threat or waiting for more concrete evidence of an actual break.
Every deal, every interview. 5 minutes.
TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.