- Buterin warns AI advances could weaken lattice cryptography and increase ECDSA risks.
- Hoskinson argues that RSA’s history does not establish a hidden shortcut against lattice schemes.
- Drake warns ECDSA could break within months and supports using fresh addresses.
Vitalik Buterin and Charles Hoskinson disagree over whether advances in AI could expose new weaknesses in lattice-based cryptography. Buterin sees RSA’s history as a reason to prepare for unexpected mathematical breakthroughs, while Hoskinson argues that the comparison does not establish a credible threat to current lattice-based systems.
Buterin Says the Skeletons May Still Be in the Closet
Buterin wrote that he does not recommend anyone scramble to move funds to new wallets today. He did ask the industry to take AI-accelerated mathematics seriously and to reduce exposure to schemes that are vulnerable to quantum computers and “potentially AI-vulnerable” ones as well.
His main concern is lattice-based cryptography, including ML-DSA and FHE. The common view, he said, has been “elliptic curves broken, hashes safe, lattices safe”. He sees “a good chance” that the concrete security of lattices takes serious hits over the next two years of AI math.
Buterin’s question is whether similar shortcuts exist for curves and lattices that humans have missed, but AI may find. He also called this one more reason ECDSA could fall faster than expected, which is why he backs the “fresh address” advice.
Hoskinson Reads the Same History the Other Way
Hoskinson says the number field sieve came from specific arithmetic and was finished by 1993, and RSA sizes have barely moved in the thirty years since. His lesson is that “the skeletons ran out”.
Anyone claiming a hidden lattice shortcut must name what plays that role, he argues, and he says Buterin’s formula for the sieve is itself wrong. He adds that lattice attacks were already priced in, citing sieving costs falling from 2^0.415n in 2008 to 2^0.292n in 2016.
“And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can’t be avoided, then tells TLS, Tor, VPN, and messaging operators to get “much more paranoid” about the only post-quantum KEM that is actually deployed,” he wrote.
He also warns that doubt about hybrid ML-KEM, already in browsers and messengers, could keep traffic on weaker classical encryption. He accuses Buterin of “bag-holding” hash research, a charge his post does not support with evidence.
Where Drake Fits
Security Researcher Justin Drake backed the alarm, saying ECDSA could break before quantum computers arrive, “in the worst case in months, not years”. His evidence is a list of recently fallen mathematical conjectures, which this report has not independently verified.
What Neither Side Can Show
Neither cites an AI-found break of a deployed cryptosystem. Buterin’s case is a forecast about the next two years. Hoskinson calls that unfalsifiable, since every year without a break becomes “not yet”.
What Holders Can Do Now
For crypto holders, Buterin’s warning highlights the potential for AI-assisted mathematical breakthroughs to weaken existing cryptography sooner than expected. He supports using fresh addresses to reduce exposure to public-key risks, but advises against rushing to move funds. Hoskinson, meanwhile, disputes the basis for Buterin’s concerns about post-quantum cryptography. Neither position indicates that current cryptographic systems have been broken.
Related: AI Vulnerability is a Serious Threat to Crypto, Though Not Urgent—Vitalik Buterin
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.