Justin Drake Calls Crypto Into Bunker Mode on Three Fallen Hypotheses, and Claude Refutes One
Justin Drake asked holders on Oct. 7 to move funds to unused addresses in case AI breaks ECDSA; Ben DiFrancesco called a botched rotation riskier, and the 3SUM preprint crediting Claude lifts capability 0.2.
By Ryan Elliott Dennis · 26 sources · 11 min read
Justin Drake, a researcher at the Ethereum Foundation whose X profile reads "Bitcoin security researcher," posted at 14:14 UTC on Oct. 7 a call for "the blockchain industry to calmly begin planning for 'bunker mode'" 1. His recommendation is a controlled migration of funds to addresses whose public keys stay hidden behind a hash, because "it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years" 1. He defines the break: "By 'break' I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster)" 1. By 05:41 UTC on Oct. 8 the post had drawn 3,310,919 views, 12,252 likes and 1,015 replies 1. Europol published a report the same day that counts about 6.9 million bitcoin at addresses with exposed public keys 13.
Drake's post reached 3.31 million views; Shin's two posts drew under 3,000 each
ComparedDrake asks holders to migrate on three results
His post asks large holders to move "the bulk of their funds to addresses that have never signed a transaction," to sign from each address once, then to move on 1. Binance, Bitbank, Robinhood, Bitfinex and Tether are the five firms he names as having "an opportunity to harden their cold storage" 1. Three results carry the evidence. "Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot," Drake wrote 1. From those three he reaches the sentence the post is built on: "Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us" 1.
"Brace," "consider" and "IMO" carry the ECDSA claim. He concedes "the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published," and supplies his own explanation: "I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case" 1. Four months earlier, on June 2, Drake put the odds of qday by 2032 at 50 percent and called 2029 "a good target date for migration" 18. The Ethereum Foundation's post-quantum page, last updated June 27, opens the other way: "We do not believe a cryptographically relevant quantum computer is imminent" 20. On Oct. 7 his closing paragraph names strawmap.org and asks that its timelines be "revisited and accelerated" 121.
Nine dated steps from Google's March estimate to Drake's Nov. 12 London keynote
TimelineThe data9 rows · sources
| Date | Event | Source |
|---|---|---|
| Google Quantum AI publishes its elliptic-curve quantum estimate after engaging the U.S. government | [17] | |
| OpenAI says an internal model disproved the Erdős unit distance conjecture | [11] [26] | |
| Drake puts qday by 2032 at 50 percent and names 2029 for migration | [18] | |
| OpenAI's integer multiplication preprint, family 109, carries this date | [7] | |
| Alman and Vassilevska Williams post the 3SUM preprint crediting Claude | [6] | |
| OpenAI posts 722 manuscripts in 372 families, its Oct. 6 count | [1] [9] | |
| Drake calls for bunker mode at 14:14 UTC; Buterin answers at 23:28 | [1] [2] | |
| Ethereum Foundation post-quantum retreat opens in Cambridge, through Oct. 12 | [19] | |
| Drake keynotes Post-Quantum Ethereum in London at 10:00 | [22] |
OpenAI owns one fall, Anthropic's model another, and the third is the best checked
Family 109 of OpenAI's catalogue carries the integer multiplication result, "Integer multiplication below n log n," a preprint dated Sept. 23 7. Its bound reads O(n(log n)^(1-κ)) with κ = 2^-182, on a multitape Turing machine 7. A saving of (log n)^(2^-182) rounds to a factor of 1 at every input length a computer can hold, and the 242 Lean markers in the manuscript map, as counted at 05:28 UTC on Oct. 8, skip family 109, which is also missing from the 173 entries OpenAI's formalization catalogue held at that hour 78. The README itself moved: it read 722 manuscripts on Oct. 6 and 719 by 05:41 UTC on Oct. 8, three fewer than the count Drake cites 9.
Anthropic's model produced the 3SUM result. Josh Alman of Columbia University and Virginia Vassilevska Williams of MIT posted a 76-page preprint to arXiv on Oct. 5 that solves 3SUM on n integers in O(n^1.9992) time and APSP in O(n^2.9995) time, refuting both hypotheses of fine-grained complexity 6. Its first page states: "Claude, an AI model developed by Anthropic, discovered the algorithm that refutes the 3SUM, APSP, and Exact Triangle hypotheses" 6. "An Anthropic employee used an internal research model to investigate open problems in the theory of cryptography," the authors write, and "Claude was tasked with verifying and improving the constructions, but instead developed this algorithm, first for the average case, then for the worst case. The session used 16M output tokens with no human input" 6. Anthropic shared the algorithm with the authors in September 2026 under a confidentiality agreement, offered compensation, and, after the paper was written, used an internal model to certify the main results in Lean 4 610. So the one fall that began as a cryptography question ended as an algorithm, with a gain of 0.0008 in an exponent.
The unit distance disproof is the oldest of the three and the best checked. OpenAI said in May that an internal model "has disproved this longstanding conjecture, providing an infinite family of examples that yield a polynomial improvement," and that "The proof has been checked by a group of external mathematicians" 11. Nine mathematicians, Noga Alon and W. T. Gowers among them, posted a human-checked version of the counterexample to arXiv on May 20 26.
What about cryptanalysis itself? A search of the catalogue's manuscript map, as fetched on Oct. 8, for nine terms, crypt, discrete log, ECDSA, secp, cipher, hardness assumption, 3SUM, APSP and hash function, returns each 0 times 7. CryptoSlate put the gap in one line: "OpenAI's announcement does not report a practical attack on ECDSA or RSA. Drake's months timeline is a worst-case conjecture, not a demonstrated capability" 14. Andrew Sutherland of MIT had stated the test a day earlier: "Until and unless they release the model and people can replicate their results, I think you should treat any claims about one-shotting problems with a single agent as unverified," Sutherland told Scientific American 12.
Drake's call rests on five checked facts and five forecasts or witness accounts
The recordThe data10 rows · sources
| Column | Item | Source |
|---|---|---|
| On the record | 3SUM solved in O(n^1.9992) time, with a Lean 4 certificate from Anthropic | [6] [10] |
| On the record | 0 hits for crypt, ECDSA, discrete log or hardness assumption across the manuscript map's 372 families | [7] |
| On the record | OpenAI's family 109 saves a factor of (log n)^(2^-182) over n log n | [7] |
| On the record | The unit distance disproof was checked by external mathematicians | [11] [26] |
| On the record | About 6.9 million bitcoin sit at addresses with exposed public keys | [13] |
| Claimed or open | A 16M-token Claude session ran unattended, per the preprint's methodology note | [6] |
| Claimed or open | ECDSA breaks within months at worst, a case Drake labels IMO | [1] |
| Claimed or open | U.S. government censorship of cryptanalysis, on Drake's witness | [1] [18] |
| Claimed or open | Satoshi's 20K addresses of 50 BTC shield small wallets, by Drake | [1] |
| Claimed or open | Lattices take serious hits within two years, Buterin's forecast | [2] |
Buterin, Qureshi, DiFrancesco and Griffith answer within ten hours
Haseeb Qureshi, managing partner at Dragonfly, quote-posted Drake at 16:26 UTC. "Unfortunately, on reflection, I think this is a very sober call. No reason to be taking unnecessary risk with all of the rapid progress happening in mathematics. The risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions," Qureshi wrote, and closed with "It's UTXO-mode for a while" 3.
Vitalik Buterin posted at 23:28 UTC a response that links to Drake's post. "I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography," Buterin wrote 2. He then extended the risk to lattices: "But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math" 2. His practical line adds a warning from his own history: "I personally have lost more money in botched migrations than I have lost in all hacks combined" 2. Read closely, Buterin gives Drake the direction and drops his timeline; his two-year horizon for lattices is a forecast about a family the OpenAI catalogue leaves untouched 27.
Ben DiFrancesco, founder and chief executive of ScopeLift, a crypto engineering consultancy, took the other side on a live X broadcast, in words Laura Shin, host of the Unchained podcast, posted at 22:38 UTC on Oct. 7 42325. "Don't panic and rush and do something stupid ... You're much more likely to lose funds becsuse [sic] you go to rotate all your cold wallets and screw something up than you are to have it stolen by a GPU farm anytime soon," DiFrancesco said 4. Austin Griffith, who works at the Ethereum Foundation on developer onboarding, put it in layers seven minutes later: "My smooth brain take on this is that there's levels here and ECDSA gets cracked by this clever math, but then you have like hash function and hash signing that are harder and then you have like quantum computing ... this is like a couple of layers down," Griffith said 524.
Europol's European Cybercrime Centre, in the same day's report, states that "Cryptocurrencies will not collapse due to quantum computing," CoinDesk reported 13. Four voices, Drake, Buterin, Qureshi and Europol, each name exposed public keys as the liability. DiFrancesco and Griffith dispute the timing: months against years.
Drake's months against DiFrancesco's botched rotation over 6.9 million bitcoin
Both sidesThe data2 rows · sources
| Side | Who | Claim | Source |
|---|---|---|---|
| For | Justin Drake | ECDSA may break before qday, in the worst case in months, so holders should migrate calmly to addresses whose public keys stay hidden behind a hash. | [1] |
| Against | Ben DiFrancesco | A holder is far more likely to lose funds by rotating every cold wallet and making a mistake than to have them stolen by a GPU farm anytime soon. | [4] |
What stands behind the censorship line?
The record behind Drake's claim that he has "witnessed first-hand the US government censoring academic quantum cryptanalysis results" is his June 2 post about a Google Quantum AI paper he co-authored 118. There he wrote: "As a co-author of the Google paper I witnessed some of the context surrounding this censorship. To be honest, multiple aspects of that context don't sit well with me" 18. The same paragraph closes with praise: "the Google team's professionalism has been absolutely exemplary, and they deserve nothing but praise," Drake wrote 18. Google's blog, by Ryan Babbush and Hartmut Neven on March 31, says this: "To share this research responsibly, we engaged with the U.S. government and developed a new method to describe these vulnerabilities via a zero-knowledge proof, so they can be verified without providing a roadmap for bad actors" 17. Google calls it responsible disclosure, Drake calls it censorship, and the record holds his word beside Google's sentence.
Where this sits on the ledger
The method moves the reading on evidence and prices a post at 0.0. Meta's rename on Sept. 28 and Trump's Super Intelligence Force on Oct. 4 each held governance flat, and the OpenAI catalogue Drake cites already moved capability 0.4 on Oct. 7. Drake's post and the four answers are opinion; Decrypt carried his post on Oct. 7 and Cointelegraph carried Buterin's and Qureshi's answers on Oct. 8 1615, and the post-quantum retreat on Oct. 9 to 12 and the Nov. 12 keynote are calendar entries 141922.
One datum in his post is new to the ledger. The Alman and Vassilevska Williams preprint is dated, public, and credits Anthropic's internal research model with refuting hypotheses that stood for decades; a search of this journal finds it uncounted. Read as a pattern, it is a second lab reaching the class of result that earned OpenAI's catalogue its step. Capability moves up 0.2, inside the inferred band of 0.1 to 0.5, one notch above the floor, for three reasons: the exponent gain is 0.0008, the discovering model stays internal, and the Lean certificate came from the same lab's model after the paper was written 610. Verification holds at 0.0, because the censorship allegation rests on Drake's account alone and the catalogue returns 0 hits for crypt, ECDSA or discrete log to check 717.
Drake's phrase touches one clause of the ledger's four-clause definition. The definition asks for a deployed system that runs unsupervised for weeks on economically valuable work across most occupations, at ten gigawatts of energized compute acting as one machine, improving its own successors at a rate outsiders measure, and proving to a third party what it ran. A 16M-token session that produced one algorithm is unsupervised work on one problem, which bears on the first clause alone 6; the catalogue and the preprint are silent on the other three, and both results came from models their labs keep internal, so the fourth clause stands at 0.0 as well 69. The reading counts the preprint as capability evidence and counts the word superintelligence as Drake's.
What would each side need? Drake's reading wins with a published private-key recovery on secp256k1 above toy size. DiFrancesco's wins with each month that passes with the 6.9 million exposed bitcoin where they sit. The day's two capability steps sum to 0.6, and the reading closes Oct. 7 at 3.7.
A 3SUM preprint crediting Claude lifts capability 0.2; Drake's post moves 0.0
The moveThe data5 rows · sources
| Measure | Value |
|---|---|
| Reading before this day | 3.1 |
| This piece's move | +0.2 (Capability, inferred) |
| Band for inferred evidence | 0.1 to 0.5 |
| Reading after the day (with 1 other piece that day) | 3.7 |
| Distance to 100 | 96.3 |
Claude's 3SUM algorithm cut the exponent by 0.0008, from 2 to 1.9992
The numberThe data1 row · sources
| Measure | Value | Source |
|---|---|---|
| Cut to the 3SUM exponent, from 2 to 1.9992, in the preprint Drake cites | 0.0008 of an exponent | [6] |
By the numbers
- 3,310,919 views, 12,252 likes, 1,655 reposts and 1,015 replies on Drake's post by 05:41 UTC on Oct. 8 1.
- About 6.9 million bitcoin sit at addresses with exposed public keys, by Europol's count 13.
- O(n^1.9992): the 3SUM bound in the Alman and Vassilevska Williams preprint, against the textbook n^2 6.
- 2^-182 is κ in OpenAI's integer multiplication result, family 109, which the formalization catalogue, 173 entries at 05:28 UTC on Oct. 8, leaves out 78.
What to watch
The Ethereum Foundation's post-quantum retreat runs Oct. 9 to 12 in Cambridge, and Drake keynotes "Post-Quantum Ethereum" at 10:00 on Nov. 12 at the Kimpton Fitzroy in London, at a forum co-hosted with Bitmine 1922. A strawmap edit that pulls the 2029 forks forward would be the first governance signal; the draft as read on Oct. 8 still schedules seven forks by 2029, and governance holds at 0.0 until that line changes 21. For the capability step, an outside referee's report on arXiv:2610.06783 or a Lean replay of the 3sum-apsp project by a party outside Anthropic would confirm the datum, while a retraction, or a Lean statement found to differ from the theorem, would reverse it 610. A published private-key recovery on secp256k1 credited to a model would move capability by a full step.
Sources
- 1Today I call upon the blockchain industry to calmly begin planning for "bunker mode", X, Justin Drake, Oct. 7, 2026
- 2I don't recommend anyone scramble to move their funds to new wallets today, X, Vitalik Buterin, Oct. 7, 2026
- 3Doomerism has now hit cryptography, X, Haseeb Qureshi, Oct. 7, 2026
- 4Ben DiFrancesco on Justin Drake's warning on AI breaking ECC, X, Laura Shin, Oct. 7, 2026
- 5Austin Griffith on the rumors AI has broken ECC, X, Laura Shin, Oct. 7, 2026
- 6Truly Subquadratic 3SUM and Truly Subcubic APSP via Triangles in Sparse Lopsided Graphs, arXiv, Josh Alman and Virginia Vassilevska Williams, Oct. 5, 2026
- 7CONTENTS.md: manuscript map, OpenAI (GitHub), OpenAI, Oct. 6, 2026
- 8lean/formalization.yaml: Catalog of papers with a formalized main result, OpenAI (GitHub), OpenAI, Oct. 6, 2026
- 9openai/math: README, OpenAI (GitHub), OpenAI, Oct. 6, 2026
- 10Truly Subquadratic 3SUM and Truly Subcubic APSP: a Lean 4 formalization, Anthropic (GitHub), Anthropic, Oct. 8, 2026
- 11An OpenAI model has disproved a central conjecture in discrete geometry, OpenAI, May 20, 2026
- 12OpenAI unleashes hundreds more math results upon a field already in shock, Scientific American, Joseph Howlett, Oct. 6, 2026
- 13Quantum computers threaten exposed private keys rather than blockchains, Europol warns, CoinDesk, Olivier Acuna, Oct. 7, 2026
- 14OpenAI math breakthroughs raise 'bunker mode' alarm from Bitcoin researcher Justin Drake, CryptoSlate, Oluwapelumi Adejumo, Oct. 7, 2026
- 15Vitalik Buterin backs crypto 'bunker mode' amid rapid AI math advances, Cointelegraph, Felix Ng, Oct. 8, 2026
- 16Ethereum Researcher Says AI May Break Encryption Before Quantum Does, Decrypt, Decrypt Staff, Oct. 7, 2026
- 17Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly, Google Research, Ryan Babbush and Hartmut Neven, March 31, 2026
- 18Today a crazy quantum story just got wilder, X, Justin Drake, June 2, 2026
- 19Quantum resistance, Ethereum.org, Oct. 8, 2026
- 20Post-Quantum Ethereum, Ethereum Foundation, Ethereum Foundation Post-Quantum team, June 27, 2026
- 21L1 Strawmap: Ethereum Draft Roadmap, Ethereum Foundation, EF Architecture team: Justin, Thomas, Toni, Vitalik, Oct. 8, 2026
- 22Ethereum Institutional Forum, London, 12 November 2026, Ethereum Institutional Forum, Oct. 8, 2026
- 23ScopeLift: Crypto Engineering Consultancy, ScopeLift, Oct. 8, 2026
- 24Austin Griffith, austingriffith.com, Austin Griffith, Oct. 8, 2026
- 25About: Laura Shin, Crypto Journalist, Unchained, Oct. 8, 2026
- 26Remarks on the disproof of the unit distance conjecture, arXiv, Noga Alon, Thomas F. Bloom, W. T. Gowers, Daniel Litt, Will Sawin, Arul Shankar, Jacob Tsimerman, Victor Wang and Melanie Matchett Wood, May 20, 2026