“Bunker mode” is a plan proposed this week by Ethereum researcher Justin Drake: crypto holders would gradually move funds to fresh addresses whose public keys have never appeared on a blockchain, in case AI-driven mathematics breaks the signatures that protect Bitcoin and Ethereum wallets. No such attack exists today, but the warning has split the industry, and it is worth understanding what it would mean for your own coins.
Where the idea came from
On Wednesday, Oct. 7, Drake called on the industry to “calmly start planning for ‘bunker mode’.” His concern is not only quantum computers. It is that AI could help someone find a mathematical shortcut against ECDSA, the elliptic-curve signature scheme used by Bitcoin and Ethereum, and that this could happen “in months, not years” in a worst case.
The warning came a day after OpenAI published hundreds of maths manuscripts produced by an unreleased model. Some included proofs that can be checked by computer. According to reporting by CoinDesk and CryptoSlate, nothing in that release targeted blockchain cryptography.
Vitalik Buterin agreed the risk deserves attention and went further. He said lattice-based cryptography, one of the main families of “post-quantum” schemes that the U.S. standards agency NIST standardized in 2024, could also “take serious hits from the next two years of AI math.” But he told people not to rush: “I don’t recommend anyone scramble to move their funds to new wallets today.” He also noted that he has lost more money in botched migrations than in hacks.
Why public keys are the weak point
Every crypto wallet has a private key (secret) and a public key (shareable). Signing a transaction proves you have the private key. Today’s security assumes it is practically impossible to work backward from a public key to the private key.
If that assumption ever breaks, through quantum computers or a new mathematical method, the coins most at risk are the ones whose public key is already visible on-chain. Coins sitting behind only a hash of the public key have an extra layer of protection, because hash functions are believed to be much harder to attack.
Here is roughly how exposure looks on the major networks:
| Network / address type | Public key visible on-chain? |
|---|---|
| Bitcoin, very old pay-to-public-key outputs (many early-era coins) | Yes, from the start |
Bitcoin legacy and SegWit addresses (start with 1 or bc1q) that have only received |
No, only a hash is shown |
| Bitcoin addresses of those types that have ever sent funds or are reused | Yes, the key is revealed when you spend |
Bitcoin Taproot addresses (start with bc1p) |
Yes, the key is part of the address |
| Ethereum accounts that have sent at least one transaction | Yes, recoverable from any signature |
| Ethereum accounts that have only received | No |
| Solana accounts | Yes, the address is the public key |
That is why “move to a fresh address” is the core of bunker mode. A brand-new address that has never signed anything doesn’t show its public key, so an attacker would have nothing to start from.
Not everyone agrees
The debate split quickly, The Block reported. Dragonfly’s Haseeb Qureshi called Drake’s message “a very sober call.” Others worried that pushing millions of users into mass migrations creates risks of its own: mistyped addresses, lost seed phrases and a wave of scammers posing as “migration tools.”
Solana Foundation’s Jacob Creech argued that Solana users would not need bunker mode. He said a future upgrade could let users prove they know their wallet seed with a hash-based proof and then move to a quantum-resistant signature scheme. Starknet went the other way. A day after Drake’s post, it said it is considering leaving Ethereum to become its own quantum-resistant layer 1 by 2027.
On timelines, the Ethereum Foundation’s target for moving the network to quantum-resistant cryptography is December 2029. Bitcoin has no agreed date. Any change there would need a soft fork with broad community support.
What you can sensibly do now
None of this requires urgent action, and a calm approach is safer than a rushed one. Practical steps that help in any scenario:
- Stop reusing addresses. Most modern wallets generate a new receiving address each time. Use that feature.
- Keep long-term savings in addresses that have never sent a transaction. For Bitcoin cold storage, that usually means a fresh
bc1qaddress that you only receive to. - If you do move funds, test first. Send a small amount, confirm it arrived, then move the rest. Double-check every character of the address.
- Ignore unsolicited “quantum migration” offers. No legitimate wallet or foundation will DM you a link asking for your seed phrase. Rely on official announcements from your wallet maker.
- Watch your wallet’s roadmap. Hardware and software wallet makers will need to add post-quantum signature options once networks support them.
Why it matters
Markets reacted to the debate. CoinDesk listed “cryptography fears” among the reasons bitcoin dropped toward $80,000 on Thursday. The bigger issue is time. Upgrading the signature schemes of networks worth trillions of dollars takes years of coordination, and there is real disagreement about how much time is left. Planning early is cheaper than reacting late, which was the main point of Drake’s post.
FAQ
Has AI broken Bitcoin or Ethereum encryption?
No. No practical attack on Bitcoin or Ethereum wallet keys has been demonstrated. Bunker mode is a contingency plan for a worst case, not a response to an actual break.
Should I move my crypto to a new wallet today?
Buterin and most security experts say there is no need to scramble. Good hygiene, like avoiding address reuse and keeping savings in addresses that have never sent funds, already reduces exposure.
Are Taproot bitcoin addresses less safe?
Against today’s attacks, no. Against a future break of elliptic-curve cryptography, Taproot outputs show their public key directly, so they would be exposed sooner than unspent bc1q addresses.
Sources
- CoinDesk: >Bitcoin and ether holders urged to prepare “bunker mode” against possible AI attacks
- Cointelegraph: >Vitalik Buterin backs crypto “bunker mode” amid rapid AI math advances
- The Block: >Crypto industry split over Justin Drake’s AI warning
- CryptoSlate: >Vitalik Buterin urges calm as AI raises new fears over cryptography
- NIST: >FIPS 204, Module-Lattice-Based Digital Signature Standard (ML-DSA)
- Bankless via Yahoo: >Starknet weighs becoming an L1 to chase quantum resistance
This article is for information only and is not financial or security advice. Always verify wallet procedures with your wallet provider.



