AIがビットコインの暗号を破る?「数カ月」の最悪シナリオに警鐘
よきょい
イーサリアムの研究者ジャスティン・ドレイク氏は2026年10月7日、ブロックチェーン業界に「バンカーモード」への備えを呼びかけました。大口で高度な保有者に対し、公開鍵が一度も露出していない新しいアドレスへ資産の大半を計画的に移すよう促す内容です。
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase).
Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets.
IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).
Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot.
Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time?
Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)
Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once.
Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.
I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026).
Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS.
Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security.
The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026
きっかけは、OpenAIが10月6日に公表した、社内の最先端モデルによる数学上の新たな成果群でした。
ビットコインとイーサリアムは所有権の証明と取引の承認に楕円曲線暗号(公開鍵から秘密鍵を逆算することが極めて難しい性質を利用した暗号方式)を用いています。ドレイク氏はAIが秘密鍵の復元を大幅に容易にする古典的アルゴリズムを見つけ出す可能性を指摘。最悪の場合、ECDSA(楕円曲線デジタル署名アルゴリズム)の実質的な破綻が「数年ではなく数カ月」で訪れ得るとしています。
ただし、OpenAIの発表はECDSAやRSAへの実用的な攻撃を報告したものではありません。数カ月という時間軸は最悪ケースの推測であり、そうしたアルゴリズムが存在するかどうかも分かっていません。同氏自身、拙速な移行はかえってリスクを高めると警告しています。
ドレイク氏はバイナンス、ビットバンク、ロビンフッド、ビットフィネックス、テザーを名指しし、コールドストレージ(ネットから切り離した保管)の運用強化を主導するよう求めました。イーサリアムの耐量子基盤は2029年頃を目標としていますが、同氏はこの工程の見直しを主張しています。
Triaカードは世界中で使える仮想通貨クレジットカードで、最大6%が仮想通貨でキャッシュバックされます。
資産運用や最大40倍レバレッジの仮想通貨取引も同一のカード管理アプリから行えます。「バーチャルカードプラン」は期間限定割引となっているため是非この機会に登録しておきましょう。(登録に必要なアクセスコード:MWVJXJ6475)
Triaの特徴
Pick up