We must ensure one thing: even in the worst case, the blockchain is still secure.
Written by: @hosseeb, Dragonfly Partner
Translated by: AididiaoJP, Foresight News
Two days ago, OpenAI released 722 mathematical manuscripts, claiming it to be "the most important moment in the history of mathematics." Fundamental problems that have plagued mathematicians for over a century were successively broken, with each problem only requiring 3 hours of computational power. Mathematicians were stunned—they could no longer predict what would happen next.
It now seems that cryptography might be the next target.
Scott Aaronson said that OpenAI has set its sights on breaking cryptography.
The crypto industry must seriously face the "Mathematics Doomsday"—what will happen when superintelligent AI clusters target fundamental cryptography?
Matthew Green replied to @kmad and @matthew_pines on October 8, saying, "I feel we may lose public key cryptography."
Let’s be clear: we are not talking about AI accelerating quantum computing processes. That is certainly possible, but quantum computing requires a lot of physical engineering, which AI cannot accomplish overnight. This process takes time and is publicly observable. Preparing for the quantum era is crucial, but the path is relatively clear.
We are discussing some unexpected mathematical breakthrough—something that overturns the foundational assumptions of classical cryptography, allowing ordinary computers to compute discrete logarithms and thus break modern public key cryptography.
This would be a survival-level disaster.
Justin Drake said on October 7, "Today I call on the blockchain industry to calmly start planning for a 'bunker mode.' My personal suggestion is to initiate a controlled asset migration, moving assets to new addresses, where the public key is still hidden behind a hash."
In his viral "bunker mode" post, Justin essentially advocated: save yourself, protect your token assets well. The disaster may fall on others, but at least you know you are safe.
This is the doomsday theory of cryptography. It equates to saying, since you know the apocalypse is coming, start stockpiling supplies.
The problem with doomsday theories is not in the core judgment. Of course, there is a tail risk of catastrophic error. You cannot outright say the risk is zero.
The problem with doomsday theories lies in their response: if this is true, what should we do?
We cannot know the probability of public key cryptography having some fundamental weakness. It might be very low, but it is not zero. For convenience in discussion, assume this possibility is 5%. This means there is a 95% chance that everything is normal. We will write blog posts discussing this, hesitating repeatedly, and in the end, nothing bad will happen.
In fact, in that 95% scenario, AI likely merely confirms our original belief: public key cryptography is reliable.
But if I tell you now that I have a cryptographic scheme that has a 95% chance of protecting your funds, you certainly wouldn’t fully trust this scheme. The standard by which cryptographers measure security risk is a failure probability low to the order of 2^-128, meaning "almost impossible failure," rather than "most likely won't fail."
Some would say: that's right, but if ECDSA is broken, the problems society faces are much greater than those in blockchain! Consider banks, TLS, certificate authorities—blockchain is the area you should be least worried about.
But you should not take this as comfort. Banks can recover, TLS can recover, certificate authorities can recover. They can redo KYC and switch to new cryptographic standards.
The crypto industry cannot. Once public key cryptography fails, blockchains cannot recover. In the worst-case scenario, anyone can compute others' keys, meaning anyone can take others' money. We don't know who owns what and cannot prove anything. That no longer becomes cryptocurrency; it is a graffiti wall, and we have to start over.
Therefore, we must insure against such failures. We cannot guarantee that cryptography will not collapse, but we can ensure it will not destroy the blockchain. This type of "optimization" must occur simultaneously at both the protocol and societal levels, and immediate action and coordination are needed.
A common saying is, "This is not a drill." But in reality, this is an absolutely necessary drill.
We are like countries that must conscript everyone and teach everyone to shoot. War may come, and you are unlikely to be sent to the front lines. But if you are sent, we need you to immediately become a real soldier.
The opposite of the doomsday theory is a decisive action plan. Do not retreat but prepare to withstand potential disasters, which means we must start making changes now.
Why Governance Must Change
Historically, our confidence in cryptography is built upon a set of social processes.
Cryptographers spend years trying to attack a structure. If it hasn’t been broken, we say it’s probably okay. After ten years, we say it's almost certainly okay and generate absolute trust in production environments. But almost all cryptographic schemes will eventually be broken—attack methods are advancing, safety margins are shrinking, and ultimately, a better scheme must be substituted.
This pace has never been fast enough for blockchain: migration can take years, and social consensus can keep pace with changes in cryptography.
However, this premise is wobbling. We are about to face cryptanalysts that are stronger than any human, who will scrutinize these schemes with an unprecedented rigor. There are probably only a few thousand truly qualified cryptanalysts in the world, and that number is about to increase by several orders of magnitude.
In the past 40 years, all the achievements humanity has accumulated in cryptanalysis may not be as much as what AI is about to accomplish. Work that used to take ten years to complete may now be done in months. Even overnight.
The rhythm that blockchain governance has become accustomed to will no longer work in that environment.
Now it is wartime for cryptography; the norms of peacetime no longer apply. We must be able to act very quickly because things can change very quickly. If social consensus cannot keep up with the pace of technological and cryptographic changes, then social consensus must be immediately adjusted.
But Won't This Induce Panic?
Vitalik said on October 8, "I do not advise anyone to rush to move funds to new wallets today. But we should take seriously the risks posed by AI-accelerated mathematics to cryptography and minimize our exposure to not just quantum-vulnerable cryptography but potentially AI-vulnerable cryptography as well."
Panic is not the answer. I agree with Vitalik’s view: if people are encouraged to panic, they are more likely to incur losses in a hasty migration, which is worse than the actual risk of ECDSA keys being intercepted.
The so-called "bunker mode" is not a real solution. If you transfer the key to a new address alone, you may be safe. But then what? The crux of bunker mode is: your coins cannot move. As long as you don’t move, it can protect you. But if the entire chain collapses, what good is it to be safe by yourself? If everyone’s coins are being stolen or dumped, your coins are also worthless. Even if your address is safe and sound, what does it matter?
No, the solution must be at the systemic level. Encouraging people to fight individually does not solve the problem.
Meanwhile, the statement, "most importantly, everyone should remain calm," is increasingly untenable. We should honestly and directly explain the risks, ensure people take them seriously, and encourage them to take action.
This continually reminds me of the Cold War. During the Cold War, Western society was repeatedly told: nuclear war could break out. For most people, civil defense drills seemed useless—hiding under a desk wouldn’t stop a nuclear bomb. But precisely because everyone participated in the drills, society truly understood the gravity of the risks. The political winds then shifted to avoiding war at all costs while constructing bomb shelters just in case. And indeed, we came close to nuclear war several times. We were truly lucky. The stories of the Cuban Missile Crisis and Stanislav Petrov illustrate: the probability is not zero.
When it comes to cryptography, we might also be lucky. It’s very likely, but we should be prepared in case luck is not on our side.
So, how must governance change?
1) In a crisis, speed is more important than decentralization. Chains that can coordinate quickly will have an advantage. Decentralized social consensus does not naturally match the rhythm of ultra-fast technological changes. Governance mechanisms must adjust as soon as possible. Even if it means relaxing decision rules, even if it means giving validators more power, it must be done. Potential crises need rapid and decisive responses.
2) The entire ecosystem must mobilize. It’s not just protocol developers; wallets, exchanges, RPC providers, applications, asset issuers, and end users all need to act in unison to respond as an ecosystem.
3) Plans must be prepared in advance. If things have already collapsed without a plan, it will be too late.
The market will closely watch which chains take this matter seriously. I have already received inquiries from large investors who understand why this is concerning and want to know if our whole industry has answers.
So, let’s provide an answer.
Cryptography Recovery Mode
I propose that each major blockchain implement a mechanism as soon as possible, which I call "cryptography recovery mode." This will only be activated in the worst-case scenario as a nuclear war-level contingency plan.
The general idea is as follows:
In the next protocol upgrade, implement a brand new, extremely simple hash-based public key system. (Hash-based signatures rely on fewer cryptographic assumptions.) This is akin to Cold War-level minimalist cryptography. This scheme is slow and expensive and extremely cumbersome to use. We really don’t want to use it—almost anything else is better than it if given a choice. But if we really have to use it, the chain will slow down to a crawl, and DeFi will essentially be paralyzed.
But it can work. Technically, it can work, which is better than nothing.
Everyone will create a backup key using this thoroughly inadequate signing scheme. All users will be guided to establish a connection between the ordinary address and this hash-based backup key. Initially optional, it will become mandatory after a few months. Once mandatory, you cannot sign new transactions with ECDSA keys until you have set up a hash-based backup key. Without a backup key, the transaction will fail outright.
Every exchange will also begin generating backup keys for their addresses. Coinbase, Metamask, and Ledger will prompt you to create one before you sign if they find you do not have a backup key. Thus, everyone will have a backup plan. Of course, we will continue to use ECDSA in our daily operations.
We will preset an emergency switch. If disaster strikes and AI discovers a vulnerability in ECDSA, validators can reach consensus to initiate the emergency plan and enter crisis mode. No protocol upgrade is needed; based solely on the statements of validators, a vote can be conducted to activate the switch.
Once the switch is activated, all addresses will enter cryptography recovery mode. At this point, ECDSA has already failed. Completely failed.
Then What?
By that time, the chain will be a mess. Nothing will be operational; it will be nearly unusable—but technically, it can still run. Developers will have to start figuring out: how bad is the damage, which cryptography is still intact, how to transition to a new chain, and how to bring performance back to acceptable levels. At least for now, everyone’s balances are still safe, and there are ways to recover.
What about those who didn't have time to migrate? It is almost certain that a considerable portion of addresses will be left behind.
Those who still hold their mnemonic phrases can generate a hash-based zero-knowledge proof at any time (similar to @VitalikButerin's proposal for 2024) and assign themselves a new hash-based address. If their address has never signed any transactions (the so-called "bunker mode"), recovering with zero-knowledge proofs will be very simple.
But many people will not be able to do this. For them, the countdown has already begun. To recover, they can only take the following route: they must both generate ECDSA signatures and solve a proof-of-work hash puzzle to unlock the address and transfer the assets out. The difficulty of this puzzle will adjust based on the amount of native tokens held in the address. This means that if you hold 100 ETH, the difficulty will be 100N.
But this N grows exponentially. After 1 day, it will be 100N; after 2 days, it will be 200N; then 400N, then 800N. Validators can vote to limit N or restrict the growth rate based on the nature of the vulnerability and their modeling of the risks. Perhaps we will have a few months, perhaps only a few hours.
It should be noted: in real attack scenarios, this will turn into a race. If someone truly finds an efficient way to crack ECDSA keys, the true owner's only advantage is: the attacker must first crack the key before doing the proof of work; whereas the true owner only has to do the proof of work, and they should be faster. This makes large-scale theft difficult to implement. Once large-scale theft is detected, validators can significantly accelerate the rate of difficulty increase to prevent more funds from leaking (if the situation goes completely out of control, they can also raise the difficulty to infinity, permanently freezing all vulnerable coins).
I am sure I’ve missed many key details. This is just a proposal; I am neither a cryptographer nor a protocol designer. But the overall idea is: similar mechanisms should be implemented quickly across each blockchain.
The market will soon raise this requirement. Given the changes occurring in the field of mathematics, every blockchain needs a backup recovery plan, and consensus must be reached in advance—so that when that moment truly arrives, no one will still be debating how to transition.
In a crisis, speed is everything.
In this case, we should not let the pursuit of perfection derail our responsibilities. If OpenAI is actively pursuing this matter right now, we do not know how long it will be before unexpected cryptographic breakthroughs occur. The first version of the cryptography recovery mode can be rough (it probably should be rough), but once a preliminary plan is in place, it can be gradually refined. (Note that if quantum breakthroughs suddenly appear, this mechanism also applies. But it primarily needs to respond to fundamental breaches of the underlying cryptography.)
The key is that we should not be solely engaged in debates or bickering on Twitter but truly take action.
Nothing Can Be Done Once and for All
A few weeks ago, I wrote an article arguing that Zcash should complete its post-quantum migration and then no longer make changes.
I now retract that statement. When the mathematical foundation beneath us is as shaky as it is now, nothing can be done once and for all.
Perhaps in a few years, we will have more confidence in the foundations of cryptography. But for now, everything is still in flux.
This requires us to respond faster, to trust the judgment of protocol teams more, and to face the current trade-offs more honestly. Ultimately, it is about maintaining the security foundations of the entire crypto industry in a rapidly changing technological landscape.
The "mathematics doomsday" of cryptography is approaching, and we must be prepared.
I want to make one thing clear: the odds are high that nothing will happen, and everything will be fine. AI will deploy massive computational power and ultimately conclude—cryptography is all sufficiently secure.
But we must ensure one thing: even in the worst case, the blockchain is still secure.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。