Adam Shao|Oct 08, 2026 13:45
I asked Claude Fable 5.1 to analyze and deduce the risks listed in the article, interpreting them from the following three points: the possibility of elliptic curves being hacked by AI, what would happen if it really happened, and what should cryptocurrency holders do:
1、 The possibility of this matter
The core proposition of the article is that elliptic curve digital signatures (ECDSA) may have been hacked by classical algorithms before Quantum Day, and in the worst case, the private key can be recovered within a week on the GPU cluster within a few months.
Reasons to support this concern
Elliptical curves do indeed have rich algebraic structures (Schoof, Frobenius, pairing), and the more structures there are, the more theoretically attacked surfaces there are; Hash functions are intentionally designed to have no structure.
If AI really achieves "decades of progress compressed into weeks" in mathematics, then the fact that humans have not found attack methods in the past 40 years is no longer strong security evidence.
The author's statement about "government suppression of cryptanalysis results" cannot be verified, but the government has a strong motivation not to disclose such breakthroughs, and this asymmetry itself is a risk.
Reasons for refuting or weakening
The discrete logarithm problem of prime domain elliptic curves is one of the longest and most thoroughly attacked targets in cryptography, and there is currently no sub exponential algorithm. The analogy of 'quantum algorithms often predict classical algorithms' is a bit far fetched: Ewin Tang's de quantization is aimed at linear algebraic problems such as recommendation systems, while Shor's period search has shown no signs of de quantization for 30 years.
The author has a clear position of interest: he is promoting Ethereum's hash cryptography roadmap, and disaster narratives help accelerate the agenda.
There is a huge gap between "super intelligence proves many theorems" and "super intelligence finds a specific polynomial time ECDLP algorithm".
My rough judgment is that the probability of ECDSA being breached by classical attacks within a few months is still low (I will put it in single digit percentages), but it should indeed be raised compared to a year ago; And this is an extremely thick tail risk - once it occurs, the loss is close to 100%, unlike a regular pullback. This "low probability, high loss, irreversible" structure is precisely the type worth hedging at a small cost.
2、 What would happen if it really happened
The key is that this is not a problem of cryptocurrency, but of the whole Internet. TLS、SSH、 The bank API, code signing, and PKI of various countries all rely on ECDSA/RSA. However, traditional finance has legal identity and transaction reversibility as a fallback, while cryptocurrency does not have the advantage of "private key as ownership" which has turned into a fatal flaw in this scenario.
Ranking of on chain exposure levels (from most dangerous to relatively safe)
Early Bitcoin P2PK addresses (public key directly on chain, including approximately 1 million BTC from Satoshi Nakamoto), all reused addresses
Taproot (P2TR) Address - Note that Taproot output directly exposes the (adjusted) public key and is not protected by hashing, which many people are unaware of
All Ethereum EOA accounts that have conducted transactions (public key exposed during signature), Solana, and all elliptic curve based chains (Ed25519 is also an elliptic curve, not immune)
Exchange cold wallet - usually address reuse, is the biggest 'honeypot'
P2PKH/P2WPKH Bitcoin addresses that have never been signed, Ethereum addresses that have never sent transactions - the public key is still hidden behind the hash, making it relatively secure
A very important time logic: if it takes a week to recover the private key, the 'new address strategy' is effective because you only have a few minutes from broadcasting the transaction to confirmation. But if the algorithm progresses to crack within a few minutes, then as soon as you send a transaction, it will be replaced by attackers in the memory pool - at that time, the entire elliptic curve chain cannot be securely transferred, and can only wait for the hard fork to reach the hash signature. So 'new address' is just a matter of buying time, not the ultimate solution.
Price path: In reality, you are unlikely to be stolen first, but rather smashed first. Several dormant addresses from the Satoshi era suddenly moved → Market panic → Price collapse → Your coin is still there, but its value has evaporated. For small holders, price risk is much greater than the risk of private key theft (this is what the article refers to as the "Satoshi Nakamoto Shield" - attackers will target the biggest target first).
3、 What can people who hold a large amount of cryptocurrency do
Operation hygiene with near zero cost (worth it whether you believe it or not)
Bitcoin: Transfer funds to unused P2WPKH (starting with bc1q) or P2PKH addresses; Avoid using Taproot addresses for long-term storage; Never reuse the address, transfer the change to a new address after each spend.
Ethereum: Go to a brand new address that has never initiated a transaction (using the same mnemonic to derive a new path). A better approach is to use a smart contract account (ERC-4337), as its verification logic can be upgraded and can be switched to a hash signature scheme in the future without the need for relocation.
Separate "daily use" and "long-term storage": put the large head in a refrigerated new address and do not move it; The small head is used for operation.
Re evaluate the proportion of exchange deposits. In this scenario, self hosted new addresses are more secure than exchange cold wallets - exchange addresses are the first target of attackers.
Position level (depending on your risk tolerance)
This is not a 'sell all' signal, but if the proportion of encrypted assets to your net assets is too high (such as more than half), this tail risk is a good reason to re-examine concentration.
Consider buying long-term put options with deep virtual value at a low cost (such as Deribit's BTC/ETH options or the put of ETFs like IBIT in the US stock market). This type of insurance usually incurs loss on option premiums, but it is designed specifically for "small probabilities, huge losses". Note that Deribit itself is also on chain custody, and counterparty risk is also established in this scenario; US stock ETF options are more reliable at the legal level.
Distributed chains with different signature mechanisms have limited help - mainstream chains are all elliptic curves. Chains that truly use hash signatures (such as QRL) have extremely poor liquidity and belong to speculation rather than hedging.
Do not do: panic selling, hasty migration leading to operational errors (typing the wrong address, exposure of mnemonic words). The article itself repeatedly says' don't rush '.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink