AIToday
AI Safety & AlignmentTHE DECODERPublished: Oct 9, 2026, 01:00 JST

Ethereum's Justin Drake urges "bunker mode" over AI wallet threat

Ethereum's Justin Drake urges "bunker mode" over AI wallet threat

3 Key Points

  1. What happened

    Justin Drake called on the blockchain industry in a post on X to prepare a "bunker mode," recommending funds be moved to addresses that have never signed a transaction. Vitalik Buterin agreed in a reply but warned against acting too fast.

  2. Why it matters

    Signing can expose an attacker's route to a wallet's private key, whereas funds tied to a hash-only address stay protected, according to Drake. Buterin said he has lost more money to botched migrations than to hacks.

WHO IT HITSCrypto wallet holders and the teams that maintain wallet and migration tooling face pressure to plan for a signature-scheme failure, while weighing Buterin's warning that rushed migrations can cost more than hacks.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The debate is notable because the two researchers land in different places from the same worry. Drake's recommendation is behavioral and immediate: move funds to addresses that have never signed, so only the public key's hash is exposed. Buterin's reply accepts the concern but pushes back on speed, citing his own losses from botched migrations rather than hacks. His longer-term position is architectural: rely as much as possible on hash functions alone, because even lattice-based schemes, often considered quantum-safe, could be weakened by advances in AI.

The caution is grounded in a simple fact: so far, no one has actually broken the current ECDSA signature scheme in practice. That gap between theoretical exposure and observed breakage is likely why Buterin frames rushed changes as a real risk of their own.

FAQ
What does Justin Drake recommend people do?
He recommends moving funds to addresses that have never signed a transaction. This keeps only the public key's hash visible, so the private key cannot be recovered.
Has the ECDSA signature scheme actually been broken?
No. So far, no one has actually broken the current ECDSA signature scheme in practice.
Why does Vitalik Buterin caution against a fast migration?
He said he has lost more money to botched migrations than to hacks. He also argues long-term for an architecture relying as much as possible on hash functions alone.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleAWS launches open-source Physical AI Toolchain