• Justin Drake, an Ethereum researcher, has recommended a slow, controlled migration of holdings to fresh addresses, beginning with the largest holders.
  • No wallet has been broken. The signature scheme he is talking about is intact, and his case rests on how quickly AI systems are now producing mathematics.
  • Ethereum co-founder Vitalik Buterin has since backed taking the risk seriously while telling people not to rush, and Ledger’s chief technology officer has argued a mass migration would cause more harm than it prevents. There is still no change and no formal Ethereum Foundation guidance.

Somewhere between a research post and a headline, a precaution turned into an emergency. An Ethereum researcher suggested that people begin gradually moving their coins to new addresses. By the time it reached most feeds, it read as a warning that wallet security breaks within months.

Nothing about the way your wallet works changed this week. What changed is that a lot of people are now being told, by accounts that did not read past the headline, to move their money quickly. Rushing a transfer of crypto is one of the most reliable ways to lose it: a mistyped address, a backup that was never tested, or a helpful looking “migration tool” built by someone who saw the same headline you did. The precaution being described is real and arguable. The urgency wrapped around it is not.

What ECDSA actually does

Your crypto is not stored in your wallet. It sits on a public ledger, and what you own is a : a secret number so large that guessing it is not a realistic activity.

From that private key, your software derives a public key using elliptic curve mathematics. The operation runs easily in one direction and is believed to be infeasible in the other, which is the entire foundation of the thing. Your public key can be shown to the world without giving anything away, because working backwards from it to your private key is supposed to be impossible with any computer we have.

ECDSA, the Elliptic Curve Digital Signature Algorithm, is the scheme that uses those keys to sign transactions. It proves you hold the private key without ever revealing it. Bitcoin uses it, Ethereum uses it, and so does almost everything else you own.

Why a brand new address is safer than an old one

An address is not your public key. On Bitcoin and on Ethereum alike, the address is derived from a hash of the public key, and a hash cannot be run backwards. Until you spend from an address, the chain shows only that hash. Your public key stays off the ledger.

The moment you sign a transaction, that changes. The signature publishes your public key permanently, for anyone to copy. So an address that has received funds but never sent any is in a genuinely different position from one that has spent: a future attack that could derive private keys from public keys would have nothing to work with on the first, and a published target on the second.

That distinction is the whole basis of the fresh address advice, and it is also its limit. A fresh address protects you only until you use it, which is why Drake’s recommendation includes moving the remaining balance again after any transaction that exposes the public key. It is a delay rather than a fix. The actual fix is a post-quantum signature scheme at the protocol level, and that is years of engineering and coordination away on every major chain.

What Drake actually said

Writing on X, Drake argued that recent progress in machine-generated mathematics has moved the timeline. “It is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years,” he wrote, pointing to the structure that makes elliptic curves useful in the first place: “Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings.”

His suggested response was deliberate rather than panicked. “My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses,” he wrote, starting with large and sophisticated holders, and he was explicit that “a rushed migration would do more harm than good”.

Those two sentences arrived in most coverage separated from each other. The first travels well. The second is the one that changes what an ordinary holder should do today, which is very little.

Buterin backs the concern, Ledger pushes back

The post no longer stands on its own. Vitalik Buterin, who co-founded Ethereum, has since said publicly that the industry should take the risk to cryptography from AI-accelerated mathematics seriously, and attached the same caution Drake did. “Don’t rush anything,” he said, in comments reported by The Block.

That is support for the premise rather than for any particular timetable, and it is still a personal view from someone without the power to change the protocol on his own. It does matter for how the story travels, though. A warning from one researcher is easy to dismiss and easy to exaggerate. The same warning repeated by the best-known name on the network will be read by a great many more people, most of whom will meet it through a headline.

The first substantive argument against the plan has come from Ledger’s chief technology officer, who warned that moving funds en masse to fresh addresses would itself be expensive in mistakes: transfers going wrong, backups failing, people acting under pressure they did not need to be under. That is a hardware wallet maker arguing against an industry-wide shuffle of hardware wallet balances, which is worth bearing in mind, and the objection is also the one that most of this story’s critics would have made anyway.

So the disagreement that now exists is about whether a slow migration is worth doing at all, not about whether anyone should hurry. On that second question, every named participant so far says no.

The maths behind the worry

Complex trigonometric equations and geometric diagrams drawn on a classroom blackboard.
Equations and geometric diagrams on a classroom blackboard. The concern over reused Ethereum addresses rests on the maths behind the signature scheme. Photo by https://kaboompics.com/ on Pexels.

Drake’s reasoning rests on a run of recent results from OpenAI, which published a set of new mathematical findings across algebra, theoretical computer science and mathematical logic, and said it had used 10,000 autonomous agents working in parallel to produce a solution related to the Navier-Stokes equation in 88 hours. Those are the company’s own announcements about its own systems, and this reporting does not include independent confirmation from outside mathematicians.

“Recent days have been humbling for human mathematical intuition,” Drake wrote. “Long-held, unquestioned hypotheses have fallen.” That is a researcher’s read on the direction of travel. It is not a demonstration that elliptic curve cryptography has weakened, and no wallet, address or balance has been shown to have been compromised by AI-driven cryptanalysis.

How this differs from the quantum warnings you have already read

Quantum risk has been discussed in crypto for a decade. The shorthand is “qday”, the point at which a sufficiently large quantum computer could derive private keys from public ones. The comfort in that argument has always been the hardware: building such a machine is a physical engineering problem with visible milestones, so the industry assumed it would see the threat coming years out.

The claim here is different in one respect. If mathematical progress rather than hardware is what breaks the scheme, there is no construction schedule to watch. A result could appear in a paper. That is why the suggestion is precautionary, and it is also why it is impossible to put a probability on. Drake is describing a scenario to brace for, not a vulnerability anyone has found.

The case for not hurrying

Set against the threat is a cost that is certain rather than hypothetical. Every mass movement of funds in crypto produces losses through plain human error: coins sent to the wrong chain, written down once and never checked, hardware wallets restored incorrectly under time pressure. A coordinated scramble by millions of people would produce a great deal of that, and none of it would be recoverable.

It also produces a phishing opportunity of unusual quality. If a story tells people they must move funds to a new address to stay safe, every fake “secure migration” site and support account becomes plausible. Our self-custody guide covers the basics of verifying a wallet and a destination address, and those basics matter more in a week like this than in a quiet one.

For UK holders, the practical position is that no exchange or wallet provider we can see has asked customers to do anything, and one of the largest hardware wallet makers has publicly argued against it. There is also a tax wrinkle worth knowing before anyone moves at scale: transferring coins between addresses you control is not normally a disposal, but swapping assets or routing through a service during a migration can be, and our crypto tax guide sets out where those lines fall.

What to watch

Three things would change the picture. Independent mathematicians confirming or deflating OpenAI’s results, which would tell you whether the premise holds. Published cryptanalysis showing actual weakening of the curves in use, rather than progress in adjacent fields. And formal guidance from wallet makers, exchanges or the Ethereum Foundation itself: Buterin’s comments carry weight, but they are still one person’s view rather than an institutional instruction, and nothing has been issued that a wallet provider would act on.

Until at least one of those happens, treat any message instructing you to move funds immediately as a scam until proven otherwise. The researcher who started this conversation asked for a controlled migration over time, led by the largest holders. The co-founder who backed him said the same thing about not rushing. Everything travelling faster than that was added afterwards.

Update, 8 October 2026: Vitalik Buterin has since said publicly that the risk from AI-accelerated mathematics is worth taking seriously, while warning people not to rush any migration, and Ledger’s chief technology officer has argued that a mass move to fresh addresses would cause costly mistakes. The summary, the section on Drake’s post and the closing section have been updated to reflect both.