Buterin warns AI may crack lattice crypto within two years

In this article5 sections
Ethereum co-founder Vitalik Buterin said on October 7, 2026 that there is a “good chance” AI-driven mathematics will seriously weaken lattice-based cryptography within two years, warning that a family of schemes built to survive the quantum era may face a nearer problem. According to Cryptobriefing, Buterin named ML-DSA, a quantum-resistant digital signature scheme, and fully homomorphic encryption (FHE), which lets computers compute on encrypted data without decrypting it, as systems that could be significantly undermined.
He also flagged rising risk to ECDSA signatures, the system crypto wallets commonly use to authorize transactions, noting the danger grows as public keys become exposed on-chain. Ethereum researcher Justin Drake made a similar point the same day, saying recent breakthroughs in AI-driven mathematics could produce ECDSA vulnerabilities much sooner than previously anticipated and calling for faster preparation.
Key facts
- Buterin said on October 7, 2026 that there is a “good chance” lattice security could be compromised within the next two years.
- He named ML-DSA and fully homomorphic encryption as systems that could be significantly undermined, and flagged growing ECDSA risk.
- Ethereum researcher Justin Drake said the same day that AI-driven math could expose ECDSA weaknesses sooner than expected.
- Blockonomi reported that Buterin suggested multiplying key sizes by 10 for plausible long-term security in public-key encryption.
- Ethereum’s Lean roadmap has shifted toward hash-based signatures such as WOTS and SPHINCS+.
Why hash-based signatures are favoured
Buterin’s warning lines up with a direction Ethereum already chose. The network’s Lean roadmap has moved toward hash-based signature schemes such as WOTS and SPHINCS+, reducing reliance on cryptography that looks vulnerable to quantum attacks, AI-driven attacks, or both. Blockonomi reported that lean Ethereum excludes lattices, ML-DSA, Falcon and lattice-based commitments inside ZK proofs, relying on hash-only designs for signatures.
Buterin drew a comparison to factoring: what naively takes time 2^(n/2) was cut by number field sieves to 2^O(n^(1/3)), forcing RSA keys and signatures to about 400 bytes instead of 64 bytes. He asked in a post on X whether similar hidden weaknesses exist for elliptic curves and lattices, saying humans may not find them but bots soon will. In his words, there is “a good chance that the concrete security of lattices will take serious hits.” Blockonomi quoted his summary that hash-based schemes beat lattice-based ones wherever hash-based is possible at all.
Public-key encryption is the harder case, because Buterin said theorems show it cannot be built from hashes alone and needs a trapdoor object such as lattices or code-based systems. His guidance there was to multiply key sizes by 10. He said he does not yet see a reason to pad hash byte sizes, and would raise round counts first if concerns grow. He noted that P = NP would break hashes but called that very unlikely.
Address hygiene, not panic
Despite the timeline, Buterin urged people not to make panic-driven moves with their assets. He advised keeping funds in addresses that have never executed a transaction, since an address that has never sent anything has not revealed its public key, shrinking the attack surface. He warned that rushed wallet changes carry their own cost, saying he personally has lost more money in botched migrations than in all hacks combined. Blockonomi also reported he favours offchain multisig confirmations and offchain delivery of encrypted privacy notes. Cryptobriefing reported no immediate market impact was linked to the warnings.
Why it matters
The discussion is not confined to blockchains; it extends to secure websites, messaging apps and VPNs. For holders, the practical takeaway is address hygiene. For builders, the message is about design choices: projects leaning on lattice-based schemes for signatures or encryption may want to revisit those decisions, and Buterin is signalling a preference for hash-based alternatives where workable. The quantum-computer threat has long been the headline risk to crypto security; this warning adds AI-accelerated mathematics alongside it.
What to watch
Buterin framed his concern as a probability, not a certainty, and the two-year window is a forecast. Any concrete AI-assisted result against lattice schemes or ECDSA would turn the warning into an emergency. The next signals to watch are further AI-assisted mathematics results and whether Ethereum’s Lean roadmap continues moving signatures and proofs toward hash-only designs.
This is not financial advice, and crypto markets are volatile and uncertain.
Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.
Sources: Crypto Briefing, Blockonomi


