ブテリン氏がAIによる仮想通貨の脅威を警告
暗号資産界のオピニオンリーダーであり、イーサリアムの共同創設者であるヴィタリック・ブテリン(Vitalik Buterin)氏が、AI(人工知能)の急速な進化がもたらす暗号技術へのリスクについての見解を示した。
I don’t recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it’s also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be? This is a major part of the reason why for the past year ethereum’s lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that’s a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it’s possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it’s much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs … * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than "anyone can take the money" https://t.co/oVjwZog2lL
— vitalik.eth (@VitalikButerin) October 7, 2026
今日、誰にも資金を新しいウォレットに急いで移すことをお勧めしません。でも、AI加速の数学が暗号学にもたらすリスクを真剣に受け止め、量子脆弱な暗号だけでなく、潜在的にAI脆弱な暗号へのエクスポージャーを最小限に…
同氏は、AIによる数学的進歩が従来のセキュリティ基盤に影響を与える可能性を指摘する一方で、保有者に向けて性急なウォレット移行(送金)を行わないよう強く注意を促している。
AIによる暗号技術への深刻なリスク
近年のAI技術の発展は、人間が何十年もかけて見落としてきた数学的な近道(ショートカット)やブレイクスルーを短期間で発見する可能性を秘めている。ブテリン氏は、ビットコイン(Bitcoin/BTC)やイーサリアム(Ethereum/ETH)などの多くの暗号資産ウォレットを保護している楕円曲線デジタル署名アルゴリズム(ECDSA)のような複雑な代数構造が、AIを活用した解析によって脅かされるリスクを深刻に捉えるべきだと主張している。
また、量子コンピューター時代への備えとして有力視されてきた格子暗号(Lattice-based cryptography)システム(ML-DSAや完全準同型暗号など)についても、今後のAIの進歩によってセキュリティが弱体化する恐れがあると言及されている。こうした動向の背景には、OpenAIが内部モデルによる数学的成果の発表を行うなど、自動化された研究が急速に進展している実態がある。
バンカーモードの提言と専門家の見解
イーサリアム財団の研究者であるジャスティン・ドレイク(Justin Drake)氏は、最悪の場合、数カ月以内にECDSAが侵害される恐れがあるとして、大口保有者や業界全体に対して防衛態勢(バンカーモード)への備えを呼びかけた。彼は、公開鍵がハッシュ値の背後に隠された新しいアドレスへ慎重に資金を移動することを推奨していた。
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don’t rush. While I believe there is cause for action a rushed migration would do more harm than good. Don’t panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May’s unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday’s OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I’ve witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11’s "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I’ll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi’s shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I’ll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026
本日、私はブロックチェーン業界に対し、冷静に「バンカーモード」への準備を始めるよう呼びかけます。私個人の推奨は、資産の制御された大量移行を新たなアドレスへ…
しかし、この主張に対しては反対の声も上がっています。コインベースの暗号技術部門を統括するイェフダ・リンデル(Yehuda Lindell)氏は、楕円曲線暗号の根底にある前提が急激に崩壊するという根拠や証拠は存在しないと反論。暗号技術者たちの間でも、今回の脅威の深刻度や緊急性については慎重な議論が続いている。
ブテリン氏が警鐘を鳴らすパニック的な移行の罠
ドレイク氏らが一部で推奨する動きに対し、ブテリン氏はAIによる脅威自体は真剣に受け止めるべきとしながらも、「今日すぐに新しいウォレットへ資金を移動しようと慌てるべきではない」と警鐘を鳴らしている。
彼は、十分な準備がないまま慌ただしくセキュリティ・アップグレードやウォレット移行を行うと、設定ミスや不適切な手順によって甚大な経済的損失を招く恐れがあると指摘。自身の過去の経験としても、ハッキング被害そのものよりも、移行時のトラブルや失敗によって失った資金の方が大きかったと語っており、パニックに陥った拙速な行動を戒めている。
今後の対策と求められるアプローチ
この状況を受け、ブロックチェーン開発や運用の現場では、変化するリスクに対処するための具体的な対策が見直されている。
ハッシュベース暗号の優先:
イーサリアムの簡素化されたロードマップでは、AIや格子暗号に対する脆弱性を避けるため、可能な限り「ハッシュベース」の署名方式(WOTSやSPHINCS-など)を優先する方針が示されている。
慎重なウォレット運用:
資金を移動させる必要が生じた場合でも、慌ただしい緊急対応ではなく、公開鍵の露出を防ぎつつ着実かつ慎重な準備を進めることが重要。
プライバシーとオフチェーンの活用:
プライバシー保護のプロトコルにおいては、暗号化された情報をオンチェーンに直接記録することを避け、第三者システムを介したオフチェーン送信を活用することが推奨されている。
AI技術の進化は暗号セキュリティの前提に新たな問いを投げかけているが、過剰な焦りや性急な行動はかえって資産を危険にさらす原因となる。暗号資産の利用者や開発者は、過度なパニックを避けつつ、堅実で長期的な視点に基づいたセキュリティ対策を講じることが求められている。
























