Bitcoin and Ether Under AI Pressure: “Bunker Mode” for Holdings on Already Signed Addresses
A researcher at the Ethereum Foundation considers a break of the ECDSA signature by AI possible within months in the worst case, and advises large holders to move to addresses that have never been used. Vitalik Buterin disagrees on the pace, and Coinbase's chief cryptographer sees no evidence.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Justin Drake, a researcher at the Ethereum Foundation, wrote on X on October 7, 2026 that artificial intelligence may break the signatures of Bitcoin and Ethereum sooner than a quantum computer will. He called on the industry to plan a “bunker mode” for large holdings: an orderly move to addresses that have never signed a transfer.
The short answer to the question hanging on this: your coins are not under acute threat today. There is no demonstrated attack on the signature scheme, Drake is describing a worst case, and clear objections came out of the cryptography world within hours. The point matters all the same, because it touches a property of blockchains that most holders have never noticed: an address only reveals its public key once something leaves it for the first time. Knowing that, you can lower your risk without haste and without new technology.
“Bunker Mode”: What Justin Drake Wrote on October 7
Drake names a concrete yardstick in his post for what he counts as a break. For him the scheme is broken once a private key can be computed back in about a week on available hardware, for instance on a large cluster of graphics processors. That is a different threshold from the theoretical vulnerability cryptographers have been discussing for years, and it sits considerably lower.
He put the time frame in the formula that in the worst case this is a matter of months, not years. In the original he wrote of a break “in the worst case in months not years”. As the trigger he cited a series of 722 mathematical results that OpenAI had published the Tuesday before. His reasoning for why elliptic curves of all things should be susceptible, he put like this: “Elliptic curves feel especially vulnerable to superintelligence.” Decrypt has documented the wording of the post. Curves carry a rich mathematical structure, and structure is what clever attacks can work their way along. Hash functions are built precisely to offer as little of it as possible.
For Ethereum, Drake announced that he would push for “maximum defensive acceleration” in the switch to hash-based cryptography. He addressed a separate appeal to the custodians: Binance, Bitbank, Robinhood, Bitfinex and Tether should harden their cold storage. That is notable, because together these houses hold a substantial share of traded balances and have been signing from their addresses for years.
ECDSA: the Signature With Which Bitcoin and Ether Authorise Every Transfer
ECDSA stands for Elliptic Curve Digital Signature Algorithm. It is the scheme with which both Bitcoin and Ethereum check whether a transfer comes from the entitled party. Two numbers belong to every account: a private key that only you know, and a public key that can be computed from it. The computation works in one direction only. The public key follows from the private one in fractions of a second, while the reverse path is considered practically impossible as things stand.
That one-way street is the foundation. Were it to fall, anyone knowing an address's public key could derive the private one from it and move the coins. Neither a hardware wallet nor a passphrase nor an exchange with two-factor protection would change anything about that, because the attack would not take place at your device but at the mathematics behind it.
One restriction makes the difference between panic and planning. Your Bitcoin address is not the public key but a hash of it. A hash cannot be computed backwards, not even by a machine that cracks elliptic curves. As long as an address has only ever received, nothing but that hash stands in the blockchain. The public key becomes visible only when you send something away from it for the first time, because the signature carries it along.

Why an Address Becomes Attackable Only Through Its First Transfer
From this mechanism follows a division you can trace on your own holdings. Addresses that have never sent anything count as protected, because their public key sits behind the hash. Addresses that have already sent once count as exposed. There is nothing in between, and the line does not run along the question of how secure your wallet is, but along the question of whether it has already signed.
For Ethereum the picture is worse. There the account itself is derived from the public key, and every interaction with a smart contract involves signing. Anyone who has held Ether for years and swapped, staked or granted an approval even once is sitting on an exposed address. With Bitcoin the position is mixed: anyone who sent their coins to a fresh address once and has only held since then is on the better side.
The practical snag: spending necessarily exposes the address. A wallet you use regularly cannot be kept in the protected state permanently. Drake's proposal therefore targets the holdings that are going to sit still anyway, not the money you trade with. How to separate custody and use cleanly is shown in our hardware wallet comparison, which also ranks the devices by how well they manage several separate accounts under one seed.
Hardware Wallets ComparedSatoshi's Shield: 20,000 Old Addresses Holding 50 BTC Each as the First Target
Drake makes an argument that has drawn little attention in the debate so far and that sounds reassuring for small holders. Around 20,000 exposed addresses are attributed to the inventor of Bitcoin, each holding 50 BTC, the reward of the earliest blocks. These addresses have been untouched for a decade and a half and are visible to everyone.
An attacker who really could break ECDSA would face a question of sequence. Computing time is finite, every key costs about a week on a large cluster by Drake's own estimate, and at the top end of the field sit those twenty thousand addresses with the highest value per attack. He calls this, in effect, a shield: anyone holding less than 50 BTC on one address is not the first target, because the effort pays off better elsewhere.
This shield is a time buffer and not security. It assumes that the attacker thinks economically, that they do not parallelise, and that nobody would rather damage a chain for political reasons than enrich themselves. As a planning figure it serves all the same: it tells you that you have days and weeks to act cleanly, not hours.
Buterin Applies the Brakes: Botched Moves Cost Him More Than All Hacks Combined
The most prominent reaction came from Vitalik Buterin, and it fell into two parts. On substance he agrees with Drake that AI-driven advances in mathematics deserve more attention than the industry has given them so far. On the pace he clearly disagrees. Nobody, he says, should start shoving balances onto new wallets in a hurry today.
He draws his reasoning from his own experience, and it is the strongest argument against acting too fast: by his own account, botched moves have cost him more than all the hacks he has lived through put together. A mistyped destination, a clipboard manipulated by malware, a seed that ends up in a photo while the new wallet is being set up: these mistakes happen in haste, and unlike a mathematical breakthrough they are real today.
There is also a risk that surfaces in every wave of migration. As soon as a headline moves holders to switch, guides, helper services and supposed checking tools appear that harvest precisely what they promise to protect. Signing an approval in such a phase without having read it loses your money to a drainer, not to a superintelligence.
Objection From Cryptography: Coinbase's Chief Cryptographer Sees No Evidence
Yehuda Lindell, who runs cryptography at Coinbase, was more pointed than Buterin. In his own words he sees “no evidence whatsoever” that the assumptions behind elliptic curve cryptography are close to falling. The mathematical advances that AI systems have achieved this year are no argument against ECDSA, he says, because they concern different classes of problem.
Samson Mow, head of the company Jan3, likewise told his readership to stay calm and thought little of the warning. The specialist coverage classified the episode consistently as a risk scenario: OpenAI has presented no practical attack on ECDSA, and Drake's months-long horizon is an upper bound of the conceivable, not a forecast.
What remains notable is that the lines do not sort along the usual camps. In March of this year, after a widely noted paper from Google, Drake himself put the probability of a quantum breakthrough by 2032 at ten percent or more. That he now considers AI the faster route is a sharpening within his own argument, not a reversal.

Hash-Based Signatures: WOTS and SPHINCS as the Goal of the Ethereum Roadmap
The technical answer to the scenario has been on the table for years and is called a hash-based signature. Instead of relying on the structure of elliptic curves, it rests on hash functions alone, on exactly the components Drake considers comparatively robust. Buterin names WOTS and SPHINCS as candidates and argues for avoiding lattice-based schemes where alternatives exist.
What That Means for the Timetable
A switch of this kind is not a software update rolled out overnight. It affects the signature format of every transfer, every wallet, every exchange and every service that builds transactions. With Bitcoin, a change of this magnitude would come about only through a consensus of developers, miners and the industry, and that is exactly where it sticks: proposals that would invalidate old signatures after a deadline meet the charge that they expropriate everyone who does not move in time. The other side counters that unmoved old balances otherwise become a quarry for the first successful attacker.
For you this means the protocol layer will not rescue you in the coming months. What lies in your hands is the choice of the address your holding sits on.
Document Holding Periods and Transfers CleanlyWhat a Move to a Fresh Address Means for Your Holding Period
At this point a cryptography debate turns into a German tax question, and it is the reason many holders hesitate. The worry runs: if I send my coins to a new address, does the one-year holding period start again, and do I thereby lose the tax exemption on a gain?
The answer is reassuring. A transfer between two wallets that both belong to you is not a sale. No beneficial owner changes, no price is realised, and neither gain nor loss arises. The holding period on your coins therefore runs on as though nothing had happened. The case is different only if you take the detour of a swap for the move, by selling and buying anew: that is a disposal with all the tax consequences.
What really matters with a transfer between your own wallets is the documentation. The tax office sees a transfer in the blockchain and cannot tell whether two of your own wallets or a sale to a stranger stands behind it. So record which address you moved how much from, to which address, and when, and keep the original purchase receipt with it, because that carries the acquisition date that counts. With larger holdings or nested transactions, your tax adviser decides in the end, not a rule of thumb from an article.
Custody at an Exchange, on a Hardware Wallet or in Multisig: Where Your Public Key Sits
Whether you can act at all depends on who holds your keys. If your coins sit at an exchange, you own no address of your own but a claim against the house. Whether its cold storage sits on exposed addresses cannot be told from outside, and it was precisely these houses that Drake's appeal addressed. What is left to you is the choice between trust and self-custody.
With your own wallet the decision is in your hands. Every common hardware wallet generates any number of addresses from a single seed, and one of them can stay untouched while you trade with another. You need no second device and no new seed for that, only a fresh account in the software you already use.
With multisig constructions a closer look pays off, because several public keys are in play there and the setup alone can expose them. Anyone running such a solution should look at which of the participating keys have already signed.
Old Bitcoin Addresses: as Long as No Signature Is Out There, Time Remains
The finding of this day is unspectacular and therefore usable: a break of ECDSA has not occurred, has not been demonstrated and, in the judgement of several cryptographers, is not foreseeable either. What has occurred is an occasion to take a look at which addresses your own money sits on. That work costs half an hour, is useful for every future risk, and can be done without any haste at all.
- Look at which of your addresses have already sent. Every blockchain explorer shows you the outgoing transactions for an address. If none is to be seen there, your public key sits behind a hash. If you have no address of your own at all because everything sits at an exchange, the first step is the decision about custody: which software solutions are suited to it is set out in our software wallet comparison.
- Set up a separate account for the part that stays put. Separate the holding you do not touch from the one you trade with, and move it in a single, calmly checked operation to an address that has never signed. Document the date, the amount and both addresses while you are at it; a portfolio tracker takes that off your hands, and which of them carry the holding period correctly is in our overview of tax tools and portfolio trackers.
- Let your exchange know you are watching. If a substantial part of your holding sits at a trading venue, the question about its custody practice is a fair one, and it will be asked more often. How the large houses stand on custody, regulation and transparency is shown in our overview of the best crypto exchanges.
What remains is the sentence that sticks from this week, and it comes not from Drake but from Buterin: the most expensive part of a move is almost never the attack it is meant to protect against.
(As of October 8, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about ECDSA and exposed addresses
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Ethereum Price Prediction with Vitalik Buterin New Leadership after ETH Price Struggles in Bitcoin's Shadow
- Borrowing Against Bitcoin Instead of Selling: When German Tax Still Applies
- Crypto Tax in Germany: What Applies in 2026 and What Is Set to Change in 2027
- Bitcoin 29 Percent Below Last Year: Which Crypto Losses You Can Still Use Before the One-Year Holding Period Expires
- Germany's Crypto Holding Period: What Happens Now Signing for Petition 201716 Closed on September 15
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
October 5, 2026 7:21 PM

Bitcoin price at $85,662 one year after the all-time high: what to watch now
Bitcoin stands at $85,662, which is 32.1 percent below the all-time high whose anniversary falls on October 6. In euros the gap is smaller, and for anyone who bought in October 2025 the one-year tax period is running out at the same time.
September 9, 2026 4:29 PM

Bitcoin and Taxes in Germany: Holding Period, Savings Plan, ETP and Mining
Bitcoin gains are tax-free after twelve months. What that means for a savings plan with twelve deadlines, why ETPs are taxed differently, and what applies to mining, gifts and losses.
October 3, 2026 4:40 PM

Investing in Bitcoin With a Savings Plan or a Lump Sum: What the December 31 Tax Cut-Off Changes
Anyone putting money into Bitcoin now chooses between a lump sum, a monthly instalment and an ETN in a securities account. The German finance ministry’s draft bill would keep the one-year holding period only for holdings bought by December 31, 2026.
September 23, 2026 4:34 PM

A Bitcoin State Reserve by Statute: What the US Bill H.R. 8957 Means for German Holders
On September 16, 2026 the US House financial services committee advanced a bill that would make government Bitcoin holdings unsellable for 20 years. What the text actually says, what Saxony's sale of 49,858 Bitcoin sets against it, and the three points German holders should check now.
September 22, 2026 1:28 PM

Selling Bitcoin and Cashing Out in Euros: How It Works in Germany
Between the sell order and the euros in your current account stand the exchange, your bank and the tax office. Knowing the order of events saves fees, waiting time and, in the best case, the entire tax on the gain.
September 18, 2026 10:14 PM

Bitcoin Back Above $80,000: Buy More, Hold or Take Profits? What to Check Now
Bitcoin is back above $80,000, for the first time since September 7. Whether you buy more, hold or take profits depends less on the daily price than on three things you can check yourself: your holding period, the way you buy, and where your coins are kept.
October 8, 2026 10:39 AM

Bitcoin Cash and the CME Futures Launch on October 19: Will the Listing Carry the Price?
The CME Group plans to introduce futures on Bitcoin Cash on October 19, with a standard contract of 250 BCH. The price stands at $294.93 and has given back the jump from the announcement in full.
October 7, 2026 7:18 AM

Certificate, Bitcoin ETN or the coin itself: what each route means for tax and custody
A Bitcoin certificate, an ETN and the coin itself all lead to the same price, but to three different tax treatments and three different risks. The comparison shows which route fits your portfolio and why December 31, 2026 becomes the cut-off date.
October 6, 2026 1:23 AM

50 euros a month in Bitcoin, 118 instalments since 2017: savings plan vs lump sum
118 monthly instalments of 50 euros since January 2017 add up to €5,900 paid in and around €54,500 today. The same instalment since January 2024 is up only 14.5 percent, and since October 2025 the savings plan beats the lump sum by almost 39 percentage points.
September 27, 2026 4:12 AM

Bitcoin ETF Inflows Turn 2026 Positive: How to Tell If the Demand Holds
US spot Bitcoin ETFs took in roughly $2.4 billion in the week to September 25, the strongest week since October 2025, and that turns the 2026 year-to-date balance positive. Why the daily inflow fell 87 percent within the same week, and what to check on buying route, holding period and custody.
September 24, 2026 10:11 PM

Bitcoin Price Prediction: What to Check on Levels, Holding Period and Leverage Before the October 28 Rate Decision
Bitcoin is trading at around $83,800, a third below its October 2025 high, while the sentiment index reads greed. Which dates, levels and deadlines over the coming weeks really decide your net gain, and which of them you steer yourself.
September 24, 2026 4:11 PM

Bitcoin Cash Falls 5.5 Percent After a 50 Percent Week: Check Your Buy Route, Leverage and Holding Period
Bitcoin Cash fell to $335.19 on September 24, 2026, after gaining almost 50 percent in seven days. The rally was set off by CME's announcement of September 22; what that means for buy route, leverage, holding period and custody is set out here.
September 22, 2026 4:12 PM

Nearly $1 Billion Into Bitcoin ETFs: What to Check on ETNs, Portfolio and Holding Period
US spot bitcoin ETFs took in a net $999 million on September 21, the third consecutive day of inflows. German investors cannot reach these funds: what ETNs, the holding period and your buying route mean for you.
September 20, 2026 1:11 PM

Bitcoin Golden Cross: What Twelve Signals Since 2014 Really Show
Bitcoin's 50-day line has crossed its 200-day line. We evaluated all twelve golden crosses since 2014 ourselves and measured what happened afterwards. The result argues against the common reading of the signal.
August 24, 2026 10:29 AM

Buying More Bitcoin at $77,000: Savings Plan or Lump Sum
Bitcoin stands at $77,256 after gaining 22.78 percent in a week. This guide shows you how to buy more cleanly at this price and which method fits which starting position.
October 8, 2026 4:38 AM

Crypto Market Slides: Bitcoin Loses 4.2 Percent and $651 Million of Long Bets Are Liquidated
Bitcoin has lost 4.2 percent since Tuesday afternoon, and ether and XRP more still. Three reasons can be documented: outflows from the US ETFs, $651 million of forcibly closed long bets and Fed minutes holding out the prospect of another rate rise. A crash it is not, and what to check before buying more is set out here.
October 6, 2026 4:32 AM

Bitcoin for a gift card: what paying with crypto means for your holding period
Paying for a gift card with Bitcoin is a sale for tax purposes. What counts as the disposal proceeds, when the twelve-month holding period bites, and the four records the tax office expects.
October 2, 2026 5:02 PM

Bitcoin or Ethereum in the fourth quarter of 2026: the two largest crypto-assets compared
Bitcoin is scarce by protocol rule, Ethereum only as scarce as its utilisation, and on access and tax in Germany the paths part again. This comparison puts the verifiable figures on supply, usage, staking and purchase route side by side, without making a price call.
September 25, 2026 7:24 PM

Bitcoin Forecast: What to Check on Levels, Holding Period and Buying Route Before the Quarter Ends
Bitcoin stands at $83,877 at 16:40 UTC on September 25, 2026, and the measured volatility of the past 30 days spans a band of $73,600 to $94,200 for the coming month. More important than that band before the quarter ends are three checks: holding period, buying route under MiCA and the reporting duty in force since January 2026.
September 24, 2026 10:19 PM

Bitcoin for Retirement: What Applies from 2027 and What You Decide Now
Bitcoin is not permitted in any state-subsidised retirement product, including the new retirement savings account from 2027. Anyone who still wants to use crypto assets for their own pension goes through private assets, and there a cutoff date at the end of 2026 is shifting the tax rules right now.
September 19, 2026 10:35 AM

The Cost Average Effect with Bitcoin: What Twelve Instalments Really Deliver
Twelve monthly instalments of 100 euros produced an average price of 66,472 euros and ran 33.6 percentage points ahead of the lump sum purchase on the same starting day. The calculation also shows when the savings plan is the worse route.
September 14, 2026 4:19 AM

Fed Rate Decision of September 16: What It Means for Your Bitcoin Savings Plan
Recap as of September 27, 2026: this article appeared before the US Federal Reserve's rate decision on September 16, 2026, when futures markets mostly expected a hike. It describes what a hike means for your monthly instalment, a running crypto loan and your holding periods.
October 2, 2026 4:39 AM

Donating bitcoin: when does the full market value count, when only the purchase price?
A bitcoin donation to a charitable organisation is deductible as a donation in kind, and the donation itself produces no taxable gain. The size of the deduction turns solely on whether a sale would have been taxable on the day of the transfer.
September 25, 2026 10:26 PM

Selling bitcoin privately: the tax in Germany and the records you need
A direct sale to a private individual falls under the same one-year rule as an exchange sale, but there is no tax report to go with it. This guide walks through the calculation, the 1,000 euro threshold and the records the tax office wants to see.
September 22, 2026 10:13 AM

Circle Lends Against Bitcoin via cirBTC: Why the Wrapper Can Cost You the German Holding Period
Circle launched loans against deposited bitcoin on September 21, 2026. In Germany, the detour through the cirBTC token is very likely a swap, and a swap restarts your one-year holding period.
September 17, 2026 7:12 PM

Gifting Bitcoin to Children: Allowance, Holding Period and the Tax Office Report
Transferring Bitcoin to your child hands over your holding period and your entry price along with the coins. This guide sets out what really applies in Germany on the allowance, the reporting deadline, representation and custody.
August 14, 2026 6:23 AM

Bitcoin Savings Plan and Tax: How the Holding Period, FIFO and the Exemption Limit Interact on Monthly Buys
Every savings plan instalment is a separate acquisition for tax purposes, with a holding period of its own. How the exemption limit, the order of disposal and record-keeping duties interact on monthly Bitcoin buys, with the sources from the statute and the Ministry of Finance circular.
More from CryptoTicker
