Don't Panic, and Don't Reuse Addresses
An Ethereum Foundation researcher says AI could break the cryptography securing bitcoin within months. The cryptographers I respect dispute that timeline. Address hygiene reduces your exposure, and the work on other signature schemes is already underway.

TFTC - Truth for the Commoner The Commoner | |||||||||||||||||||||||||||
Thursday, October 8, 2026 | |||||||||||||||||||||||||||
Sup, freaks. A warning that AI could break the cryptography behind bitcoin took over X yesterday. I'm skeptical, but there's a caveat worth knowing and a few habits worth checking. | |||||||||||||||||||||||||||
WHAT TO EXPECT IN THIS NEWSLETTER
| |||||||||||||||||||||||||||
Marty's Bent | |||||||||||||||||||||||||||
Don't Panic, and Don't Reuse AddressesJustin Drake from the Ethereum Foundation put out an alarming post yesterday calling on the industry to start planning for what he calls "bunker mode." He wants holders, starting with the big ones, to move the bulk of their coins to fresh addresses whose public keys have never been revealed on-chain. His reasoning: "IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years." He isn't talking about a quantum computer. He means someone recovering private keys in about a week on hardware that already exists, like a large GPU cluster, using math that frontier AI models might discover. I'm not a cryptographer and I can't tell you with any certainty whether this threat is real. My gut tells me it's being overblown and that nobody should panic, and a lot of the cryptographers I respect are saying the same thing. But after yesterday's lead, I'm certainly not going to dismiss what these models might be able to do. On Tuesday, OpenAI released 722 math manuscripts produced by an internal model, and it has already withdrawn three of them after finding a sign error. One claims integer multiplication can be done faster than n log n, which was widely believed to be the limit. Earlier this week, a paper from Josh Alman and Virginia Vassilevska Williams said Claude discovered an algorithm that breaks the long-standing 3SUM conjecture. Back in May, an OpenAI model disproved an Erdős conjecture about unit distances. Drake looks at all of that, notes that elliptic curves have a lot of mathematical structure to poke at, and asks whether they're next. The piece of his argument I have the hardest time with is the evidence that isn't there. He points to the "striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published" and says "Backroom interventionism is my base case." Put simply, the labs aren't publishing crypto results, so maybe they found something and are sitting on it to avoid a massive disruption. Maybe. But a paper that doesn't exist isn't evidence of a break, and that's a big stretch to ask people to start moving billions of dollars around on. Yehuda Lindell, Coinbase's head of cryptography, called it "a really bad take" and said there is "no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography." He makes the distinction directly: "The fact that AI can prove theorems that have been hard does not indicate in any way that problems assumed to be hard are not." He admits nobody can prove the curve is hard. His point is that amazing AI math doesn't, by itself, put elliptic curve hardness in danger. Coinjoined Chris made the same point in a post I reposted: "No new attack is presented here. No complexity bound has changed. No meaningful reduction in the work factor against secp256k1 has been demonstrated." Even Vitalik, who wants the risk from AI-accelerated math taken seriously, said he doesn't recommend anyone scramble to move their funds to new wallets today. Think about what a break would actually mean, too. Lindell pointed out that whoever could do this could forge certificates to impersonate bank websites and sign malicious apps and operating system updates. Ledger CTO Charles Guillemet said a practical attack on secp256k1 or similar curves "would not stay confined to Bitcoin and Ethereum. It would compromise TLS, code signing, most banking systems, and a large fraction of deployed public-key infrastructure at once." Bitcoin would not be the only thing on fire. There is one caveat I want to add. When I sat down with Jonas Nick and Mikhail Kudinov for TFTC #700 at the very end of last year, Jonas said something that has stuck with me ever since. The security proofs cryptographers write for bitcoin's signatures rest on the assumption that secp256k1 can't be broken. "We know the elliptic curve is broken," he told me. "This makes me uneasy." He was talking about Shor's algorithm, which can break the curve on a big enough quantum computer that nobody has built yet. But he also brought up the scenario everyone is arguing about today: "It might not even be a quantum computer. It could be just our curve is broken classically." Jonas's point was that the curve is vulnerable to a sufficiently capable quantum computer, and that a classical break is another scenario worth preparing for. Whether AI speeds any of that up is anybody's guess. What should calm people down is that he, Mikhail and others have been doing the deep research for exactly this. They put out a paper late last year on hash-based signature schemes for bitcoin, and in August Jonas and his collaborators published SHRINCS, a draft BIP for a post-quantum signature scheme designed specifically for bitcoin. Adam Back pointed to that work in his response yesterday, calling Drake's post "no sky is falling FUD". On the show, Mikhail said lattice-based schemes were next on their list. None of this has to be a panicked transition. It's about creating optionality, other ways of generating key pairs for bitcoin that are ready before we need them. As Jonas put it, "Right now, I wouldn't lose my sleep over it for sure as well. But on the other hand, 10 years in Bitcoin even is not such a long time if we need to prepare for an upgrade like that." In the meantime, there are best practices bitcoiners have been preaching for years that make sense no matter what you think of Drake's timeline. Don't reuse addresses. Legacy P2PKH and native SegWit P2WPKH addresses contain a hash of your public key rather than the key itself. If that key hasn't been exposed somewhere else, it stays hidden until you spend, when it shows up in the mempool and then on-chain. That reduces your exposure. It doesn't make you quantum-proof. If you keep receiving to an address you've already spent from, those coins sit behind a key everyone can see. Pay attention to the type of address you're receiving to as well. Old pay-to-public-key outputs, including a lot of the coins mined in bitcoin's earliest days, put the public key right in the output. So does Taproot, even on a brand new address. Project Eleven's risq list, which Drake cited, estimated that 8,177,337 BTC sat in addresses with exposed public keys as of its September 14 update. Drake specifically called on Binance, Bitbank, Robinhood, Bitfinex and Tether to harden their cold storage. If you do decide to move coins, take your time. Guillemet warned that a "mass migration" would "create operational mistakes that lose funds with higher probability than the scenario being mitigated." My concern right now is losing coins through a rushed migration, not an unproven prediction that AI cracks the curve next month. I'm not going to rush a transfer because of Drake's timeline, and I don't think you should either. | |||||||||||||||||||||||||||
SIGNAL | |||||||||||||||||||||||||||
MONEY Iraq made dollars 15% more expensive overnightIraq's central bank changed the official exchange rate yesterday. Banks now pay 1,510 dinars per dollar and the public pays 1,520, up from 1,320. It takes about 15% more dinars to buy a dollar, and every dinar sitting in someone's savings lost about 13% of its dollar value. Iraq earns most of its money selling oil in dollars and pays its people in dinars. With Hormuz choking off oil revenue, The National reports the government had already been delaying salaries in several provinces and paying farmers and contractors late. A weaker dinar turns each oil dollar into more dinars for the budget. Savers and anyone buying imported food or medicine pay for it. Al Jazeera reports some MPs want it reversed, and the finance minister and central bank governor are due before parliament today. This is what governments do when the money runs short. Fix the money, fix the world. | |||||||||||||||||||||||||||
MACRO The 10-year auction cleared at its highest yield since 2000The Treasury sold $39 billion of 10-year notes yesterday at a 5.300% high yield. According to Dow Jones, that's the highest yield at a 10-year auction since November 2000. Bids came in at 2.77 times the amount offered, indirect bidders took 80.3% of the competitive bids accepted and primary dealers were left holding just 2.5%. Treasury found buyers at 5.300%. The same day, the minutes from the Fed's September meeting said "most participants assessed that another increase in the target range for the federal funds rate would likely be appropriate by year end," while stressing they go into every meeting with an open mind. The government is finding buyers, but servicing its debt keeps getting more expensive. | |||||||||||||||||||||||||||
CONTROL Russia lets bitcoin in through a narrow doorThe Bank of Russia published its first registers of licensed crypto custodians and exchange operators this week: five custodians and four exchange operators. Interfax lists Sberbank and VTB among the custodians, and VTB is on both lists. Sber is targeting December 1 to offer crypto inside its existing apps, pending regulatory approval. The rules for regular people tell you what this really is. Non-qualified investors have to pass a test and can buy no more than 300,000 rubles a year through each intermediary, and the central bank says paying with crypto inside the country remains prohibited. Every purchase on this route runs through a licensed intermediary with a cap the state sets, and you still can't spend what you buy. That's bitcoin on the state's terms. | |||||||||||||||||||||||||||
LIGHTNING Core Lightning node runners: upgrade nowCore Lightning released v26.06.9 yesterday with "fixes for vulnerabilities responsibly reported by a number of sources," and the team says "We strongly recommend upgrading to this release." The changelog covers channel reestablishment, splicing, onion handling and HTLCs during channel shutdown. One fix means an offered HTLC that hits its deadline while a channel is shutting down now force-closes the channel "so forwarded funds cannot be lost to a late fulfill." The team is holding back the tests for the security fixes for now to make it harder to build exploits quickly. Last week the project warned that "attackers are targeting unpatched nodes" running older versions. If you run CLN, don't sit on this one. | |||||||||||||||||||||||||||
ENERGY Five counties hit pause on data centers in two daysFour counties passed new data center moratoriums on Monday and Tuesday, and a fifth extended one. Beaufort County, North Carolina voted 6-1 for a one-year pause. Columbus County, North Carolina approved 120 days. Baldwin County, Alabama passed 180 days on rezoning, data centers and renewable projects in county-zoned areas. Humboldt County, California approved a 45-day ban in unincorporated areas, and Mendocino County extended its ban to 2028, exempting facilities under 3 megawatts. WITN reports no data center is even proposed in Beaufort, and a Baldwin commissioner said none has come before her board. Those two counties have time to set terms before anyone shows up. I'd rather see them use it to make developers cover their own power and infrastructure costs instead of leaving residents with the bill. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
⚡ FREEDOM TECH CORNER | |||||||||||||||||||||||||||
Android users can now check BlueWallet's buildBlueWallet v8.0.2 adds reproducible build tooling for the Android APK. If you can build from source, you can build the APK yourself and compare it with the published one, excluding signing metadata and a crash-reporting build ID. That lets you check that the app you installed was built from the code you can read instead of taking the release binary on trust. iOS isn't covered. The release also fixes the RBF speed-up and cancel buttons for HD Bech32 wallets, which is the button you want working when a transaction gets stuck. If you're on Android, update. | |||||||||||||||||||||||||||
DATA SNAPSHOT | |||||||||||||||||||||||||||
Spot price, block height and hashrate estimate: October 8, 2026, 10:23 a.m. ET. Bitcoin Lab daily series: October 7, 2026. U.S. spot ETF flows: October 7, 2026. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
Sources: Kraken spot quote, mempool.space block height and hashrate, Bitcoin Lab daily metrics, and TFTC ETF flows. Daily metrics use the provider’s October 7 observation, not live intraday estimates. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
Talk tomorrow, freaks. | |||||||||||||||||||||||||||
Marty Bent · TFTC · Nostr |


