Ethereum's Justin Drake urges 'bunker mode' as he warns ECDSA could break in 'months not years'
Ethereum Foundation researcher Justin Drake urged holders to begin shifting funds to never-used addresses, warning that the ECDSA signature scheme behind Bitcoin and Ethereum could be broken in "months not years.
Justin Drake, a researcher at the Ethereum Foundation, has called on crypto holders to begin preparing for what he terms "bunker mode" — moving funds into fresh addresses whose public keys stay hidden behind a hash — citing the risk that the signature scheme securing Bitcoin and Ethereum could be broken sooner than the industry assumes. The recommendation was reported by The Block on October 7.
Bitcoin and Ethereum both rely on the Elliptic Curve Digital Signature Algorithm (ECDSA) to prove that a transaction was authorized by the holder of a private key. Drake's concern, per The Block, is that ECDSA could be broken before so-called "q-day" — the point at which quantum computers become powerful enough to crack public-key cryptography. He described a break as the ability to recover a private key quickly — his example was within a week, using a large bank of GPUs — and said the worst case could arrive in "months not years."
Two caveats are Drake's own, and they matter. He stressed this is his personal recommendation, and he did not say existing cryptography has already been broken. He also warned holders not to panic or rush, saying a hurried move could do more harm than good. Current Ethereum guidance, which The Block notes, still says quantum computers cannot break the network's cryptography today and that users need take no action.
The mechanics he laid out: holders — starting with large, "sophisticated" ones — should move most funds to addresses that have never signed a transaction, because signing can expose the public key. Any funds left behind after a signature should then be moved again. Drake named Binance, Bitbank, Robinhood, Bitfinex and Tether as entities that should consider stronger cold-storage protection, and pointed to Project Eleven's "Bitcoin Risk List," which he said tracks more than 14 million addresses with exposed public keys. He added that wallets under 50 BTC enjoy some "Satoshi's shield" — roughly 20,000 exposed addresses tied to Satoshi Nakamoto, each holding 50 BTC, that an attacker would likely hit first.
As for timing, Drake tied his warning to OpenAI's publication this week of 722 mathematical manuscripts generated by an internal model, which he called evidence that "mathematical superintelligence is upon us." Elliptic curves, he argued, are more exposed than hash functions because they carry more mathematical structure.
Key facts
- Drake recommends holders move funds to never-signed "fresh" addresses; worst-case ECDSA break in "months not years" (The Block, Oct 7).
- An ECDSA break means recovering a private key quickly — e.g. within a week on GPUs (The Block).
- Project Eleven's risk list covers 14M+ addresses with exposed public keys; ~20,000 Satoshi-linked addresses hold 50 BTC each (The Block, citing Drake).
- Ethereum's current official guidance: no quantum threat today, no action needed (The Block).
The real-world read
This is a forecast from one researcher, not a disclosed break — and Drake says so himself. Note the tension he doesn't resolve: his personal "months not years" warning sits directly against the Ethereum Foundation's own standing guidance that no action is needed. The evidence offered for the accelerated timeline is a batch of AI-generated math papers, which is suggestive, not a demonstrated attack on ECDSA. No figure here quantifies the actual probability, and none is claimed to. Treat "mathematical superintelligence is upon us" as rhetoric, not a result.
Nothing here is financial or security advice.
Sources
- The Block (reputable secondary), Oct 7, 2026 — reported Drake's recommendations, the "months not years" framing, the named firms, the Project Eleven and Satoshi figures, and Ethereum's current guidance. The Block attributes all of it to Drake's own statements. (The article carried a newsletter-promotion plug, which is marketing and is disregarded here.)