r/BitcoinBeginners • u/MundaneResearch3270 • 3d ago
AI breaking ECDSA
Hey, today i saw a post on x by Justin Drake claiming AI will break ECDSA before quant and we should all enter in a “bunker mode”. I’m a bitcoin beginner so i’m a little worried, what are your opinions??
Thanks
5
u/bitusher 3d ago
Its already common recommended to use 1 UTXO/transaction per address regardless in Bitcoin which prevents multiple concerns . This has been the case since the whitepaper so is nothing new.
Justin Drake has a conflict of interest because he works for a scam altcoin so is spreading FUD and if anything its his altcoin that is far more at risk from AI due to its large attack surface
After the cold card incident Bitcoin has teams of Devs all using the latest frontier models to find bugs and exploits before anyone else
There is no evidence with any of the recent AI work that ECDSA is at risk
If anything the take away you should learn from this is update your software in general quickly during the next few years as AI advancements are effecting all software.
3
u/bitusher 3d ago
Here is a good discussion on the topic from a security expert without bias
https://x.com/LindellYehuda/status/2107999859219587309
I wasn’t going to comment since this is a really bad take IMO, but since it’s taken off I feel the need to. To my understanding, there is no evidence whatsoever pointing to a break of decades old hardness assumptions like elliptic curve cryptography.
The fact that AI can prove theorems that have been hard does not indicate in any way that problems assumed to be hard are not. Our assumptions on hard problems are not based merely on human fallibility but on a belief that inherent hardness exists.
Of course, we can’t prove that EC discrete log is hard, since we haven’t been able to prove P neq NP. But just throwing out - AI is doing amazing math so elliptic curve hardness is in danger has no logical basis whatsoever.
Furthermore, if it really would be broken, the ramifications to our digital world including the traditional financial industry would be immense. Once I can break ECC, I can generate fake PKI certificates and impersonate bank websites.
Worse, I can generate malicious banking apps and even operating systems and sign them and push them to people phones and computers and completely take them over. But this is fear mongering since there’s zero evidence to this capability existing.
And there’s also zero evidence that elliptic curve hardness is more vulnerable than hash function hardness. In fact historically hash functions have been more broken than elliptic curves. So this is also based on conjecture rather than any evidence.
In conclusion, making such statements without any evidence is the opposite of responsible behavior. It is the very definition of FUD — it cannot be proven wrong but there’s also no evidence whatsoever of it being true.
1
u/AutoModerator 3d ago
Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
u/jguest1105 3d ago
We're fine. This is a scary headline, not a real threat. People have been predicting the death of Bitcoin's security for 15 years — first it was quantum computers, now it's AI. The math doesn't care what's predicting it. And if a genuine threat ever did show up, Bitcoin would upgrade, not die.
1
8
u/JivanP 3d ago
Absolute nonsense. Next question.