
Vitalik cảnh báo: AI có thể phá vỡ ví crypto trước cả máy tính lượng tử. Ảnh: Decrypt
Nỗi lo không còn nằm ở máy tính lượng tử
Máy tính lượng tử luôn được xem là “quả bom hẹn giờ” của ngành crypto. Song, Vitalik Buterin và Justin Drake vừa chỉ ra một kịch bản đáng lo hơn: trí tuệ nhân tạo (AI) có thể tìm ra đột phá toán học đủ sức công phá lớp mật mã của crypto trước máy tính lượng tử.
Justin Drake, nhà nghiên cứu kỳ cựu của Ethereum, thậm chí cảnh báo trong kịch bản xấu nhất, một phương pháp đủ hiệu quả để phá vỡ ECDSA có thể xuất hiện trong vài tháng không cần đến vài năm.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026
Cảnh báo xuất hiện ngay sau khi OpenAI công bố một loạt kết quả toán học mới do một mô hình AI nội bộ tạo ra. Ngày 06/10, OpenAI cho biết mô hình này đã được thử nghiệm trên khoảng 4.000 bài toán và tạo ra 722 bản thảo, được chia thành 372 nhóm kết quả trong nhiều lĩnh vực toán học.
Con số này chưa đồng nghĩa AI đã tự giải 722 bài toán độc lập. Một nhóm có thể bao gồm định lý, hệ quả hoặc nhiều cách chứng minh khác nhau. OpenAI cũng chưa công bố mô hình đứng sau các kết quả này. Nhiều chứng minh được chuyển sang Lean, hệ thống cho phép máy tính kiểm tra tính hợp lệ của từng bước lập luận, để tăng khả năng kiểm chứng.
Giới toán học vẫn thận trọng và cho rằng các tuyên bố về khả năng AI tự giải những bài toán phức tạp cần được kiểm chứng độc lập. Nhưng với Drake, điều đáng chú ý không nằm ở tốc độ AI đang tiến sâu vào lĩnh vực toán học.
Nếu AI ngày càng giỏi trong việc tìm ra những cách giải toán mà con người chưa từng nghĩ tới, một ngày nào đó nó có thể tìm được cách giải nhanh hơn những bài toán đang được dùng để bảo vệ tài sản crypto. Khi đó, ngành này có thể không còn nhiều năm để chuẩn bị như kịch bản máy tính lượng tử hiện nay.
Phòng thủ trước khi AI tìm ra đường tắt
Bitcoin và Ethereum dựa vào mật mã đường cong elliptic để bảo vệ quyền sở hữu tài sản và phê duyệt giao dịch. Với Ethereum, các tài khoản thông thường sử dụng ECDSA trên đường secp256k1 - một hệ thống chữ ký số dựa trên đường cong elliptic. Cơ chế này dựa trên một giả định tái tạo private key từ public key là bài toán quá khó để thực hiện bằng máy tính hiện tại.
Nếu một đột phá toán học biến bài toán này từ gần như không thể thành có thể, hacker sẽ không cần chờ một siêu máy tính lượng tử. Chỉ cần có phương pháp mới và đủ năng lực tính toán, họ có thể tìm đường truy ngược private key của những ví đã để lộ public key.
Đó chính là điểm khiến AI trở thành một biến số mới. Máy tính lượng tử đe dọa crypto vì nó có những thuật toán như Shor, vốn có thể giải một số bài toán mật mã nhanh hơn rất nhiều so với máy tính cổ điển.
Drake vì thế kêu gọi các tổ chức lớn nên chuyển sang trạng thái mà ông gọi là “bunker mode” (hầm trú ẩn). Với các ví lớn, tài sản nên được chuyển dần sang những địa chỉ mới chưa từng giao dịch và chưa để lộ public key. Sau mỗi lần ký giao dịch, phần tài sản còn lại cũng nên được chuyển sang một địa chỉ mới.
Trên Ethereum, địa chỉ chưa từng giao dịch chỉ công khai một giá trị băm của public key. Nhưng sau khi ví ký giao dịch, public key có thể được khôi phục từ dữ liệu on-chain. Nếu ECDSA một ngày bị phá, những địa chỉ đã lộ public key sẽ trở thành mục tiêu dễ bị tấn công hơn.
Biện pháp này không áp dụng giống nhau cho mọi blockchain. Với Bitcoin, địa chỉ Taproot công khai public key ngay từ đầu. Taproot cũng sử dụng chữ ký Schnorr thay vì ECDSA, dù cả hai đều dựa trên đường cong secp256k1.
Drake cũng muốn mở rộng việc phòng thủ sang các hạ tầng quan trọng. Các hệ thống oracle và hội đồng bảo mật của layer-2 có thể thay khóa ECDSA sau mỗi lần ký thông điệp, hoặc kết hợp chữ ký hiện tại với các cơ chế dựa trên hàm băm như SPHINCS+ để tăng thêm một lớp bảo vệ.
Drake kêu gọi các tổ chức nắm giữ lượng tài sản lớn không nên chờ đến khi AI thực sự phá được mật mã mới hành động. Ông đặc biệt nhắc tới Binance, Bitbank, Robinhood, Bitfinex và Tether, các sàn giao dịch và đơn vị lưu ký lớn nên đi đầu trong việc này.
Tuy nhiên, Vitalik không muốn người dùng hiểu cảnh báo này thành tín hiệu phải lập tức chuyển toàn bộ tài sản. Bởi lẽ, chuyển tiền cũng tiềm ẩn rủi ro. Một giao dịch sai địa chỉ, lỗi vận hành hoặc mất khóa có thể gây thiệt hại ngay lập tức.
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be? This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ... * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money" https://t.co/oVjwZog2lL
— vitalik.eth (@VitalikButerin) October 7, 2026
Nhà sáng lập Ethereum cho rằng ngay cả những thuật toán được thiết kế để chống lượng tử cũng không nên được xem là lớp bảo vệ vĩnh viễn. Ethereum vì thế đang hướng tới một hệ thống có khả năng thay đổi thuật toán mật mã khi cần, đồng thời nghiên cứu các phương án ít phụ thuộc hơn vào những cấu trúc toán học có thể bị khai thác. Các giải pháp dựa trên hàm băm và chữ ký chống lượng tử cũng đang được tính đến.
Ethereum Foundation đặt mục tiêu đưa mạng lưới sang trạng thái có khả năng chống máy tính lượng tử trên cả lớp thực thi, đồng thuận và dữ liệu vào năm 2029, với giả định “Q-Day” có thể xuất hiện khoảng năm 2030.
Coin68 tổng hợp