Vitalik says that, besides the long-known quantum threat to cryptography, there is also an AI threat, and it is much closer.
The solutions that help against the quantum threat — lattices — may be exactly the weak point in an AI attack.
CZ took an interest.
Vitalik:
I don’t recommend scrambling to move funds to new wallets today. But we should take AI-accelerated math risks to cryptography seriously and minimize exposure to both quantum-vulnerable and AI-vulnerable crypto.
The core new risk is ML-DSA / FHE / lattices. (It’s also another reason, with quantum, why ECDSA may fall faster — hence the “fresh address” advice.)
Most people assume “curves broken, hashes & lattices safe.” But AI math in the next ~2 years may seriously weaken lattice security, like how number field sieves degraded factoring.
This is why Ethereum’s lean roadmap went hash-only for a year: no lattices, ML-DSA, Falcon, etc. Signatures use WOTS or SPHINCS.
Hash-only works for signatures/proofs. Public-key encryption is harder — it needs structured trapdoors (groups, lattices, codes…). AI will likely progress against any structure, so for long-term security multiply key sizes by ~10. At those sizes hashes beat lattices where possible.
Hashes are safer: P=NP is unlikely, and pure unstructured objects are more reliable than ones with limited known structure that might hide more weaknesses.
TLDR:
• Prefer hash-based over lattice-based when possible
• Be much more paranoid on lattice param sizes (applies far beyond blockchains)
• Privacy protocols: avoid putting encrypted notes onchain
• Keep funds in unused addresses if easy — but be very careful with migrations
• Multisigs: prefer offchain confirmations so signatures stay private
Post #113831
23
Forwarded from Newsmaker