🔍 Read the full analysis: The Cryptography Challenge Facing Finance And Defence As AI Advances on ThorstenMeyerAI.com
Get hardware and tech essentials delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
TL;DR
A new report on AI-generated mathematics has renewed concerns that algorithms developed with AI could weaken cryptographic systems used in finance, intelligence and defence. No cryptographic break is confirmed, and experts disagree about the scale and timing of the risk.
AI-generated mathematics has prompted new questions about the long-term security of cryptographic systems used in finance, intelligence and defence, after OpenAI published 722 mathematical manuscripts on October 6 and cryptocurrency figures warned that advances in algorithms could challenge assumptions underpinning encryption. The material has not demonstrated that any widely used cryptographic system has been broken, and experts caution that the results require independent verification.
The source report says the manuscripts were produced by an unreleased OpenAI model working on roughly 4,000 problems, with about three hours of ChatGPT Pro compute used per result on average. The papers cover 372 families of problems and include claims related to the Unique Games Conjecture, Hilbert’s tenth problem over the rationals and the Riemann zeta function. These are presented as mathematical claims, not as independently established breakthroughs.
Some developments that drew attention were about computational speed rather than famous conjectures. The report describes claims involving faster-than-expected integer multiplication and Fourier transforms. It also cites a separate result by Virginia Vassilevska Williams and Josh Alman giving a roughly n^1.9992-time algorithm for 3SUM, a problem for which quadratic time had long been considered a likely limit. The report says an Anthropic model contributed the key idea to that work; it is not one of the OpenAI manuscripts.
Cryptographer Scott Aaronson noted that cryptography was absent from the 722-paper release. According to the report, people familiar with the work say AI companies have begun discreetly testing whether internal models can attack important protocols. That testing is not public evidence of a successful attack. The report also says OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a sign error was identified, illustrating why mathematical verification remains necessary.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Risks for Banks and Defence
Public-key cryptography protects communications, financial transactions, software updates and sensitive government systems. If a practical method weakened a widely used scheme, organisations could face costly replacement work and, depending on the system and exposure, risks to data confidentiality or the authenticity of digital signatures. The concern extends beyond cryptocurrency: financial institutions, intelligence services and militaries rely on cryptographic tools whose failure could affect operations and secure records.
The source report distinguishes the potential AI-related risk from the better-known quantum-computing threat. A sufficiently capable quantum computer running Shor’s algorithm could break RSA and elliptic-curve cryptography. By contrast, the AI concern is that improved mathematical reasoning might help discover more efficient algorithms on ordinary computers. Whether that could weaken particular systems, and by how much, remains unknown.
There is also a difference in how the threats might become visible. Quantum hardware progress can be tracked through public research and engineering milestones. A useful algorithm could potentially be developed and kept secret, making an adversary’s capability harder to assess. That possibility is a reason for careful monitoring, not evidence that a hidden cryptographic break exists.
As an affiliate, we earn on qualifying purchases.
Post-Quantum Plans Meet New Questions
Governments and industry have been preparing for quantum computers by shifting away from cryptography thought vulnerable to them. In August 2024, the U.S. National Institute of Standards and Technology finalised standards including ML-KEM for establishing encryption keys, ML-DSA for digital signatures and SLH-DSA, a hash-based signature standard. ML-KEM and ML-DSA are lattice-based; SLH-DSA relies on hash functions.
The source report argues that AI raises a separate question: whether mathematical assumptions used by cryptography might be undermined by new algorithms. That possibility does not mean the standards are known to be insecure. It does mean that migration plans may need to account for continued review of the mathematics, not just progress in quantum hardware.
Cryptocurrency supplied the most visible public warning because blockchain transactions can expose public keys and make affected holdings easier to identify. On October 7, Ethereum Foundation researcher Justin Drake urged the industry to plan for “bunker mode” and consider moving funds to addresses whose public keys have not been exposed. The report estimates that about six million bitcoin are held at addresses with exposed public keys; it does not provide a full methodology for that figure.
Ethereum co-founder Vitalik Buterin responded the following day by advising against a rushed wallet migration. He pointed instead to possible risks involving ML-DSA, fully homomorphic encryption and lattice-based systems. His comments frame the issue as a reason to examine the assumptions behind newer cryptography, not as confirmation that those systems have been compromised.
““calmly begin planning for ‘bunker mode’””
— Justin Drake, Ethereum Foundation researcher
quantum-resistant encryption devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Is Confirmed
The source material does not report a successful AI-assisted attack on RSA, elliptic-curve cryptography, ML-KEM, ML-DSA or another deployed cryptographic standard. It supplies no independently validated algorithm, reproducible attack, or technical evidence showing that the standards have become practically breakable. Claims about AI-produced proofs and faster algorithms also require checking by specialists.
It remains unclear what cryptographic protocols AI companies have tested, whether any tests found new weaknesses, and whether an algorithm capable of weakening a deployed system could be kept secret. The scope of any potential threat would depend on the algorithm, computing resources, implementation and target. Drake’s suggested timeframe is his assessment, not a confirmed forecast. The estimate of exposed bitcoin addresses is also reported without enough detail here to assess how it was calculated.
As an affiliate, we earn on qualifying purchases.
Verification and Migration Reviews
The immediate next step is independent scrutiny of the mathematical work: researchers must check proofs, reproduce claimed algorithms and establish whether any improvement has practical consequences for real cryptographic keys. The withdrawal of the Hodge-conjecture claim after a sign error underscores the gap between generating a result and validating it.
Financial institutions, governments and defence organisations will need to continue their post-quantum migration work while tracking credible research into algorithmic attacks. The source material gives no deadline for a new standard or official change to existing guidance. For blockchain users, Drake and Buterin offered different levels of urgency, but neither statement establishes that funds are currently at risk from a demonstrated AI capability. Any response will depend on verified technical findings and advice from the organisations responsible for the systems.
As an affiliate, we earn on qualifying purchases.
Key Questions
Has AI broken a cryptographic system?
No such break is confirmed in the source material. It describes concerns and reported testing, but no validated attack on a deployed cryptographic standard.
What did OpenAI publish?
OpenAI published 722 mathematical manuscripts on October 6, generated by an unreleased model from roughly 4,000 problems. The claims require expert checking, and the release did not include a demonstrated cryptographic break.
How is the AI concern different from the quantum threat?
The quantum threat depends on building a sufficiently capable quantum computer to run attacks such as Shor’s algorithm. The AI-related concern is that improved mathematical reasoning could help develop faster algorithms that run on conventional computers. Neither a practical AI-assisted attack nor a timeline is confirmed.
Should cryptocurrency holders move funds now?
The source report records conflicting emphasis: Justin Drake advised planning for “bunker mode,” while Vitalik Buterin said he did not recommend scrambling to move funds immediately. The material does not confirm an active cryptographic break; readers should not treat these comments as personalised financial advice.
Are post-quantum standards known to be unsafe?
No. The report raises questions about assumptions underlying lattice-based standards such as ML-KEM and ML-DSA, but gives no evidence that they have been broken. Those standards were finalised by NIST in August 2024 as part of preparation for the quantum threat.
Source: ThorstenMeyerAI.com
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
