What signing exposes
An address whose public key has not been revealed exposes only a hash of that key. The hash cannot be used to recover the public key, leaving the funds protected from this particular attack.
Once the address signs a transaction, the public key becomes visible. In theory, an attacker could then use it to calculate the private key and access the funds.
Buterin’s caution
Ethereum co-founder Vitalik Buterin agreed with Drake in a reply on X, but warned against rushing. He said he had lost more money through failed transfers than through hacks.
Buterin’s longer-term preference is for an architecture that relies on hash functions wherever possible. Even lattice-based schemes, often considered resistant to quantum computers, could weaken as AI advances.
I think the useful distinction here is between a cryptographic vulnerability that exists today and a future risk that researchers are trying to anticipate. The announcement offers no evidence that AI can currently derive private keys from exposed public keys. What I’d want to know is how much warning wallet users would get before that changed: Drake’s advice matters most if the threat arrives faster than wallets and users can adapt.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X