Dragonfly's Qureshi Calls for Network-Level Safeguards as ECDSA Risk Debate Intensifies
AI Market Summary
Renewed debate over whether AI progress could accelerate breaks of ECDSA signatures raises tail-risk concerns for wallet security and network integrity. While some argue for user-level mitigation via fresh addresses, others stress systemic exposure and call for protocol-level recovery mechanisms. Glassnode-cited estimates that millions of BTC are linked to reused or otherwise exposed keys, with a significant portion on exchanges, heightening perceived operational and liquidation risks.
Impact level
● High
Affected assets
BTC/USDT-0.45%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Concerns that fast-moving AI advances—and eventually quantum computing—could weaken the cryptographic signatures securing crypto wallets are back in focus after fresh comments from Ethereum researcher Justin Drake.
Drake said this week that the elliptic curve digital signature algorithm (ECDSA) could, in a worst-case scenario, be broken on a timeline measured in months rather than years. He cited recent progress referenced in an OpenAI report on AI's performance in mathematics as a reason the industry should treat the risk as more immediate.
Dragonfly managing partner Haseeb Qureshi disputed the idea that the primary answer is simply moving funds to new addresses. He argued that shifting coins to fresh public keys offers limited protection if the broader ecosystem remains exposed, and urged protocol-level defenses designed to keep the network functional even under signature compromise.
Key points
- Drake warned ECDSA could fail "in the worst case" within months, not years, pointing to rapid AI progress in mathematics.
- Qureshi criticized a "bunker mode" approach as investor-focused and insufficient if large portions of the market remain vulnerable.
- Glassnode figures cited in the discussion indicate 6.26 million BTC may be exposed, including 4.33 million BTC tied to address reuse.
- Qureshi proposed a "Cryptographic Recovery Mode" that would allow validator-enforced recovery using hash-based backup signatures.
- Glassnode estimates nearly 1.8 million BTC on exchanges sits in exposed exchange balances.
Drake: a faster ECDSA timeline
Drake's argument centers on ECDSA, a signature scheme widely used for wallet authorization across the crypto ecosystem. Posting on X, he said it is "reasonable to brace" for ECDSA to break earlier than commonly assumed, with a worst-case horizon of months.
As a practical step, Drake suggested users gradually move funds to fresh wallets so the related public key is not exposed. The logic: if signature security deteriorates faster than expected, long migration timelines could leave more assets exposed.
Ethereum co-founder Vitalik Buterin said he agrees the industry should take AI-accelerated math seriously, but stopped short of endorsing an immediate rush for users to relocate funds. The split underscores the central question now facing the sector: what individuals should do immediately versus what needs to change at the protocol and infrastructure layers.
Qureshi: address migration won't solve a systemic failure
Qureshi pushed back on the framing that moving coins to new addresses is a self-contained solution. In a Thursday post on X, he described Drake's warning as "cryptographic doomerism" and argued that migrating only helps if holders do not need to move those assets again after switching.
His concern is broader than individual key hygiene. If a signature break becomes widespread and enables mass theft and forced selling, Qureshi warned even coins sitting behind newly generated addresses could become effectively worthless in practice. In that scenario, protecting a single wallet does not prevent the market-wide damage caused by a broken signature scheme.
Glassnode: millions of BTC exposed
Qureshi pointed to Glassnode data suggesting more than 31% of Bitcoin's supply may face some form of exposure. The figures cited include 6.26 million BTC in vulnerable addresses.
Glassnode co-founder Rafael Schultze-Kraft said about 4.33 million BTC of that total is exposed through address reuse, where generating a fresh address can reduce the specific reuse-related risk. Separately, roughly 1.94 million BTC is exposed through address format, a distinct vector that is not resolved simply by making a new address.
Schultze-Kraft also highlighted concentration risk: nearly 1.8 million BTC of exposed holdings sit on cryptocurrency exchanges. Glassnode added that 57% of all exchange balances are currently exposed, a notable figure given exchanges' role in custody, liquidity, and operational decision-making during periods of stress.
From migration to protocol recovery: "Cryptographic Recovery Mode"
Rather than relying mainly on end-user migration, Qureshi argued the industry should prepare network-level defenses for a world where signatures can be broken—whether by AI-driven computation in the nearer term or quantum capabilities later.
His proposed "Cryptographic Recovery Mode" would attach a hash-based backup signature plan to addresses, enabling validators to force recovery if standard cryptographic signatures can no longer be trusted. The goal is to create a path to regain control even if normal signature verification fails, reducing reliance on timing-dependent user actions.
What to watch
Drake's "months, not years" framing has increased urgency around cryptographic resilience. The next developments to monitor are concrete specifications that wallets, exchanges, and networks can implement—especially for the large share of Bitcoin held on exchanges—and whether recovery concepts like Qureshi's can be translated into deployable protocol changes without introducing new operational risks.