ドレイク氏、AIによる暗号解読リスクを警告
イーサリアム財団(Ethereum Foundation)の研究者であるジャスティン・ドレイク(Justin Drake)氏が、人工知能(AI)による数学研究の急速な進歩を背景に、暗号資産(仮想通貨)の取引に利用される暗号技術が想定より早く破られる可能性を10月7日に自身のXアカウントで警告した。また同氏は、暗号資産の保有者に対し、公開鍵が露出していない新しいアドレスへ資産を計画的に移すよう提案した。
ドレイク氏が警戒しているのは、ビットコイン(Bitcoin)やイーサリアム(Ethereum)で利用されている電子署名方式「ECDSA(Elliptic Curve Digital Signature Algorithm)」が、量子コンピューターによる暗号解読が可能になる前に破られる可能性だ。同氏は最悪のシナリオとして、数年後ではなく数カ月以内にECDSAを効率的に解読する方法が発見される可能性も想定している。具体的には、大規模なGPUクラスターなど既存の計算設備を使い、1週間程度で秘密鍵を復元できる状況を例に挙げた。
こうしたリスクに備えるため、ドレイク氏はブロックチェーン業界に対し、「バンカーモード(bunker mode)」と呼ぶ予防的な対応への準備を呼びかけた。具体的には、大口保有者や専門的な知識を持つ事業者から、資産の大部分を一度も取引に署名したことのないアドレスへ移行することを推奨している。また、移行先のアドレスで取引に署名した場合には、残った資産も別の新しいアドレスへ移すべきだと述べた。
ドレイク氏は、この対策には新しい暗号技術やウォレットの導入は必要なく、既存のウォレットで生成した別のアドレスも利用できると説明した。ただし、性急な資産移動はかえって危険を招く可能性があるとして、慎重に準備を進めるよう呼びかけた。なお、今回の提案は同氏個人による予防的な対応策であり、ECDSAがすでに破られたことを示すものではない。
ECDSAと量子コンピューター、AIによる新たなリスクとは
ECDSAは、現在のイーサリアムで一般的な利用者の取引に採用されている電子署名方式で、暗号資産の安全な管理や送金を支える重要な技術だ。利用者は自身だけが管理する秘密鍵を使って取引に署名し、ネットワークの参加者は対応する公開鍵を使って署名を検証する仕組みだ。
ECDSAの安全性は、特定の数学的な問題を効率的に解く方法が見つかっていないことに支えられている。具体的には、「楕円曲線上の離散対数問題」と呼ばれる問題を利用しており、秘密鍵から公開鍵を計算することは容易だが、公開鍵から秘密鍵を逆算することは、現在知られている通常の計算方法では極めて難しい。仮に公開鍵から秘密鍵を復元できるようになれば、第三者が本人になりすまして取引に署名し、資産を不正に移動できるおそれがある。
しかし、十分な性能を持つ量子コンピューターが実現すると、ECDSAの安全性を支える数学的な問題を効率的に解ける可能性がある。量子コンピューターでは、「ショアのアルゴリズム(Shor’s algorithm)」を使うことで、楕円曲線上の離散対数問題を効率的に解けることが理論上知られている。ブロックチェーン業界では、量子コンピューターが既存の暗号技術を破れるようになる時点を「Qデー(Q-Day)」と呼び、量子耐性を備えた暗号技術への移行が議論されている。
一方、ドレイク氏は、AIによる数学研究の進歩が、従来のコンピューターでも利用できる新たな暗号解読方法の発見につながる可能性を警戒している。同氏は、オープンAI(OpenAI)が10月6日に公開した722件の数学研究の原稿に言及し、AIによって数学研究が急速に進展しているとの認識を示した。仮にAIが楕円曲線上の離散対数問題を効率的に解く新たな計算方法を発見すれば、既存のコンピューターでも秘密鍵を復元できる可能性がある。
ドレイク氏が移行先として推奨した未使用アドレスには、公開鍵の露出を抑えられるという特徴がある。ブロックチェーンのアドレスは資産の送受信先を示す情報だが、公開鍵そのものとは限らない。例えば、イーサリアムの一般的な外部所有アカウント(Externally Owned Account:EOA)では、公開鍵をハッシュ関数で処理してアドレスを生成する。ハッシュ関数は、データを一定の長さの値に変換する仕組みで、変換後の値から元のデータを復元することは極めて難しい。そのため、アドレスが公開されていても、元の公開鍵まで明らかになっているとは限らない。
ただし、イーサリアムのEOAから取引を送信すると、その電子署名の情報から公開鍵を復元できる。このため、取引を送信したことがなく、公開鍵も露出していないアドレスでは、公開鍵から秘密鍵を復元する攻撃に対して追加的な保護が期待できる。なお、ビットコインではアドレスの形式によって公開鍵の露出状況が異なるため、すべてのアドレスに同じ仕組みが当てはまるわけではない。
ヴィタリック氏もAIによる暗号技術への脅威に言及
イーサリアムの共同創設者であるヴィタリック・ブテリン(Vitalik Buterin)氏も10月8日、ドレイク氏の投稿を受け、自身のXアカウントで見解を示した。同氏は、AIによる数学研究の進歩が暗号技術の安全性に与えるリスクを重視する一方、現時点で慌てて資産を新しいウォレットへ移すことは勧めないと述べた。
ブテリン氏は、一度も取引に署名していないアドレスで資産を保管することについて、容易に実施できる場合には有効な予防措置になるとの考えを示した。ただし、急いで移行作業を行うと、設定ミスなどによって資産を失う危険があると指摘した。同氏自身も、ハッキングより移行作業の失敗によって多くの資産を失った経験があるとして、慎重な対応を呼びかけた。
また、ブテリン氏は、量子コンピューターへの耐性が期待されている「格子暗号」についても、AIによる数学研究の進歩が安全性を脅かす可能性を指摘した。格子暗号は、格子と呼ばれる数学的な構造に関する問題を解くことの難しさを利用した暗号技術だ。同氏は、今後2年間のAIによる数学研究の進歩によって、格子暗号を効率的に解読する新たな方法が発見される可能性を指摘した。その場合、従来と同じ安全性を維持するために、より大きな鍵が必要になる可能性があるとの見解を示した。
そのうえでブテリン氏は、利用可能な場面では格子暗号よりもハッシュベースの暗号技術を優先すべきだと主張した。ハッシュベースの電子署名は、ハッシュ関数の計算結果から元の情報を求めることが難しいといった性質を安全性の根拠としている。このため、楕円曲線暗号や格子暗号を破る新たな計算方法が発見されても、それだけでハッシュベースの電子署名が破られるわけではない。ただし、ハッシュベースの暗号技術だけですべての用途に対応できるわけではなく、例えば公開鍵を使ったデータの暗号化などでは、別の暗号技術が必要になる。
ブテリン氏は、こうしたリスクへの対応が、イーサリアムの長期的な技術構想「リーン・イーサリアム(Lean Ethereum)」でハッシュベースの暗号技術を重視している理由の一つだと説明した。リーン・イーサリアムは、イーサリアムの仕組みを簡素化し、処理能力や安全性の向上を目指す長期構想だ。その重要な課題の一つに、量子コンピューターへの耐性強化がある。一方、ドレイク氏は、AIによる数学研究の進歩を踏まえ、こうした暗号技術への移行を加速させる必要があるとの個人的な見解を示した。
Today I call upon the blockchain industry to calmly begin planning for “bunker mode”. My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don’t rush. While I believe there is cause for action a rushed migration would do more harm than good. Don’t panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By “break” I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May’s unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday’s OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I’ve witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11’s “risq list” (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I’ll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from “Satoshi’s shield”, i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I’ll be pushing for maximum defensive acceleration.
— Justin Drake (@drakefjustin) October 7, 2026
I don’t recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it’s also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the “fresh address” recommendation) So far most people have been in the mode of thinking “elliptic curves broken, hashes safe, lattices safe”. But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be? This is a major part of the reason why for the past year ethereum’s lean roadmap has been going in the “hash-only” direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable “structure” – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that’s a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a “naive factoring -> GNFS” level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it’s possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it’s much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs … * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig “gracefully degrades” to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than “anyone can take the money” https://t.co/oVjwZog2lL
— vitalik.eth (@VitalikButerin) October 7, 2026
画像:PIXTA