🔍 Read the full analysis: Cryptography At A Turning Point For Finance And Defence on ThorstenMeyerAI.com
Get smart everyday buys delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
TL;DR
A report describes a release of 722 AI-produced mathematical manuscripts and renewed scrutiny of whether AI could find algorithms that weaken cryptographic systems. No cryptographic break is confirmed; experts disagree on the urgency, and the security of post-quantum lattice standards remains an open question.
A report says the publication of 722 mathematical manuscripts produced with an unreleased AI model has renewed scrutiny of whether AI could discover algorithms that weaken cryptographic systems. No cryptographic protocol has been shown to be broken, and the report presents the concern as a possible second threat alongside quantum computing—not as evidence that current encryption has failed.
According to the source report, OpenAI published the manuscripts on October 6, grouping them into 372 families from work on roughly 4,000 problems. The report says the internal model used about three hours of ChatGPT Pro compute per result on average. The manuscripts include claims about well-known mathematical problems, but those claims require review and should not be treated as settled proofs.
The report highlights algorithmic results relevant to computational complexity, including faster methods for integer multiplication and Fourier transforms, and a result for 3SUM that it says challenges a long-standing conjecture. It attributes discussion of these results to computer scientist Scott Aaronson. The account also says an OpenAI claim concerning the Hodge conjecture for products of K3 surfaces was withdrawn after a sign error was identified. These examples concern mathematical claims; they do not establish a cryptographic break.
The report says Aaronson observed that cryptography was absent from the published manuscripts and had heard that AI companies were discreetly testing whether internal models could attack cryptographic protocols. That account is not independently detailed in the material provided. Separately, Ethereum Foundation researcher Justin Drake urged the industry to plan calmly for a possible “bunker mode,” while Ethereum co-founder Vitalik Buterin cautioned against rushing to move funds and raised questions about lattice-based post-quantum cryptography.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Why Finance and Defence Are Exposed
Cryptography protects financial transactions, government communications and military systems. A practical algorithmic attack could undermine digital signatures or encryption even if it ran on ordinary computers, rather than requiring a large quantum machine. The potential reach is why the report frames AI-driven mathematical research as a concern for finance, intelligence and defence.
The concern is not that AI has already defeated encryption. It is that a mathematical advance could alter estimates of how much computing is needed to solve a problem on which a protocol’s security depends. If such an advance were kept secret, organisations might have less warning than they would from visible progress in quantum hardware. That possibility is a scenario described by the report, not a confirmed event.
For financial institutions and defence agencies, the immediate implication is scrutiny, not panic: they must understand which systems rely on which assumptions, and how quickly those systems could be updated if the assumptions change. The source offers no evidence of compromised accounts, stolen funds, intercepted communications or a newly practical attack.
As an affiliate, we earn on qualifying purchases.
The Quantum Migration Already Under Way
The established concern is quantum computing. A sufficiently capable, error-corrected quantum computer running Shor’s algorithm could break RSA and elliptic-curve cryptography, both widely used public-key systems. That prospect has led governments and companies to plan migrations to post-quantum cryptography.
The source says NIST standardised three relevant schemes in August 2024: ML-KEM for establishing encryption keys, ML-DSA for digital signatures, and SLH-DSA, a signature scheme based on hash functions. These standards were selected to resist known quantum attacks. The new concern described in the report is that AI might help find classical algorithms that challenge mathematical assumptions behind some schemes, including lattice-based designs. The material does not show that this has happened.
Blockchain systems make some risks easier to observe because public keys can be exposed on-chain. Drake’s warning, as quoted in the report, focused on moving funds to addresses whose public keys have not been exposed. The report estimates that roughly 6 million bitcoin are held at addresses with exposed public keys, but provides no further methodology for that estimate. Buterin’s response was more cautious and extended the discussion to lattice-based standards, rather than endorsing an immediate wallet migration.
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Has Been Shown
The central unknown is whether AI systems can find a useful, new algorithm against a deployed cryptographic scheme, and whether any such discovery has already been made privately. The source says companies are testing models but gives no named protocols, test results, independent verification or evidence that a working attack exists.
It is also unclear how much of the reported mathematical work has been independently checked. The withdrawn Hodge-conjecture claim illustrates that AI-generated results can contain errors. Faster algorithms for selected problems do not automatically translate into attacks on encryption, signatures or key exchange; the connection would need to be demonstrated for each system.
The report does not specify the year of the October 6 and 7 events in the supplied material, nor provide details that would establish the publication’s full review process or the basis for the bitcoin exposure estimate. Its claims about undisclosed company testing and potential timing of an ECDSA break remain attributed assessments, not confirmed capabilities.
quantum-resistant encryption hardware
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Verification and Migration Checks
The next meaningful test is independent verification: researchers would need to examine the AI-generated manuscripts, reproduce any claimed algorithmic improvements and determine whether they affect real cryptographic parameters. Until that work is published, the source supports attention to the issue but not a conclusion that current systems have failed.
Financial firms, government agencies and defence organisations will continue planning post-quantum migrations, while checking which systems use RSA, elliptic curves, lattice-based schemes or hash-based signatures. The report does not identify a new government deadline, standard change or confirmed vulnerability. Any change in recommended practice would depend on technical evidence from researchers and standards bodies.
For cryptocurrency holders, the two public figures’ comments point to different levels of urgency: Drake recommended preparing for a possible protective posture, while Buterin said users should not rush to move funds. The material does not establish that a general wallet migration is required. Further public results, documented testing and guidance from protocol developers will determine whether the concern shifts from precaution to a specific response.
As an affiliate, we earn on qualifying purchases.
Key Questions
Has AI broken a cryptographic system?
No break is confirmed in the source material. It describes concern about AI potentially finding new algorithms, not a demonstrated attack on a deployed protocol.
What did OpenAI publish?
The report says OpenAI published 722 AI-produced mathematical manuscripts in 372 families on October 6, based on work on roughly 4,000 problems. The claims require independent checking, and at least one reported claim was withdrawn after an error was found.
How is the AI concern different from the quantum threat?
The quantum risk depends on building a sufficiently capable quantum computer. The AI concern described here is that a model could help discover a better algorithm that runs on conventional computers. The source provides no evidence that such an attack has been found.
Are post-quantum standards known to be vulnerable?
No. The source raises questions about assumptions behind lattice-based approaches, including ML-DSA, but does not show that ML-DSA or another post-quantum standard has been broken.
Should cryptocurrency users move their funds now?
The quoted views differ: Justin Drake recommended planning for a more protective posture, while Vitalik Buterin said he did not recommend scrambling to move funds. The source establishes no general requirement for users to move assets.
Source: ThorstenMeyerAI.com
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
