🔍 Read the full analysis: Why Finance And Defence Are Rethinking Cryptography In The Age Of AI on ThorstenMeyerAI.com
Get hardware and tech essentials delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
TL;DR
An October report about AI-generated mathematical work has prompted new debate over whether AI could uncover algorithms that weaken cryptographic systems. No cryptographic break has been reported, and experts disagree about how quickly the risk could materialize. Finance, intelligence and defence agencies face the challenge of preparing without treating speculation as proof.
A report describing 722 AI-produced mathematical manuscripts has prompted researchers to question whether artificial intelligence could uncover algorithms that weaken cryptographic systems used by banks, governments and militaries. No cryptographic protocol has been shown to be broken, but the discussion is challenging the assumption that post-quantum systems based on lattices are automatically safe from every emerging threat.
According to the source material, OpenAI published the manuscripts on October 6, describing work from an unreleased internal model across 372 families of problems. The reported results include claims about long-standing mathematical questions and faster approaches to certain computational problems. These remain claims requiring expert verification. The source also notes that OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a sign error was identified.
The results most relevant to cryptography are not proof that encryption has failed. Rather, they concern the possibility that algorithms long thought difficult may be more tractable than expected. Computer scientist Scott Aaronson highlighted reported advances involving integer multiplication and Fourier transforms, while a separate result on 3SUM was attributed to work by Virginia Vassilevska Williams and Josh Alman, with a key idea reportedly originating from an Anthropic model. Cryptographic security relies on mathematical problems being computationally hard, so improved algorithms could matter even if they do not directly reveal secret keys.
The source says Aaronson also observed that cryptography was absent from the published collection and reported that AI companies were discreetly testing models against important protocols. That account is not evidence that a successful attack exists. Public comments from Ethereum researchers brought the concern into view: Justin Drake urged planning for a possible future threat to exposed public keys, while Vitalik Buterin cautioned against an immediate rush to move funds and pointed to possible risks for lattice-based systems.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Security Planning Beyond Quantum Risk
Finance and defence organizations have been preparing for quantum computers because a sufficiently capable machine running Shor’s algorithm could break widely used public-key systems such as RSA and elliptic-curve cryptography. That threat has a recognizable hardware pathway: researchers can track quantum processors, error rates and engineering progress. An AI-discovered algorithm could run on conventional computers and might remain undisclosed, making it harder for institutions to identify a countdown or know when a migration deadline has arrived.
The practical consequence is not that banks or militaries should abandon current protections overnight. It is that security plans may need to account for uncertainty about the mathematical assumptions beneath both existing and replacement systems. A weakness in a signature scheme could affect authentication and software updates; a weakness in key-establishment systems could threaten confidential communications. For intelligence and defence, the possibility that an adversary could keep a discovery secret adds a planning problem distinct from the visible race to build quantum hardware.
These consequences remain conditional. The source reports no successful AI-driven cryptographic attack, and mathematical results do not automatically translate into practical attacks against deployed systems. The concern is that a major change in algorithmic understanding could make existing assessments stale before organizations have finished migrating.
quantum-resistant cryptography hardware
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
From Quantum Migration to AI
Governments and companies have been moving toward post-quantum cryptography in response to the quantum threat. The source says the U.S. National Institute of Standards and Technology standardized key replacements in August 2024: ML-KEM for establishing encryption keys, ML-DSA for digital signatures, and SLH-DSA, a signature scheme based on hash functions. The standards represent a planned response to quantum attacks; their adoption does not establish immunity to all future mathematical advances.
The new debate draws a distinction between system families. The source characterizes lattice-based methods as potentially exposed if better algorithms are found, while hash-based schemes may have different security properties. That is a risk assessment, not confirmation that a weakness exists in ML-KEM, ML-DSA or any deployed system. It also explains why some cryptocurrency researchers have discussed limiting exposure of public keys. Blockchain addresses can make certain public information visible, but the source’s suggested precautions and estimates should not be read as proof of an active attack.
“Calmly begin planning for ‘bunker mode’.”
— Justin Drake, Ethereum Foundation researcher
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Reported
No successful attack on RSA, elliptic-curve cryptography or the cited post-quantum standards is established in the supplied material. The AI-generated mathematical claims are still being checked, and the source describes at least one withdrawn proof. It is also unclear whether AI systems have found a practical cryptographic attack, whether any organization has verified such a result, or whether a government or company has kept one secret.
The source’s account of private testing by AI companies is attributed indirectly and provides no named protocols, results or independent confirmation. Drake’s estimate of a possible ECDSA break is a warning, not a measured forecast. The material also does not provide enough detail to assess the reported bitcoin exposure estimate or establish a timeline for any threat. These gaps make it important to distinguish preparedness discussions from evidence of a current compromise.
As an affiliate, we earn on qualifying purchases.
Verification and Migration Decisions
The immediate next step is independent review of the reported mathematical work and any claimed applications to cryptography. Security researchers and standards bodies will need to establish whether a new result changes the practical cost of attacking a protocol, rather than relying on a theoretical improvement alone. The supplied material does not identify a formal review schedule or a new migration deadline.
Financial institutions, intelligence agencies and defence organizations are likely to continue post-quantum migration while reviewing how they evaluate the assumptions behind replacement systems. For readers, the clearest current status is that research and planning are accelerating, but the evidence presented does not support claims that cryptographic protections have already failed. Further verified findings—not the possibility of an AI breakthrough by itself—will determine whether standards or deployment plans need revision.
As an affiliate, we earn on qualifying purchases.
Key Questions
Has AI broken encryption or a major cryptographic protocol?
No. The supplied source reports no confirmed cryptographic break. It describes mathematical results and warnings about possible future algorithms, many of which require verification.
Why are banks and defence agencies concerned?
They rely on cryptography to protect communications, authenticate users and secure systems. A better algorithm could weaken assumptions underpinning those protections, potentially without the visible hardware milestones associated with quantum computing.
Are post-quantum standards such as ML-DSA known to be vulnerable?
No vulnerability is established in the source material. The standards were designed to address quantum threats, while researchers are discussing whether mathematical advances could affect the assumptions behind lattice-based systems.
Should cryptocurrency users move funds immediately?
The source does not establish an active attack. Vitalik Buterin specifically said he did not recommend an immediate rush to move funds. Any security decision should rely on verified guidance rather than unconfirmed warnings.
Source: ThorstenMeyerAI.com
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
