However, Jameson Lopp, who has spent the past several months dealing with the aftermath of AI attacks on Bitcoin infrastructure, believes fears of an imminent break in fundamental cryptographic mathematics are inflated and have little to do with reality. While theorists panic over a hypothetical breach of the foundations of encryption, hackers are using AI for much more down-to-earth purposes — automatically searching for ordinary human bugs in application code and wallet firmware.
As someone who has been battling AI acceleration of vulnerability discovery for several months now, I think worrying about cryptographic breaks is getting ahead of ourselves – we have much more pressing actual issues to deal with. Theoretical future problems can wait.
— Jameson Lopp (@lopp) October 8, 2026
Commenting on the broader concern, Lopp emphasized: “Worrying about cryptographic breaks is getting ahead of ourselves — we have much more pressing actual issues to deal with.” In his view, the industry needs to address pressing operational problems, while “theoretical future problems can wait.”
Why “bunker mode” is premature
Lopp’s position is supported by Google Threat Intelligence statistics: the monthly number of disclosed software vulnerabilities has nearly doubled over the past year. Neural networks have become ideal scanners, finding implementation flaws within minutes — such as weaknesses in seed phrase generation in Coldcard wallets — that would have taken humans weeks to uncover.
Lopp believes that focusing on breaking ECDSA is counterproductive while AI is effortlessly exposing poorly written software.
Ethereum co-founder Vitalik Buterin also joined the debate. While acknowledging the long-term risks AI poses to cryptography, he nevertheless agreed that premature action can be more dangerous than the threat itself. Buterin jokingly noted that he personally lost more money due to botched wallet updates than from all hacker attacks combined.
Instead of “retreating to the bunker,” basic security hygiene is recommended: collect multisig signatures off-chain and do not send transactions from savings addresses in order to keep their public keys hidden.
To date, there have been no recorded cases of active ECDSA keys being successfully cracked, which only reinforces the point that the AI threat to Bitcoin through cryptanalysis is currently greatly exaggerated.
As Jameson Lopp sees it, the winners of this race will not be those building barricades against a hypothetical future “super AI,” but those who are cleaning up the security of existing software right now.

