2 min read

Justin Drake Urges ‘Bunker Mode’ Planning for Ethereum ECDSA Risk

The researcher warned a worst-case cryptographic break could arrive within months, while users do not need to take immediate action.

Mentioned assets
Researcher examines a hardware wallet beside compact computing equipment / TokenPost.ai
Researcher examines a hardware wallet beside compact computing equipment / TokenPost.ai

Ethereum researcher Justin Drake urged crypto holders to prepare for a possible future break of the Elliptic Curve Digital Signature Algorithm, or ECDSA, which protects standard externally owned accounts.

“Today I call upon the blockchain industry to calmly begin planning for ‘bunker mode,’” Drake wrote Wednesday, Oct. 7.

Drake said a worst-case ECDSA break could arrive in “months not years” and allow private-key recovery in about one week with a large GPU cluster. He also stressed that current cryptography has not been broken.

His recommendation is aimed primarily at large holders: gradually move funds to fresh addresses whose public keys have not been exposed through signed transactions. On Ethereum, an account that sends a transaction reveals its public key on-chain. An account that has only received Ether (ETH) exposes an address hash rather than the public key itself.

Ethereum uses ECDSA on the secp256k1 curve for standard externally owned accounts. The long-term concern is that a sufficiently capable quantum computer, or a future mathematical breakthrough, could derive private keys from exposed public keys.

No current quantum computer can break Ethereum’s cryptography, and users do not need to take immediate action. Breaking 256-bit elliptic-curve cryptography could require roughly 1,200 logical qubits, while existing hardware remains far from that capability.

The network is preparing a longer-term transition to post-quantum cryptography. Its roadmap includes account abstraction and EIP-8141 as possible routes for migrating account signatures. EIP-8141 is under consideration for the Hegotá upgrade in the second half of 2026.

The potential exposure extends beyond Ethereum. One February 2026 analysis placed approximately 6.9 million Bitcoin (BTC), or about 33% of circulating supply, in quantum-vulnerable addresses at block height 936,882. Another analysis estimated approximately 6.7 million BTC. The figures reflect different methods and dates.

The risk remains a future threat rather than a confirmed exploit. Drake is calling for controlled preparation, while no immediate user action is required. The network’s broader security planning is outlined in Ethereum’s path to a cryptographic computer.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…