
Ethereum co-founder Vitalik Buterin and Cardano founder Charles Hoskinson have entered a highly technical public debate over one of crypto’s biggest long-term security questions: what happens if artificial intelligence dramatically improves humanity’s ability to attack cryptographic systems?
Buterin warned that AI-accelerated mathematics could uncover weaknesses in cryptographic assumptions far faster than researchers currently expect.
Hoskinson strongly rejected that framing, arguing that Buterin is treating speculation as a security model and unfairly casting doubt on lattice-based cryptography.
What you'll learn 👉
Vitalik Warns AI Could Change Cryptographic Security Faster Than Expected
Buterin’s argument starts from a simple concern.
AI systems could accelerate mathematical research enough to discover attack methods that humans have not yet found.
He compared this possibility with the history of integer factoring.
Naive factoring appears extremely difficult, but decades of mathematical progress produced algorithms such as the number field sieve that dramatically reduced the practical security of RSA.
Buterin’s concern is that similar undiscovered techniques may exist for elliptic curves or lattice-based cryptography.
If AI delivers decades of mathematical progress in only a few years, cryptographic systems thought to be secure today could turn out to have weaker concrete security than expected.
This is one reason Buterin favors Ethereum’s move toward hash-based cryptography where possible.
I don’t recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it’s also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover – but bots soon will be? This is a major part of the reason why for the past year ethereum’s lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* – and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" – either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that’s a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it’s possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it’s much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs … * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it’s easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures – a much better place to be than "anyone can take the money" https://t.co/oVjwZog2lL
— vitalik.eth (@VitalikButerin) October 7, 2026
He argued that hash-based constructions contain less exploitable mathematical structure than systems built around elliptic curves or lattices.
For signatures, he pointed toward hash-based approaches such as WOTS and SPHINCS-style systems.
Buterin was much more cautious about public-key encryption because that problem cannot simply be replaced with hashes.
His personal conclusion was that lattice-based systems may need much larger parameters to remain safe under a world where AI speeds up mathematical discovery.
He even floated the idea that key sizes might need to become dramatically larger.
Hoskinson Says the Lattice Warning Has No Concrete Attack Behind It
Hoskinson’s response was lengthy and highly critical.
His main objection is that Buterin does not identify an actual attack.
Hoskinson argues that saying AI may discover hidden structure is not enough.
Security engineering, in his view, should identify a specific attack, estimate its computational cost, and then adjust parameters based on that model.
Without that, he views the warning as speculation.
Hoskinson also disputes Buterin’s comparison between lattice cryptography and the history of integer factoring.
He argues that the number field sieve emerged from very specific mathematical properties involving smooth numbers, factor bases, and congruences.
If someone believes lattices contain an equivalent hidden weakness, Hoskinson says they need to explain what mathematical structure could enable it.
Hoskinson Defends Lattice-Based Cryptography
Hoskinson also explained that lattice cryptography has been studied aggressively for decades.
He pointed to major advances including LLL, BKZ, lattice sieving, and improved enumeration methods.
His argument is that these developments were already incorporated into parameter selection for modern post-quantum schemes.
He specifically mentioned ML-KEM and ML-DSA, which are designed around known lattice attacks and modern cost estimates.
Hoskinson also pointed toward theoretical connections between breaking certain lattice problems and solving hard geometric problems on lattices.
In his view, this gives lattice cryptography a stronger mathematical foundation than Buterin’s post acknowledges.
Hoskinson Says Hash-Based Systems Have Their Own Risks
Another major part of Hoskinson’s response targeted Buterin’s preference for hashes.
Hoskinson argued that hashes are not automatically free from structure.
Vitalik is now trying to convince everyone that lattices are bad because he is bag-holding too much hash-based crypto research can’t back out. The case against lattices is the GNFS story, a.k.a. a hunch about "structure," and a multiplier pulled out of thin air. None of it has ever held up in the last few decades. The factoring analogy is wrong. The number field sieve didn’t come from generic cleverness. It came from very specific arithmetic -> smooth numbers, factor bases, relations stitched together by linear algebra into a congruence of squares. If you claim lattices have a GNFS hiding in the closet, you have to name what plays that role. "Structure" names nothing. The sieve was finished by 1993, and RSA sizes have barely moved in the thirty years since, so the lesson of factoring is that the skeletons ran out. Even the formula in the post is wrong. GNFS is exp(O(n^(1/3) (log n)^(2/3))), and if you’re going to size parameters by analogy, you could at least get the analogy’s complexity right. Lattices had their sieve era decades ago. LLL in 1982, BKZ, pruned enumeration, sieving at 2^0.415n in 2008 and 2^0.292n in 2016. Every one of those was priced into parameters the moment it appeared. ML-KEM and ML-DSA are sized against exactly these attacks with a cost model that hands the attacker free memory and drops polynomial factors. The post talks as if nobody has ever seriously looked at lattices. Forty years of the best people in the field moved is the constant in the exponent. The post also skips the one thing lattices have that GGEV and Peikert proved: breaking random LWE or SSIS instances at the right parameters solves approximate shortest-vector problems on every lattice of that dimension. A "skeleton" for plain LWE wouldn’t be some clever trick for one family. It’s a theorem for one of the most attacked problems in computer science. SHA-256 has no theorem like that. Its security is that nobody has broken it yet, which is exactly the standard the post refuses to extend to lattices. If you actually want to worry about structure in lattices, then look at the algebra of rings and ideal lattices. Cramer, Ducas, Peikert, and Regev (2016) and Cramer, Ducas, and Wesolowski (2017) gave quantum attacks on Ideal-SVP in cyclotomic fields. Albrecht, Bai, Ducas, and Kirchretched NTRU. Those results killed real schemes, and none of them touch ML-KEM or ML-DSA, which are module schemes with small moduli. Ducas, Plançon, and Wesolowski showed the quantum ideal attack does worse than plain BKZ at every dimension, applied the structure, measured how far the attacks reach, standardized outside their range, kept FrodoKEM with no ring at all, and added HQC in 2025 so KEMs don’t rest on lattices alone. Vitalik is either unaware of this or hash-crypto bagholding is causing citation amnesia. Then there’s the claim that hashes are "intended" to have no structure, as if intent were a security proof. Differential cryptanalysis destroyed both MD5 and SHA-1 by attacking their round functions, with no help from P = NP. Of every family he lists, hashes are the only one whose deployed primitives have actually been broken. And the hash-only roadmap he’s defending runs on Poseidon and Poseidon2, low-degree polynomial maps over small prime fields, built specifically to be easy to express algebraically. They are the most algebraically structured hashes anyone has ever put into production. Gröbner-basis and interpolation attacks are an active research area, and the Ethereum Foundation even funded a cryptanalysis bounty on Poseidon because of it. If AI is going to eat structure, Poseidon gets eaten long before Module-LWE. The proof systems are no better. FRI, STIR, and WHIR at aggressive parameters rest on Reed-Solomon proximity-gap conjectures nobody has proven, and Fiat-Shamir is argued in the random oracle model. That’s what "hash-only" actually means in practice. And "we’d pad the round count first" gives the game away, because extra rounds only defend against structure. He’s admitting the structure is there. The theory gets mangled too. Impagliazzo and Rudich is a black-box separation about proof techniques. It is not a theorem that public-key encryption "needs structure," and Merkle’s puzzles already give hash-only key agreement with a quadratic gap, which Barak and Mahmoody showed is optimal in that model. "P ≠ NP so hashes are safe" is wrong as well, because P ≠ NP doesn’t imply one-way functions exist, let alone that SHA-256 is one. That gap is the entire subject of Impagliazzo’s five worlds. And the claim that an object with zero known structures is safer than one with exactly three is a probability claim with no underlying probability model for generic prime-field elliptic curves; the record runs the other way: every subexponential ECDLP attack since 1985 needed a special curve; everyone identified and excluded it, and Shoup’s generic-group bound says precisely what a new attack would have to exploit. Nobody has found one in forty years. "Multiply key sizes by ten" is numerology. Lattice attack cost goes like 2^(c·β). A better constant means you scale dimension by c/c’, so a 20 percent improvement costs you about 25 percent more dimension, not 10x. A subexponential break means no multiplier saves you, because 10^n is still subexponential. Neither case gives you ten. Bytes aren’t even a security parameter, since raising the modulus at fixed noise can make LWE easier. Parameter selection is a complexity formula set against a security target, and this post contains no formula. "AI will deliver fifty years of math in two years" isn’t a threat model. It names no algorithm or cost, and it can never be falsified, because every year without a break is just "not yet." It also cuts against hashes at least as hard as against lattices, and the post never explains why it shouldn’t. The field already has a working process for extraordinary claims. In 2024, a preprint claimed a quantum polynomial-time algorithm for LWE, and the bug was found in about ten days. Rainbow and SIKE fell on laptops during the NIST process, under the same public scrutiny that let the lattice schemes survive. An AI-found attack follows the same process: check it, run it through the estimators, and reparameterize. Abandoning the most studied post-quantum family before an attack exists is panic. And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can’t be avoided, then tells TLS, Tor, VPN, and messaging operators to get "much more paranoid" about the only post-quantum KEM that is actually deployed. Harvest-now-decrypt-later is happening right now, and hybrid ML-KEM, already shipping in browsers and messengers, is the defense. Spreading doubt about it, or bloating it tenfold until handshakes break, keeps traffic on classical crypto longer, which is the outcome he says he’s worried about. "Send encrypted notes offchain through a third party" fixes nothing, because delivering to someone you’venever spoken to still needs public-key encryption, and now you’ve added a trusted party that sees your metadata and can drop your messages. Lumping ML-DSA and FHE into one bucket shows a weak grasp of both, since they live in completely different parameter regimes with different attacks. Use hash-based signatures where they fit; the IETF has worked on XMSS for years, and there have been many great advancements. They are an algebraic dead end, however. You can’t easily do the things we treasure in the elliptic-curve world. Security engineering means naming the attack, costing it, and sizing the fix within the context of broader business and technological objectives. Vitalik never does this. He writes these damn posts that convince lots of engineers to abandon incredibly important research, and then we have to stumble back to it after years of false starts: Plasma, Ethereum 2.0, Casper, Accounts, etc etc etc. Now we are going to attack Lattices.
— Charles Hoskinson (@IOHK_Charles) October 9, 2026
He pointed to historical examples such as MD5 and SHA-1, which were eventually broken through advances in cryptanalysis.
He also referenced Poseidon and Poseidon2, hash functions designed for efficient use inside zero-knowledge systems.
Because these constructions have algebraic structure, Hoskinson argues that they are not obviously immune to the kind of AI-assisted mathematical research Buterin is worried about.
He also challenged the idea that adding more rounds automatically solves the problem.
If a hash function contains exploitable structural weaknesses, extra rounds may improve security, but that still means the structure itself must be understood.
The Two Founders Disagree on How to Prepare for Unknown Attacks
The disagreement is ultimately philosophical.
Buterin is arguing for caution in the face of unknown mathematical advances.
His position is that cryptographic systems with less visible structure may be safer if AI suddenly becomes much better at mathematical discovery.
Hoskinson wants a much more concrete standard.
He argues that cryptographic engineering should not abandon or weaken confidence in a major security family without a specific attack, complexity estimate, or reproducible result.
He also believes overly cautious warnings could have real-world consequences.
Lattice-based systems are already being deployed to defend against harvest-now-decrypt-later attacks, where encrypted traffic is collected today in the hope that future quantum computers can decrypt it.
Hoskinson worries that discouraging lattice adoption without evidence could delay the transition away from classical cryptography.
Hoskinson Also Rejects the “10x Key Size” Idea
One of Hoskinson’s strongest criticisms targets Buterin’s idea of multiplying key sizes by ten.
He calls that approach arbitrary.
His argument is that cryptographic parameters should be adjusted mathematically based on how much an attack improves.
If an attack becomes 20% more efficient, for example, the correct response is not automatically to multiply the entire key size by ten.
The adjustment depends on the actual relationship between attack cost, dimension, modulus, noise, and other scheme-specific parameters.
Hoskinson argues that a huge fixed multiplier does not represent serious cryptographic parameter selection.
Overall, both positions point toward the same uncomfortable reality.
Crypto and the wider internet are entering a period where cryptographic assumptions may face pressure from both quantum computing and increasingly capable AI.
The disagreement is over how aggressively engineers should react before a concrete new attack actually appears.
For more crypto news and price predictions, click here.
Subscribe to our YouTube channel for daily crypto updates, market insights, and expert analysis.

