Ledger CTO Charles Guillemet has pushed back against suggestions that recent artificial-intelligence-assisted mathematical results could soon undermine the elliptic-curve digital signature algorithm securing Bitcoin, arguing that any such collapse would first affect far larger systems and that current findings do not indicate an imminent practical break.
Guillemet, who leads technology at the hardware-wallet maker, posted the comments on October 9 after Ethereum researcher Justin Drake called on the industry to plan a controlled migration of funds. The exchange highlights a split over how seriously holders should treat theoretical progress released by OpenAI days earlier.
Guillemet’s Assessment of the Risk
In the post, Guillemet wrote that anyone worried about AI breaking ECDSA and wiping out Bitcoin “in the next few months, at minimal cost” should “take your pills.” He stated that if asymmetric cryptography fell, Bitcoin would be the least of the resulting problems because TLS, banking systems, secure communications, and critical infrastructure would face comparable or greater exposure. “Worrying about your coins at that point is like worrying about your Wi-Fi password while the house is on fire,” he wrote.
He added that nothing indicates researchers are near a breakthrough capable of recovering private keys from public keys on available hardware. The remarks directly address Drake’s October 7 statement that it is now reasonable to brace for the possibility ECDSA breaks before quantum day, in the worst case in months rather than years, defined as fast private-key recovery on something like a large GPU cluster. Drake recommended a controlled mass migration to fresh addresses whose public keys remain hidden behind a hash, while cautioning against rushing.
Guillemet has previously examined longer-term signature migration options for Bitcoin. In mid-September he reviewed a draft proposal known as SHRINCS that combines stateful and stateless hash-based signatures, noting that the network does not face an immediate quantum threat but that any transition could take years.
OpenAI Results and Their Scope
The discussion follows OpenAI’s October 6 release of hundreds of mathematical manuscripts produced by an internal model. One preprint, dated September 23 and titled “Integer multiplication below n log n,” claims an algorithm achieving T(n)=O(n(n)1-) with =2-182 on a fixed multitape Turing machine. The result improves on the long-standing O(nn) bound associated with the 2019 work of Harvey and van der Hoeven, but only by an extremely small power of the logarithm.
Community researchers subsequently tightened the exponent under the same framework. A repository maintained in connection with Douglas Colkitt reported reviewed constructions reaching values above 2-15, still far from practical speed-ups for cryptographic sizes. Guillemet described the original finding as genuinely interesting mathematics that does not change understanding of how to break ECDSA. He noted that a standard requiring every hardness assumption to be proven unbreakable before use would leave hashes equally untrusted.
Drake had cited the integer-multiplication result, along with other recent disproofs, as evidence that mathematical intuition is being upended and that elliptic curves, which contain algebraic structure, may prove more exposed than hash functions designed to minimize it. No public cryptanalysis has demonstrated a classical algorithm recovering secp256k1 private keys from public keys at the scales used by Bitcoin or Ethereum.
Industry Context and Practical Steps
Bitcoin addresses that have never spent funds keep the public key concealed behind a hash until the first outgoing transaction. Once a signature is broadcast, the public key becomes visible on-chain and remains so. Drake’s suggested precaution, i.e. moving the bulk of holdings to never-used addresses and sweeping remaining balances after any spend, relies on that existing property and does not require new cryptography. He pointed to exposed public keys tracked on lists such as Project Eleven’s and named several exchanges and issuers as candidates to review cold-storage practices.
Guillemet’s response underscores that the same signature schemes protect everyday internet traffic and financial messaging. A practical break would therefore surface first, or simultaneously, outside cryptocurrency. Researchers continue to monitor both classical mathematical progress and quantum resource estimates; neither has yet produced a method that recovers production ECDSA keys on hardware available today.
Also read: SlowMist Flags BitBay and EtherVista Hacks as Attackers Drain $32,600 From DeFi Vault & Pool
