Orply.

Crypto Faces an AI Security Risk Without a Known Attack

Jordi HaysJohn CooganTylerTBPNFriday, October 9, 20269 min read

AI-driven advances in mathematics could threaten the cryptography that protects crypto wallets, but the risk is harder to define than the quantum threat the industry has spent years preparing for. On Diet TBPN, host John Coogan relayed warnings from Vitalik Buterin and cryptographer Matthew Green, while arguing that crypto has time to strengthen its defenses rather than rush funds into new wallets. Coogan and co-host Jordi Hays also questioned whether the open-source tools that could expose vulnerabilities should be restricted.

AI math creates a cryptography risk without a defined target

AI’s recent progress in mathematics has raised a security question for cryptocurrency: could new mathematical capabilities undermine the cryptography that protects wallets and blockchains? John Coogan said Vitalik Buterin and others in crypto are sounding the alarm. He cited cryptographer Matthew Green’s assessment: “I think we might lose public key cryptography.” As Coogan relayed it, Green’s warning points to the scale of the potential change: security protocols, and the crypto industry built on them, could require major restructuring.

The uncertainty is not just whether current cryptography can be weakened, but what kind of weakness defenders should look for. Coogan said cryptography was absent from the catalog of AI-enabled math results being discussed. Researchers may have avoided cryptography, he suggested, or found results they have not published while defenses are developed. Jordi Hays raised another possibility: cryptography may simply be holding up.

That is different from the quantum threat crypto has been considering for years. The industry has discussed “Q-Day” and worked on quantum-resistant approaches. As Coogan described it, quantum computing has a recognizable mathematical target, including Shor’s algorithm. With AI-driven math, the threat may be harder to characterize in advance: there could be another algorithm, potentially running on ordinary hardware, that exposes a weakness defenders did not know to test for.

Coogan relayed Buterin’s advice not to rush funds into new wallets, while taking AI-accelerated cryptographic risks seriously and minimizing exposure to vulnerable systems. Buterin’s concerns included ECDSA, ML-DSA, fully homomorphic encryption and lattices. Coogan said Buterin saw a possibility that AI math could significantly affect the concrete security of lattices over the next two years, and that ECDSA could fall faster than expected. The practical message, as Coogan summarized it, was to pay closer attention—not to scramble immediately.

The market response was more measured than the online alarm.

3%
Bitcoin’s reported one-day decline, while remaining up 3% for the month

Coogan and Hays questioned whether the industry’s familiar response—“HODL”—would be enough if the assumptions securing wallets needed to change. Coogan argued that an attacker who opened every Bitcoin wallet might destroy the trust that gives the stolen assets value. Hays noted that someone might still act to cause chaos. The tension is between the incentive to preserve the value of what is stolen and the possibility of an attacker who does not care about that value.

Coogan described a rough six-month lag between closed-source and open-source AI capabilities, with some areas moving faster. He compared Anthropic’s April 7, 2026 release of Mythos Preview with a CrowdStrike report released October 7. According to Coogan, the report described a 26-year-old in China using an open-source, Chinese-developed AI agent in cyberattacks against South Korean banks. He presented the timing as an example of how quickly open-source capabilities might catch up.

As Coogan described the incident, the attackers accessed information about tens of thousands of bank clients, including names, addresses and phone numbers. The reported incident was not a theft of the banks’ money. He stressed that the system accessed and the level of access matter: banks have multiple systems, and he speculated that the compromised one might have been relatively peripheral. Hays joked that it could have been client-gifting software. Coogan contrasted this with crypto wallets, noting that traditional banks may have transaction rollbacks and backups on tape or paper.

The timeline gives crypto a reason to prepare, but the nature of the threat is less settled than the quantum scenario. Coogan said the crypto community has time to go “bunker mode,” while emphasizing that AI math is a newer challenge: with quantum, defenders have had a specific algorithm to plan around; here, they may not yet know the shape of the risk.

The response could also collide with crypto’s politics. Coogan described proposals from some in the AI safety community to register large compute clusters, track data centers, and require licenses or reporting for training and inference. Such measures could make it easier to identify someone running many agents against Bitcoin wallets. But for a community shaped by opposition to government control of money, limits on open-source AI would be a difficult proposal to accept.

Hays distinguished digital attacks from biological risks. Someone trying to exploit cryptography, he argued, is in the familiar territory of hacking—even if the consequences could be financial chaos—rather than the very different task of creating and distributing a pandemic. Coogan added a more speculative concern: an AI agent that broke into wallets could use the resulting capital to obtain more compute or hire people, making a loss-of-control scenario more human-enabled.

Tyler said the crypto industry has some capacity for self-governance and protocol changes, and pointed to a Bitcoin Policy Institute open letter calling for stronger defenses and investment in inference to find a path forward. He said most people in crypto are against limiting open-source models. That leaves an unresolved question: whether the industry will respond chiefly by strengthening its own defenses or support restrictions on the tools that could expose weaknesses.

The discussion also questioned what public math results can tell us about progress elsewhere. Hays argued that mathematics is unusually shareable: researchers have reasons to publish a proof, while someone who finds a commercially valuable result may have reason to keep it private. In his view, the public math results could be only part of the picture, alongside people applying current models in their own fields. Coogan connected that argument to a mid-summer Bitcoin sell-off that some had linked to AI’s ability to attack crypto, followed by a rally. The market, he said, may be responding to several narratives at once.

AI can change the work without removing the reason to do it

The response to AI-generated mathematical proofs was not uniformly celebratory. Coogan relayed a joke by Nabeel Qureshi contrasting mathematicians, artists and chess players: mathematicians and artists object that AI is plagiarism, while chess players wonder whether they can use it to improve their ratings. The joke captures a tension in the discussion: people may object to AI’s role in producing work and still want to use it themselves.

The question of what remains valuable in mathematics came into focus through John Urschel, the former Baltimore Ravens lineman who left professional football to study math at MIT. Coogan discussed a Wall Street Journal account of Urschel reading OpenAI’s recent mathematical papers. Urschel was “absolutely floored,” Coogan said, and understood the proofs well enough to assess them at a level few people could.

Urschel later published a paper, “On the Growth Factor of Random Matrices,” and acknowledged help from OpenAI models. Coogan presented him as an example of a mathematician combining his own expertise with AI assistance. Urschel compared mathematics to chess: computers may be better than humans, but that does not end the enjoyment of trying to find the right move. “I really want to understand the why of things,” Urschel said, as quoted by Coogan. “It doesn’t ruin the why.”

Coogan connected that distinction to using ChatGPT to retrieve obscure facts about Silicon Valley companies. The model could answer questions he had spent years researching, but he still wanted to follow the trail and learn. For him, access to an answer did not replace the value of understanding how the pieces fit together.

The hosts briefly tested the same question against online chess. Hays asked how a platform could distinguish a player using an AI copilot from one playing unaided. One response was that a sudden jump in playing strength, or consistently making optimal moves, could expose assistance. Coogan wondered whether models might instead help a weaker player make slightly better moves while imitating human play. The exchange left the detection question open, but also raised a question of incentive: if someone wants to play the strongest engine, they can already do so; using one to win against people may offer little satisfaction.

The Starbucks–Chipotle idea is still only an exploration

A Financial Times report, discussed by the hosts, said Starbucks had explored taking over Chipotle. The reported proposal was not confirmed as a formal offer, and the people cited in the report warned that a deal of this size could be difficult to complete. At the figures discussed, Chipotle had a market value of about $41 billion; a combined company would be worth roughly $102 billion and, if completed, would rank as the largest restaurant acquisition of all time.

The reported interest would reunite Starbucks chief executive Brian Niccol with Chipotle, where he had previously been CEO. The hosts noted that Chipotle had lost about half its value since Niccol left for Starbucks in August 2024, while questioning whether his departure had caused the decline. They treated the report as an early-stage possibility, not an announced transaction. The complexity of combining two large consumer businesses could prevent a deal from materializing.

The hosts also discussed PepsiCo after Joe Weisenthal shared comments attributed to its CEO: “We don’t feel good about the beverage business,” alongside a commitment to put urgency into improving sodas. They wondered aloud about new flavors, an alcoholic product or a larger soda format. Those were jokes and speculation; the substance was the CEO’s expressed concern about the beverage business and urgency around improving sodas.

Private AI-company figures now have public-market consequences

Reports about OpenAI’s revenue illustrated the difficulty of comparing private-company figures. Coogan said one leak put OpenAI near $70 billion, while another report put it near $50 billion. The hosts said the numbers were unclear and described information passing through investors and limited partners before reaching the press, with figures shifting as people tried to make them comparable.

One possible difference involved cloud revenue. In the hosts’ example, OpenAI might count a dollar spent on its model through AWS as revenue, while Anthropic might treat part of the money it pays Amazon as a cost. The accounting difference could make reported figures look unlike one another even when they describe similar activity. The hosts thought someone may have tried to normalize the numbers, but said the effort appeared sloppy and that it was unclear why the figures had not been corrected sooner.

Private companies are not on the same regular reporting schedule as public companies. Yet Coogan and Hays argued that OpenAI and Anthropic are now large enough for estimates of their performance to affect public companies and market expectations. A leak about an ordinary private company might have little effect on other stocks; a leak about a major AI lab can matter to investors in companies with exposure to the labs.

Coogan described a hypothetical market manipulation: someone could leak an inflated revenue figure, buy on the rumor, then short before more accurate numbers emerge. He explicitly called that securities fraud. His broader point was that private-company information can be consequential enough to move public stocks, creating an unusual incentive to trade on unconfirmed figures. He also noted that there are public-company proxies connected to the AI labs, including SpaceX, Oracle and SoftBank.

That influence fed into a discussion of whether AI labs should go public. Coogan said an IPO could improve corporate governance and distribute gains beyond a small group of insiders, including through retirement accounts and broad market funds. He presented that as a case for wider public ownership, while noting that IPOs can prompt concern about putting the companies into retirement portfolios. The underlying tension is that the labs remain private, but their reported metrics can already affect public-market activity.

The frontier, in your inbox tomorrow at 08:00.

Sign up free. Pick the industry Briefs you want. Tomorrow morning, they land. No credit card.

Sign up free