AIThis post was created with the assistance of artificial intelligence (AI).

🔍 Read the full analysis: The Security Foundations Of Finance And Defence Face New Pressures on ThorstenMeyerAI.com

Before you orderOffer from Amazon

Get audio and creator gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TL;DR

An October release of AI-generated mathematical work and reports of faster algorithms have prompted fresh scrutiny of cryptographic assumptions used in finance, intelligence and defence. Researchers have not shown that RSA, elliptic-curve systems or post-quantum standards have been broken; experts disagree on how soon AI could change the risk.

AI-generated mathematical work released on October 6 and warnings from cryptocurrency researchers the following day have renewed debate about the assumptions behind digital security. The results have not broken any cryptographic system, but they have sharpened a concern for banks, intelligence agencies and militaries: AI may help discover algorithms that weaken the mathematical problems on which encryption and digital signatures rely.

OpenAI published 722 mathematical manuscripts across 372 families, according to the source report. The work came from an unreleased internal model that attempted roughly 4,000 problems. The reported results include claims concerning the Unique Games Conjecture, Hilbert’s tenth problem over the rationals and the Riemann zeta function. They remain claims requiring expert verification. OpenAI withdrew one claimed result, a proof concerning the Hodge conjecture for products of K3 surfaces, after a sign error was identified, the report says.

For cryptography, the more relevant developments involve algorithms that may improve the speed of computation. Computer scientist Scott Aaronson highlighted claims about faster integer multiplication and Fourier transforms. Separately, a paper by Virginia Vassilevska Williams and Josh Alman described a result for 3SUM, a problem long associated with a roughly quadratic-time limit; the source says an Anthropic model supplied the key idea. These are not, by themselves, attacks on encryption. They do show why researchers are examining whether AI can help find faster methods for problems thought to be computationally difficult.

Aaronson also observed that cryptography was absent from the 722 manuscripts and said his sources indicated that AI companies were discreetly testing models against cryptographic protocols. That account is not a public confirmation that a model has broken a protocol. On October 7, Ethereum Foundation researcher Justin Drake urged the cryptocurrency sector to consider protective measures, while Ethereum co-founder Vitalik Buterin cautioned against an immediate rush to move funds and pointed to possible risks in lattice-based cryptography.

At a glance
reportWhen: Developing; the cited research and publ…
The developmentAI-assisted mathematical results and warnings from prominent cryptocurrency figures have raised questions about whether existing cryptographic assumptions, including those behind post-quantum standards, need closer review.
The Old Map Is Gone — ISR Briefing
AI Dispatch · ISR Briefing · 9 October 2026

The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence

For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.

The map — then and now
Elliptic curves
Then: doomed by quantum

Now: on borrowed time — possibly shorter than the quantum countdown suggests.

Lattices (ML-KEM, ML-DSA)
Then: safe

Now: unproven against AI — and the destination most of the world is migrating to.

Codes (Classic McEliece)
Then: the conservative fallback

Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.

Hashes (SLH-DSA, LMS, XMSS)
Then: safe

Now: safest ground available — not a guarantee.

Nothing has been broken. The map changed because the threat model did.
Two threats, one migration
Quantum threat
AI-mathematics threat
Attacks
RSA & elliptic curves
Anything with exploitable structure — possibly the new lattice standards
Needs
Large error-corrected quantum computer
A better algorithm on ordinary computers
Warning signs
Visible: qubits, error rates, roadmaps
Possibly none — an algorithm can be found and kept secret
First to get there
Whoever builds the machine
Whoever has the best model — incl. states that never announce
What survives
Lattices, codes, hashes
Probably hashes; lattices need bigger keys
The quantum threat comes with a countdown you can watch. The AI threat may not.
The trigger — records broken, by slivers
Integer multiplication
< n log n

~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)

3SUM
n1.9992

Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model

Cryptography
absent

“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”

This week: shaved exponentssliver
A break: 2¹²⁸ → one GPU-weekcollapse
Remarkable mathematics — not a break. The open question: can AI compress the decades the number field sieve took into years? (conceptual, not to scale)
The crypto canary — four voices
Justin Drake · Ethereum Foundation
“Bunker mode”

ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.

Vitalik Buterin · Ethereum
“ML-DSA / FHE / lattices”

The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.

Yehuda Lindell · Coinbase
“The very definition of FUD”

“No evidence whatsoever” that elliptic-curve assumptions are close to failing.

Isabel Foxen Duke · BIP-360
Don’t treat it as a deadline

Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.

Author’s view — what I think is happening
1974 → 1990 → 1994
Differential cryptanalysis

Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).

early 1970s → 1997
Public-key cryptography

Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.

October 2026
An empty folder

No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.

Opinion, not reporting: withholding is plausible, has precedent — and would be the responsible choice. Either way: “nothing published” cannot be read as “nothing found.” There is no evidence of any AI-driven break.
Defence & intelligence — the secrets that must last
Harvest now, decrypt later

Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.

Key exchange can’t be hash-only

Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.

Hedge
US · NSA CNSA 2.0
Germany · BSI TR-02102-1
Key exchange
ML-KEM-1024 only (highest params)
ML-KEM + FrodoKEM (less structured, tighter reduction)
Signatures
ML-DSA-87; LMS/XMSS for firmware
ML-DSA, SLH-DSA, LMS, XMSS
Hybrid with classical
Not required
Required — classical-only key agreement ends from 2031
Key dates
1 Jan 2027 procurement gate · 2030 firmware & networks · 2033 most systems · 2035 all
2031 onward: end dates for classical-only use
The NSA already does much of what Buterin advises — top parameters, hashes for firmware — but its key exchange rests on one lattice family. Europe’s more diverse, hybrid posture is a sovereignty argument worth making loudly. For 15-year ISR platforms and sensors: crypto-agility is a procurement requirement.
Finance — timelines built on the wrong countdown
G7 CEG roadmap publishedJan 2026
Critical systems migrated2030–32
Whole sector migrated2035
Deadlines are ceilings

Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.

Agility over destination

“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.

Watch the canary

Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.

G7 Cyber Expert Group, co-chaired by the US Treasury and the Bank of England — six phases, non-binding, 2030–32 “challenging but prudent”.
What to do now — the same whether the threat is quantum, AI or both
Inventory

Every algorithm, key, certificate, protocol.

Hybrid

PQ + classical, as BSI requires.

Hash-based signing

Firmware, updates, long-term keys.

Conservative params

Highest sets; evaluate FrodoKEM.

Diversify key exchange

More than one mathematical family; HQC coming.

Build for agility

Swap algorithms without rebuilding.

Shrink exposure

Forward secrecy, rotation, hidden keys.

Don’t panic-migrate

Buterin: lost more in botched migrations than in all hacks.

The take

Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.

Sources: OpenAI maths release (6 Oct 2026); Aaronson, “The Mathocalypse” (7 Oct 2026); Drake & Buterin posts on X (7–8 Oct 2026); Lindell, Foxen Duke via Decrypt, cryptonews.net, Yellow; ~6M BTC via Cryptopolitan; NIST FIPS 203/204/205; NSA CNSA 2.0; BSI TR-02102-1 (2025/2026) & 1 Oct 2026 Classic McEliece advice; G7 CEG roadmap (13 Jan 2026); DES/GCHQ history. Author’s-view section is opinion. No AI-driven cryptographic break has been published. Not security or investment advice.
thorstenmeyerai.comin cooperation with vigilsar.com

Pressure on Security Migration Plans

Cryptography underpins more than cryptocurrency. Banks use it to protect communications, authenticate transactions and secure data; intelligence and defence organisations rely on it to protect sensitive information and verify systems. A weakness in widely used signatures or encryption could create risks across these sectors, although the source material reports no demonstrated break.

The concern complicates a migration already under way. A sufficiently capable quantum computer running Shor’s algorithm could break RSA and elliptic-curve cryptography. AI-assisted mathematics presents a different possibility: a better algorithm could run on conventional computers and might be developed without a public hardware countdown. If a new method undermined a hardness assumption, organizations could have less warning than they expect from tracking quantum hardware.

The practical implication is not that institutions should abandon current protections overnight. It is that security planners may need to scrutinize the assumptions behind both existing systems and replacement standards, track developments in mathematical research and prepare for updates if evidence of a real vulnerability emerges.

Amazon

smart home security locks

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Quantum Migration Meets New Questions

Governments and companies have been preparing for the possibility that quantum computers will eventually threaten public-key cryptography. In August 2024, the U.S. National Institute of Standards and Technology standardized three post-quantum tools: ML-KEM for establishing encryption keys, ML-DSA for digital signatures and SLH-DSA, a hash-based signature scheme. These standards are intended to address the quantum threat, not to guarantee security against every possible future mathematical advance.

The source report describes the usual distinction: quantum computers could threaten RSA and elliptic-curve systems, while post-quantum standards rely on other mathematical structures, especially lattices, or on hashes. Bututen’s warning challenges the assumption that lattice-based systems can simply be treated as safe indefinitely. The source does not establish that those standards are vulnerable; it reports a concern about whether their underlying problems could yield to future algorithms.

Blockchains make the issue unusually visible because public keys and transaction histories can be exposed. Drake recommended considering “bunker mode,” including moving funds to addresses whose public keys have not been revealed. The report estimates about 6 million bitcoin are held at addresses with exposed public keys. That figure describes the reported exposure, not the amount proven vulnerable to an attack.

“Calmly begin planning for ‘bunker mode’.”

— Justin Drake, Ethereum Foundation researcher

No Cryptographic Break Has Been Shown

The source material does not report a successful attack on RSA, elliptic-curve cryptography, ML-KEM, ML-DSA or another deployed standard. It also does not provide public details of the alleged internal tests by AI companies, identify which protocols were tested or describe any results. The mathematical manuscripts themselves require checking, and the reported withdrawal over a sign error underlines that AI-generated proofs can contain mistakes.

It remains unknown whether AI systems can produce an algorithm that materially weakens a cryptographic standard, how long such work might take, or whether any discovery would be disclosed. The claimed risk to lattice-based standards is a warning about possible future advances, not a confirmed vulnerability. Drake’s timeline is his assessment, not a verified forecast.

Verification and Standards Review

Mathematicians and computer scientists will need to verify the reported results and determine whether any faster methods have practical consequences for cryptographic systems. Public evidence about the AI companies’ protocol testing, if released, could help clarify what was tested and whether any weaknesses were found.

For financial institutions and government security teams, the near-term task remains distinguishing a theoretical concern from an actionable vulnerability while continuing post-quantum migration planning. The source identifies no new official deadline or standards change. Further technical review and independently reproducible results will be needed before the warnings can support a revised assessment of the security of deployed systems.

Key Questions

Has AI broken a major encryption system?

No. The source reports no demonstrated break of RSA, elliptic-curve cryptography or post-quantum standards. It describes mathematical results and concerns about what future algorithms might achieve.

What did OpenAI publish?

OpenAI published 722 mathematical manuscripts in 372 families, generated by an unreleased internal model. The reported claims are still subject to checking, and the source says one claimed proof was withdrawn after a sign error was found.

Why are lattice-based standards part of the discussion?

Post-quantum standards such as ML-KEM and ML-DSA use mathematical problems different from those threatened by known quantum algorithms. Buterin argued that researchers should not assume lattice-based security is immune to future algorithmic advances. The source does not show these standards have been compromised.

Should cryptocurrency users move their funds now?

Drake recommended considering protective measures, including addresses with unexposed public keys. Buterin said he did not recommend a scramble to move funds immediately. The source offers no confirmed attack or universal instruction for users.

What would clarify the level of risk?

Independent verification of the mathematical work, reproducible results and specific public information about cryptographic tests would help establish whether the concerns translate into practical vulnerabilities.

Source: ThorstenMeyerAI.com

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

ShinyHunters · The New APT Model.

Research uncovers how ShinyHunters has evolved into a scalable, AI-enabled extortion collective, redefining enterprise threat landscapes.

The Swarm Is The Weapon: Why Agentic Attacks Break The Defensive Playbook

Emerging autonomous AI collectives challenge existing cybersecurity defenses by operating in parallel, sharing knowledge instantly, and chaining vulnerabilities.

Every Benchmark Launched 2023-2024 Has Fallen — The METR / SWE-Bench / CORE-Bench / MLE-Bench / PostTrainBench Sequence

Every major AI research benchmark launched in 2023-2024 has either saturated or is nearing saturation, signaling accelerated AI capability growth.

AI In Programming: Which Model Should You Trust?

An analysis of AI models for software development, highlighting which models are suitable for different tasks and how to ensure reliable results.