
Máy tính lượng tử từ lâu được xem là một trong những mối đe dọa lớn đối với hệ thống mật mã bảo vệ tài sản số. Tuy nhiên, đồng sáng lập Ethereum Vitalik Buterin và nhà nghiên cứu Justin Drake cho rằng trí tuệ nhân tạo có thể khiến rủi ro xuất hiện trước khi máy tính lượng tử đạt đến năng lực cần thiết.
Theo Buterin, nếu AI giúp tạo ra lượng tiến bộ toán học tương đương 50 năm chỉ trong hai năm, những giả định về độ an toàn của các phương pháp mật mã hiện nay có thể phải được đánh giá lại. Nguy cơ không chỉ giới hạn ở mật mã đường cong elliptic đang được nhiều ví tiền điện tử sử dụng, mà còn có thể ảnh hưởng đến một số phương pháp được thiết kế để chống lại máy tính lượng tử, đặc biệt là mật mã dựa trên mạng lưới.
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be? This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ... * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money" https://t.co/oVjwZog2lL
— vitalik.eth (@VitalikButerin) October 7, 2026
Đây là kịch bản giả định về tốc độ phát triển công nghệ, không phải khẳng định rằng AI hiện đã phá được cơ chế bảo mật của Bitcoin hay Ethereum.
Cùng chia sẻ lo ngại, Justin Drake cho rằng ngành blockchain nên bắt đầu chuẩn bị phương án phòng thủ trước khả năng thuật toán chữ ký số ECDSA bị suy yếu. Trong kịch bản xấu nhất mà ông đề cập, nguy cơ có thể xuất hiện trong vài tháng thay vì nhiều năm.
Điểm đáng chú ý là một cuộc tấn công như vậy có thể không cần đến máy tính lượng tử. Nếu xuất hiện đột phá thuật toán đủ mạnh, kẻ tấn công có thể sử dụng một cụm GPU lớn để khôi phục khóa riêng từ khóa công khai. Khi đó, lớp bảo vệ cốt lõi của các ví sử dụng cơ chế chữ ký bị ảnh hưởng sẽ đứng trước nguy cơ mất an toàn.
Để giảm mức độ phơi lộ, Drake đề xuất cân nhắc lưu trữ tài sản tại các địa chỉ mới, chưa từng ký giao dịch và vẫn giữ kín khóa bí mật. Với những loại ví phù hợp, việc ký và gửi giao dịch có thể làm lộ thông tin cần thiết để khôi phục khóa công khai, tạo thêm dữ liệu cho một cuộc tấn công nếu nền tảng mật mã bị phá vỡ trong tương lai.
Tuy nhiên, cả hai không khuyến khích người dùng vội vàng di chuyển tài sản. Việc chuyển tiền thiếu kiểm soát có thể dẫn đến sai địa chỉ, thất lạc khóa hoặc những sai sót khác. Các đề xuất được đưa ra nhằm chuẩn bị cho rủi ro tiềm tàng, thay vì phản ứng trước một cuộc tấn công đã được xác nhận.
Về dài hạn, Buterin nhấn mạnh hướng phát triển các cơ chế bảo mật dựa trên hàm, giảm sự phụ thuộc vào những bài toán toán học có thể bị tác động bởi đột phá thuật toán. Với Ethereum, cảnh báo này đặt ra yêu cầu đẩy nhanh nghiên cứu và xây dựng lộ trình chuyển đổi, để mạng lưới có đủ thời gian thích ứng nếu năng lực của AI tiến triển nhanh hơn dự kiến.