🔍 Read the full analysis: Why The Old Cryptography Map No Longer Fits Finance And Defence on ThorstenMeyerAI.com
Prime made for students and young adults
- Fast, free delivery for dorm and study essentials
- Prime Video and Amazon Music included
- Member-only deals
TL;DR
OpenAI published 722 AI-generated mathematical manuscripts on October 6, including results that challenge some long-held assumptions about computational speed. Cryptographers and cryptocurrency figures have raised questions about whether AI could find new algorithms that weaken cryptography, including post-quantum systems, but no cryptographic protocol has been shown to be broken. The scale and timing of any such risk remain unknown.
OpenAI published 722 mathematical manuscripts on October 6, prompting renewed concern that artificial intelligence could find faster algorithms and weaken assumptions used in cryptography. Researchers and cryptocurrency leaders have discussed the possibility, but no cryptographic system has been shown to be broken, and the manuscripts’ mathematical claims are still being checked.
The manuscripts, grouped into 372 families, were produced by an unreleased OpenAI model working on roughly 4,000 problems. The source report says each result used an average of about three hours of ChatGPT Pro compute. The reported claims range from results related to the Unique Games Conjecture and Hilbert’s tenth problem over the rationals to a proposed zero-free region for the Riemann zeta function. These are reported claims, not a body of independently established findings.
Some results about computational speed drew particular attention. Computer scientist Scott Aaronson catalogued claimed improvements involving integer multiplication and the Fourier transform, as well as a result for 3SUM attributed to a paper by Virginia Vassilevska Williams and Josh Alman. The source report says the key idea in that work came from an Anthropic model. Such algorithmic advances matter to cryptography because security often depends on certain computations remaining difficult; however, a faster result for one problem does not by itself break a cryptographic protocol.
The report says cryptography was absent from OpenAI’s 722 manuscripts, while Aaronson cited sources who said AI companies were discreetly testing whether internal models could break important protocols. That account is not a public demonstration or independently confirmed break. Separately, OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a reported sign error, illustrating why AI-generated mathematical work requires verification.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Why Algorithmic Breakthroughs Matter
Finance, intelligence agencies and defence organisations rely on cryptography to protect transactions, communications, stored information and authenticated software. Their security plans often distinguish between systems threatened by future quantum computers and replacement systems believed to resist those attacks. The new concern raised by the source report is that an improved algorithm could affect those assumptions without requiring a quantum machine.
This is a risk question, not evidence of compromise. If researchers found a practical method to solve a problem underlying a widely used system, institutions could face pressure to replace keys, protocols and equipment. For banks and governments, that process can take years because cryptography is embedded in networks, devices and operational procedures. But the source material does not establish that AI has found such a method, how much faster any proposed method would be in practice, or whether a result would generalise to deployed systems.
The reported contrast with quantum computing is also relevant to planning. Quantum progress can be tracked through hardware and engineering milestones, while a mathematical algorithm could remain private before disclosure. That possibility makes the threat harder to monitor, but it does not show that a hidden algorithm exists or that current systems are vulnerable.
As an affiliate, we earn on qualifying purchases.
From Quantum Migration to AI Questions
For years, security planning has focused on the possibility that a sufficiently capable quantum computer could use Shor’s algorithm against RSA and elliptic-curve cryptography. In response, the US National Institute of Standards and Technology standardised major post-quantum tools in August 2024: ML-KEM for key establishment, ML-DSA for digital signatures and SLH-DSA, a hash-based signature standard.
The source report argues that AI-driven algorithm discovery could complicate a migration based on the belief that lattice-based systems are safe from the known quantum threat. That is a scenario, not a finding that the standards are broken. The standards remain the published replacements, and the material supplied does not report a successful attack on them.
Cryptocurrency has become an early focus of public discussion because some blockchain addresses expose public keys after transactions are signed. On October 7, Ethereum Foundation researcher Justin Drake urged the industry to plan calmly for a possible “bunker mode” and suggested moving funds to addresses whose public keys have not been exposed. The source report estimates that about six million bitcoin are held in addresses with exposed public keys; it does not provide a comparison baseline or establish that those funds can currently be taken.
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Has Been Shown
The central uncertainty is whether AI systems can produce a mathematically valid, practically useful algorithm that undermines cryptographic systems. The source material reports no demonstrated break of RSA, elliptic-curve cryptography, ML-KEM, ML-DSA or another named protocol. It also does not identify a specific attack, an independently verified result, or evidence that any government or company has privately obtained one.
Many of the 722 manuscripts still require expert checking, and at least one claimed result was withdrawn after an error was reported. Even a correct mathematical improvement may not be fast enough to threaten real-world keys or implementations. The source material also leaves unclear which systems AI companies have tested, what those tests found, and whether any results have been withheld.
quantum-resistant encryption devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Verification and Migration Plans
The immediate next step is independent review of the mathematical manuscripts and any reported algorithmic improvements. Cryptographers and standards bodies would need evidence about correctness, practical runtime and the systems affected before changing security guidance. The supplied material does not name a scheduled review, formal advisory or new deadline for migration.
Organisations can continue tracking post-quantum migration while treating AI-driven cryptanalysis as an emerging possibility rather than a confirmed emergency. For blockchain users, Drake’s and Buterin’s comments show differing levels of urgency, but neither establishes that funds are currently at risk from an AI-discovered method. Further public evidence—especially a reproducible cryptographic result—would change the assessment; until then, the scale and timing of the threat remain open questions.
As an affiliate, we earn on qualifying purchases.
Key Questions
Did AI break a cryptographic system?
No break is reported. The source material describes AI-generated mathematics and concerns about possible algorithm discovery, not a demonstrated attack on a deployed cryptographic protocol.
What did OpenAI publish?
OpenAI published 722 mathematical manuscripts in 372 families on October 6, produced by an unreleased internal model. Their claims are still subject to mathematical checking, and at least one claimed proof was withdrawn after an error was reported.
How is this concern different from the quantum threat?
The established quantum concern is that a sufficiently capable quantum computer could use Shor’s algorithm against RSA and elliptic-curve cryptography. The AI-related concern is that a model might help discover a better algorithm that runs on ordinary computers. The supplied material does not show that this has happened.
Are post-quantum standards known to be unsafe?
No. NIST standardised ML-KEM, ML-DSA and SLH-DSA in August 2024. The source raises questions about mathematical assumptions behind some approaches but reports no successful attack on these standards.
Should cryptocurrency holders move funds now?
The source includes Drake’s call to plan for possible protective measures and Buterin’s advice not to scramble to move funds. It reports no current AI-driven theft or confirmed cryptographic break, so the comments should be understood as differing risk assessments rather than proof of an immediate threat.
Source: ThorstenMeyerAI.com
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
