AIThis post was created with the assistance of artificial intelligence (AI).

For a decade, the security world has worked from a simple map.

Buying for a business?Offer from Amazon

Get business pricing on tech for your team

  • Business-only prices and quantity discounts
  • Tax-exempt purchasing
  • Multiple users, one account, clear invoices
As an affiliate, we earn on qualifying purchases.

Elliptic curves: doomed, eventually, by quantum computers. Lattices: safe. Hashes: safe.

Governments, banks and militaries built their migration plans on it. The plan was to leave the doomed territory before the quantum machines arrived, and to move into the safe territory, chiefly the new lattice-based standards, in time.

This week, that map stopped being reliable.

Not because anything has been broken. Nothing has, and anyone who tells you otherwise is getting ahead of the evidence. It stopped being reliable because a second threat has appeared alongside the quantum one, and it doesn’t respect the same borders. AI systems are now producing new mathematics at a rate no human community can match, and cryptography rests on mathematical assumptions that are believed, not proven.

This piece covers what happened, what two of the most influential figures in cryptocurrency are now warning, why the strongest counter-arguments still matter, and what it means for the three sectors that depend most on cryptography: finance, intelligence and defence.

The Old Map Is Gone — ISR Briefing
AI Dispatch · ISR Briefing · 9 October 2026

The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence

For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.

The map — then and now
Elliptic curves
Then: doomed by quantum

Now: on borrowed time — possibly shorter than the quantum countdown suggests.

Lattices (ML-KEM, ML-DSA)
Then: safe

Now: unproven against AI — and the destination most of the world is migrating to.

Codes (Classic McEliece)
Then: the conservative fallback

Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.

Hashes (SLH-DSA, LMS, XMSS)
Then: safe

Now: safest ground available — not a guarantee.

Nothing has been broken. The map changed because the threat model did.
Two threats, one migration
Quantum threat
AI-mathematics threat
Attacks
RSA & elliptic curves
Anything with exploitable structure — possibly the new lattice standards
Needs
Large error-corrected quantum computer
A better algorithm on ordinary computers
Warning signs
Visible: qubits, error rates, roadmaps
Possibly none — an algorithm can be found and kept secret
First to get there
Whoever builds the machine
Whoever has the best model — incl. states that never announce
What survives
Lattices, codes, hashes
Probably hashes; lattices need bigger keys
The quantum threat comes with a countdown you can watch. The AI threat may not.
The trigger — records broken, by slivers
Integer multiplication
< n log n

~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)

3SUM
n1.9992

Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model

Cryptography
absent

“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”

This week: shaved exponentssliver
A break: 2¹²⁸ → one GPU-weekcollapse
Remarkable mathematics — not a break. The open question: can AI compress the decades the number field sieve took into years? (conceptual, not to scale)
The crypto canary — four voices
Justin Drake · Ethereum Foundation
“Bunker mode”

ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.

Vitalik Buterin · Ethereum
“ML-DSA / FHE / lattices”

The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.

Yehuda Lindell · Coinbase
“The very definition of FUD”

“No evidence whatsoever” that elliptic-curve assumptions are close to failing.

Isabel Foxen Duke · BIP-360
Don’t treat it as a deadline

Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.

Author’s view — what I think is happening
1974 → 1990 → 1994
Differential cryptanalysis

Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).

early 1970s → 1997
Public-key cryptography

Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.

October 2026
An empty folder

No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.

Opinion, not reporting: withholding is plausible, has precedent — and would be the responsible choice. Either way: “nothing published” cannot be read as “nothing found.” There is no evidence of any AI-driven break.
Defence & intelligence — the secrets that must last
Harvest now, decrypt later

Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.

Key exchange can’t be hash-only

Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.

Hedge
US · NSA CNSA 2.0
Germany · BSI TR-02102-1
Key exchange
ML-KEM-1024 only (highest params)
ML-KEM + FrodoKEM (less structured, tighter reduction)
Signatures
ML-DSA-87; LMS/XMSS for firmware
ML-DSA, SLH-DSA, LMS, XMSS
Hybrid with classical
Not required
Required — classical-only key agreement ends from 2031
Key dates
1 Jan 2027 procurement gate · 2030 firmware & networks · 2033 most systems · 2035 all
2031 onward: end dates for classical-only use
The NSA already does much of what Buterin advises — top parameters, hashes for firmware — but its key exchange rests on one lattice family. Europe’s more diverse, hybrid posture is a sovereignty argument worth making loudly. For 15-year ISR platforms and sensors: crypto-agility is a procurement requirement.
Finance — timelines built on the wrong countdown
G7 CEG roadmap publishedJan 2026
Critical systems migrated2030–32
Whole sector migrated2035
Deadlines are ceilings

Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.

Agility over destination

“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.

Watch the canary

Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.

G7 Cyber Expert Group, co-chaired by the US Treasury and the Bank of England — six phases, non-binding, 2030–32 “challenging but prudent”.
What to do now — the same whether the threat is quantum, AI or both
Inventory

Every algorithm, key, certificate, protocol.

Hybrid

PQ + classical, as BSI requires.

Hash-based signing

Firmware, updates, long-term keys.

Conservative params

Highest sets; evaluate FrodoKEM.

Diversify key exchange

More than one mathematical family; HQC coming.

Build for agility

Swap algorithms without rebuilding.

Shrink exposure

Forward secrecy, rotation, hidden keys.

Don’t panic-migrate

Buterin: lost more in botched migrations than in all hacks.

The take

Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.

Sources: OpenAI maths release (6 Oct 2026); Aaronson, “The Mathocalypse” (7 Oct 2026); Drake & Buterin posts on X (7–8 Oct 2026); Lindell, Foxen Duke via Decrypt, cryptonews.net, Yellow; ~6M BTC via Cryptopolitan; NIST FIPS 203/204/205; NSA CNSA 2.0; BSI TR-02102-1 (2025/2026) & 1 Oct 2026 Classic McEliece advice; G7 CEG roadmap (13 Jan 2026); DES/GCHQ history. Author’s-view section is opinion. No AI-driven cryptographic break has been published. Not security or investment advice.
thorstenmeyerai.comin cooperation with vigilsar.com

The trigger: 722 proofs and a conspicuous gap

On 6 October, OpenAI published 722 mathematical manuscripts in 372 families, produced by an unreleased internal model from roughly 4,000 problems, using on average about three hours of ChatGPT Pro compute per result. The claims include the Unique Games Conjecture, Hilbert’s tenth problem over the rationals and a zero-free region for the Riemann zeta function. This publication has covered the release, the reaction from mathematicians and the bottleneck of checking it all.

For cryptographers, the most important results weren’t the famous conjectures. They were the ones that broke long-standing beliefs about how fast things can be computed. As Scott Aaronson catalogued them:

  • Integer multiplication below n log n, a barrier many believed was fundamental.
  • The Fourier transform below n log n.
  • 3SUM in about n^1.9992 time, overturning a half-century-old conjecture that n² was essentially optimal. This came the day before OpenAI’s release, in a paper by Virginia Vassilevska Williams and Josh Alman. The crucial idea came from an Anthropic model, not an OpenAI one.

Then Aaronson noticed something else. Cryptography was conspicuous by its absence from the 722 manuscripts. His sources told him that AI companies have begun, “gingerly and discreetly”, testing whether their internal models can break important cryptographic protocols.

A day of checking has already produced one correction: OpenAI withdrew its claimed proof of the Hodge conjecture for products of K3 surfaces, reportedly over a sign error. These are claims, not settled results. But the direction is unmistakable: assumptions about computational hardness that stood for decades are being tested by machines.

Amazon

post-quantum cryptography hardware

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Two threats, one migration

The quantum threat is well understood. A large enough quantum computer running Shor’s algorithm would break RSA and elliptic-curve cryptography, the public-key systems that protect almost everything today. That’s why the world is migrating to post-quantum cryptography. NIST standardised the main replacements in August 2024: ML-KEM for establishing encryption keys and ML-DSA for digital signatures, both lattice-based, plus SLH-DSA, a signature scheme built only from hash functions.

The AI threat is different in kind, and the differences matter more than the similarities.

Quantum threatAI-mathematics threat
What it attacksRSA and elliptic curvesAnything whose security rests on mathematical structure — potentially including the new lattice standards
What it needsA large, error-corrected quantum computerA better algorithm, running on ordinary computers
Warning signsVisible: qubit counts, error rates, published roadmapsPossibly none. An algorithm can be discovered and kept secret
Who gets there firstWhoever builds the machineWhoever has the best model, including states that will never announce it
What survivesLattices, codes, hashesProbably hashes. Lattices weakened, needing larger keys

The difference that matters most is the third row. The quantum threat comes with a visible countdown. The AI threat may not. A government can track quantum hardware progress and set deadlines against it. Nobody can track an algorithm until someone publishes it.

Amazon

lattice-based cryptography tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The crypto canary

The first public alarm came from where cryptographic exposure is most visible: blockchains, where public keys sit in the open and the money behind them can be counted.

On 7 October, Justin Drake, a researcher at the Ethereum Foundation, called on the industry to “calmly begin planning for ‘bunker mode'”. His advice: move funds to addresses whose public keys have never been exposed. An address that has never signed a transaction reveals only a hash of its key, so even a broken signature scheme can’t be used against it. “IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years,” he wrote, defining a break as recovering a private key in about a week on a large GPU cluster. Reporting puts roughly 6 million bitcoin in addresses whose public keys are already exposed.

A day later, Vitalik Buterin, Ethereum’s co-founder, made the more consequential point. He didn’t endorse the urgency: “I don’t recommend anyone scramble to move their funds to new wallets today.” But he moved the threat somewhere the industry had treated as safe:

“The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices.”

His reasoning was historical. Factoring large numbers naively takes time that grows exponentially with key size. Over decades, mathematicians developed the number field sieve, which brought that down dramatically, which is why RSA keys must be hundreds of bytes long. Buterin asked: what if similar “skeletons in the closet” exist for elliptic curves and lattices, which humans aren’t clever enough to find but AI soon will be? “There is a good chance,” he wrote, “that the concrete security of lattices will take serious hits from the next two years of AI math.”

The Structure Gradient — Figure
Figure · The structure gradient · 9 October 2026

Where the AI attack surface lives: from most mathematical structure to least

Vitalik Buterin’s argument in one picture: structure is what clever mathematics exploits. Moving right, there’s less to exploit — and less you can build. Hashes give you signatures, but not key exchange.

More structure ← → less structure
MORE TO EXPLOIT · MORE CAPABILITYLESS TO EXPLOIT · FEWER CAPABILITIES
RSA · elliptic curves
Structured lattices
Plain lattices
Codes
Hashes
Examples
RSA, ECDSA, ECDH
ML-KEM, ML-DSA, Falcon
FrodoKEM
Classic McEliece, HQC
SLH-DSA, LMS, XMSS
Can do
Signatures + key exchange
Signatures + key exchange
Key exchange
Key exchange
Signatures only
Quantum
Broken by Shor
Believed resistant
Believed resistant
Believed resistant
Resistant (larger outputs)
AI-maths exposure
Elevated — “associativity, Schoof, pairings” (Buterin)
“Core new area of risk” (Buterin)
Lower — tighter reduction (BSI)
Old, but estimates move
Lowest — designed for no structure
Standards status
Being phased out: CNSA 2030–35; BSI classical-only ends from 2031
NIST FIPS 203/204; CNSA 2.0 (1024 / 87); BSI
BSI; ISO 18033-2 (2026); not in CNSA
McEliece: BSI advises against new use (1 Oct 2026). HQC: NIST backup; BSI to recommend
FIPS 205; SP 800-208; CNSA for firmware
The trap: public-key encryption needs a trapdoor, and every known trapdoor has structure. For key exchange the choice is never “structure or none” — it’s which structure, how much margin, how many combined.
The take

Most of the world’s migration lands in the second column. If Buterin is right, that’s where AI makes its first serious dents — and the defences are the ones already on the page: larger parameters, hybrid with classical, a second family alongside, and hashes wherever signatures are enough.Spread your bets across columns. Don’t bet the archive on one.

Sources: NIST FIPS 203/204/205, SP 800-208; NSA CNSA 2.0; BSI TR-02102-1 and 1 Oct 2026 Classic McEliece advice; ISO/IEC 18033-2 Amd 2:2026; Vitalik Buterin on X (8 Oct 2026). Exposure ratings are qualitative, per the cited sources and the author’s analysis.
thorstenmeyerai.comin cooperation with vigilsar.com

That’s the heart of it. The world is migrating away from elliptic curves to escape the quantum threat, and towards lattices. Buterin’s argument is that the destination may itself be exposed to the AI threat.

His prescription: use hash-based cryptography wherever possible, be “much more paranoid” about lattice parameter sizes, and, for anything meant to be secure for the long term, consider multiplying key sizes by ten.

Amazon

quantum-resistant digital signatures

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The pushback, which matters

The case against panic is strong, and it deserves full weight.

Yehuda Lindell, head of cryptography at Coinbase, called Drake’s warning “the very definition of FUD” and said there is “no evidence whatsoever” that the assumptions behind elliptic-curve cryptography are close to failing. Isabel Foxen Duke, co-author of a Bitcoin quantum-resistance proposal, BIP-360, agreed that classical, AI-driven breaks could reach schemes considered quantum-safe, but cautioned against treating Buterin’s two-year scenario as a deadline. Buterin himself had argued only a month earlier that AI wouldn’t doom crypto security.

And there’s a technical point the alarm skips over. The records that fell this week were broken by tiny margins. Integer multiplication went from n log n to roughly n log^0.9999999999999 n. 3SUM went from n² to n^1.9992. These are remarkable as mathematics, but they’re slivers. Breaking elliptic-curve cryptography would require turning roughly 2¹²⁸ operations into something a GPU cluster can finish in a week. That’s not a sliver; it’s a collapse of the exponent. Nothing published this week shows a collapse of that kind.

The honest framing is narrower than either camp’s. The evidence shows that AI can now overturn hardness beliefs that experts held for decades. It does not show that AI can produce the specific, dramatic kind of improvement that breaks a deployed cryptosystem. The number field sieve is the precedent Buterin cites, and it shows such improvements are possible. It took decades. The open question is whether AI compresses those decades into years.

Amazon

AI cryptography research books

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

A reminder that even conservative choices erode

One development this month shows how security estimates move even without AI.

On 1 October, Germany’s federal cybersecurity agency, the BSI, advised organisations not to use Classic McEliece in new developments. Classic McEliece is a code-based scheme derived from a 1978 cryptosystem, and it had long been seen as the most conservative post-quantum choice precisely because it’s so old. Researchers estimated its key recovery cost below its claimed security levels. BSI stressed that no practical attack is possible against its recommended parameters, and said ML-KEM, FrodoKEM and HQC are unaffected.

There’s no suggestion this result came from AI. But it illustrates the point that matters for planning: security levels aren’t fixed facts. They’re estimates that move when someone finds a better attack. And the rate at which people find better attacks is the thing AI is changing.

(A correction to an earlier position: in preparing this series I had described Classic McEliece as the conservative fallback. As of this month, BSI’s advice is to prefer ML-KEM and FrodoKEM instead.)

What I think is happening

This section is my view, not reporting, and it should be read that way.

I think it is plausible that frontier AI labs have produced, or are close to producing, results relevant to cryptography, and have deliberately kept them out of public releases, sharing them with a limited audience instead. That would explain the gap Aaronson noticed in the 722 manuscripts.

There is no evidence that any such result exists. The absence of cryptography papers is consistent with three explanations: results were found and withheld; the labs chose not to pose cryptographic problems at all; or they posed them and found nothing. From the outside, those three are indistinguishable.

But withholding would have strong precedent. IBM and the NSA knew about differential cryptanalysis by about 1974, while designing the DES cipher. It became public only when Eli Biham and Adi Shamir rediscovered it around 1990, and IBM’s Don Coppersmith confirmed in 1994 that the design team had known all along. Britain’s GCHQ invented public-key cryptography in the early 1970s, the equivalents of what the world later called RSA and Diffie–Hellman, and kept it secret until 1997. Keeping cryptographic mathematics from the public has been standard practice for half a century. It isn’t a conspiracy theory; it’s history.

From GCHQ to GitHub — Figure
Figure · Fifty years of secret cryptomath · 9 October 2026

From GCHQ to GitHub: the history behind “nothing published”

Cryptographic mathematics has been kept from the public before — for decades at a time. That history is why an empty folder in a public repository isn’t reassuring.

Timeline
secret, later revealedstandards & policythis monthdeadlines ahead
The precedents
Early 1970s
GCHQ invents public-key cryptography
Equivalents of RSA and Diffie–Hellman, years before the public versions — classified.
~1974
IBM and the NSA know differential cryptanalysis
Used to harden DES against an attack the public didn’t yet know existed.
~1990
Biham and Shamir rediscover it in public
Roughly sixteen years after the designers knew.
1994
Coppersmith confirms IBM knew all along
The secret was confirmed only after outsiders had found it.
1997
GCHQ’s public-key work declassified
Over two decades of silence.
2015
NSA’s CNSA 1.0 announcement
Its timing prompted speculation about whether the NSA had found weaknesses.
The migration
August 2024
NIST publishes FIPS 203, 204, 205
ML-KEM and ML-DSA (lattices) and SLH-DSA (hashes) become the post-quantum standards.
January 2026
G7 finance roadmap
Critical systems 2030–32, sector 2035. Dated against quantum hardware forecasts.
February 2026
BSI sets end dates for classical-only key agreement
Hybrid required; FrodoKEM recommended alongside ML-KEM.
May 2026
AI disproves the Erdős unit-distance conjecture
Verified by human mathematicians — the first warning shot, in hindsight.
October 2026
1 October
BSI advises against new Classic McEliece deployments
The oldest ‘conservative’ post-quantum choice: estimates moved.
5 October
3SUM conjecture overturned
Williams and Alman; key idea from an Anthropic model.
6 October
OpenAI releases 722 manuscripts
Records fall in multiplication and the Fourier transform. Cryptography: absent.
7 October
Drake calls for “bunker mode”
ECDSA could break before Q-day, “in the worst case in months not years”.
8 October
Buterin names lattices; Lindell calls it FUD
“ML-DSA / FHE / lattices” — the migration’s destination — becomes the new risk.
Ahead
1 January 2027
CNSA 2.0 procurement gate
New US national security acquisitions must support ML-KEM-1024 and ML-DSA-87.
2030–2033
Firmware, networks, then most systems exclusive to CNSA 2.0
Hash-based LMS/XMSS for firmware signing.
2035
G7 and US targets for full migration
Assuming the threat waits that long.
The take

The precedents point one way: when cryptographic mathematics is discovered by those with reasons to keep it, the public learns about it years or decades later — usually when someone else rediscovers it. This timeline proves nothing about any AI lab today. It explains why absence of evidence is weak evidence here.In cryptography, silence has a history.

Sources: historical accounts of GCHQ’s public-key work (declassified 1997) and differential cryptanalysis (Biham & Shamir; Coppersmith, 1994); CNSA 1.0/2.0 public record; NIST FIPS 203/204/205; G7 CEG (Jan 2026); BSI TR-02102-1 (Feb 2026) and 1 Oct 2026 advice; Aaronson (7 Oct 2026); Drake, Buterin, Lindell posts and coverage. No evidence of any withheld AI cryptographic result has been published.
thorstenmeyerai.comin cooperation with vigilsar.com

It would also be the responsible choice. A lab that found a real weakness in a deployed standard should not post it on GitHub. It should disclose it quietly to the people who can fix it. OpenAI’s own system card for GPT-6 Astra already rates its cyber capability as “Critical” and keeps exploit work behind a gated programme.

Which leads to the conclusion that matters, and it holds whichever explanation is true. “Nothing published” cannot be read as “nothing found.” In the quantum era, the warning sign is visible hardware. In the AI era, the first sign of a break might be an empty folder in a public repository. Defenders can’t wait for an announcement that, if things are working as they should, may never come.

Defence and intelligence: the secrets that must last

For intelligence services and defence ministries, the threat has a specific shape: “harvest now, decrypt later.” An adversary records encrypted traffic today and stores it, intending to decrypt it once a break arrives. For a classified communication that must stay secret for 25 years or more, a break in 2035 is a break today.

How Exposed Is Your Data? — Figure
Figure · Harvest now, decrypt later · 9 October 2026

How exposed is your data? Mosca’s inequality, with an AI-shaped z

The rule cryptographers use: if data must stay secret for x years and migrating takes y years, you’re already exposed whenever x + y is greater than z, the years until a break. Quantum gives you a z you can estimate. AI may not.

Set your own numbers — presets are illustrative, not forecasts
Classified cables, health and financial records, trade secrets.
Inventory, vendors, testing, rollout. Rarely fast.
Quantum: estimated from hardware progress. AI: unknown, possibly sooner, possibly silent.
YEARS FROM TODAY
mig.
must stay secret
01020304050
The take

The inequality is old; what changed is z. Every finance and defence roadmap estimated z from quantum hardware, which comes with visible warning. An AI-discovered algorithm could shrink z without warning — and for long-lived secrets, anything harvested before migration is already gone.If x + y is larger than z, you have two levers: migrate faster (y), or keep sensitive data for less time (x).

Mosca’s inequality (Michele Mosca). Presets are illustrative assumptions for discussion, not forecasts of any break date. No AI-driven cryptographic break has been published. Not security advice.
thorstenmeyerai.comin cooperation with vigilsar.com

That changes how the AI threat matters to defence in three ways.

Key exchange is the exposed layer, and it can’t be hash-only. Buterin is right that signatures can be built from hash functions alone. But public-key encryption and key exchange, the mechanisms that protect classified communications and satellite links, can’t. They need a mathematical “trapdoor”, and every known trapdoor has structure: lattices, codes, or the group theory behind elliptic curves. Buterin acknowledges this directly. So the defence sector can’t escape structured mathematics by switching to hashes. It can only choose which structure to trust, how much margin to add, and how many different structures to combine.

The US migration path already hedges towards Buterin’s advice, but still concentrates on lattices. The NSA’s CNSA 2.0 suite for national security systems requires only the highest parameter sets, ML-KEM-1024 and ML-DSA-87, and specifies hash-based signatures (LMS or XMSS), alongside ML-DSA-87, for software and firmware signing. Being “paranoid about parameter sizes” and preferring hashes where possible is, in effect, already much of US policy. The timeline has teeth: from 1 January 2027, new national security system acquisitions must support CNSA 2.0; networking equipment and firmware signing must use it exclusively by 2030; most other systems by 2033; everything by 2035. But the key-exchange layer rests on one lattice family. If Buterin’s scenario materialises, that’s where the exposure concentrates.

Europe has hedged differently, and the difference is worth noticing. BSI’s guideline requires post-quantum schemes to be deployed in hybrid mode, combined with a classical algorithm, rather than on their own. Its 2026 edition sets fixed end dates for classical key agreement used alone, starting in 2031. It also recommends FrodoKEM alongside ML-KEM. FrodoKEM is built on plain lattice problems without the extra algebraic structure ML-KEM uses for efficiency, and its security reduction is tighter. Neither FrodoKEM nor hybrid deployment as a requirement appears in CNSA 2.0. If the next few years bring AI-driven attacks on structured lattices, the more conservative European posture will look prescient. That’s a sovereignty argument Europe should be making loudly.

For long-lived defence systems — satellites, sensors, ISR platforms built to operate for fifteen years or more — the lesson is crypto-agility. A system whose algorithms can be replaced in the field survives a break. A system with its cryptography fixed in hardware does not. For deployed sensors and the data links behind them, hash-based firmware signing is the floor, and the ability to swap the key-exchange mechanism after deployment should be a procurement requirement, not a feature.

There’s also a strategic asymmetry. A state that discovers a break will not announce it. It will exploit the archives it has already collected. The countries with the largest stores of intercepted traffic and the most capable models gain the most, and they have the strongest reasons to stay silent. That’s why the absence of public evidence is not reassuring for intelligence services.

Finance: timelines built on the wrong countdown

The financial sector’s exposure is broad: interbank messaging, payment card systems, online banking, trading infrastructure, and the public-key infrastructure that authenticates all of it. Much financial data, including transaction records, personal data and contracts, also needs to stay confidential for years.

The sector has a plan. In January 2026, the G7 Cyber Expert Group, co-chaired by the US Treasury and the Bank of England, published a coordinated roadmap for the transition to post-quantum cryptography in finance. It sets out six phases, from awareness and inventory through migration, testing and monitoring. It describes 2030–2032 as a “challenging but prudent” target for critical systems and 2035 for the sector as a whole. It’s explicitly non-binding.

The problem is not the plan. It’s the assumption underneath it. Every one of these dates was set against a forecast of quantum hardware, a threat expected to give years of visible warning. The AI-mathematics threat offers no such warning and could arrive on ordinary computers. And the main target of the migration, lattice-based cryptography, is the area Buterin identifies as newly at risk.

Three consequences for banks, insurers and market infrastructures:

Treat the deadlines as ceilings, not schedules. A roadmap that ends in 2035 assumes the threat won’t arrive before then. Against a threat with no visible countdown, earlier is the only safe interpretation, especially for data that must stay confidential.

Design for replacement, not for a single destination. If the migration ends in “we now use ML-KEM everywhere”, a future attack on lattices means starting over. If it ends in “we can change algorithms without rebuilding systems”, it doesn’t. Crypto-agility is the real deliverable; any particular algorithm is temporary.

Watch the crypto-asset sector as an early warning. Blockchains are where a classical break would show up first, because exposed public keys and their balances are public. Banks with crypto-custody businesses face the issue directly; everyone else should treat unexplained movements from long-dormant exposed addresses as a signal worth monitoring.

What to Deploy Where — Figure
Figure · Decision tree · 9 October 2026

What to deploy where: choosing cryptography when the threat might be quantum, AI or both

The article’s advice turned into choices. Start with one question: are you proving who signed something, or keeping something secret? The answers lead to very different places.

Illustrative guidance — validate with your own security team
What are you protecting?Authenticity (signatures) or confidentiality (encryption and key exchange)?
▼ ▼

Authenticity · signatures

Can the use case tolerate hash-based signatures?Firmware, software updates, long-term roots, low signing volume
Yes · stateful is manageable
LMS or XMSS

Specified by CNSA 2.0 for firmware signing (alongside ML-DSA-87). Strict state management needed — a reused one-time key is a broken key.

Yes · need stateless
SLH-DSA (FIPS 205)

No state to manage; larger signatures. The least structure of any standardised option.

No · high volume, size-constrained (e.g. TLS)
ML-DSA-87, hybrid with classical

Highest parameter set; keep the classical signature alongside; design to swap later.

Confidentiality · key exchange

Must it stay secret for more than ~10 years?Classified traffic, health and financial records, long-lived contracts
Yes · long-lived secrets
Hybrid ML-KEM-1024 + classical, plus a second family

Add FrodoKEM (BSI) for less structure; plan HQC once standardised. Forward secrecy, key rotation — and keep it off harvestable links.

No · short-lived sessions
Hybrid ML-KEM + classical

The default migration step. The point is agility: be able to change the KEM without rebuilding.

Hash-only?
Not possible

Key exchange needs a trapdoor, and every known trapdoor has structure. Choose your structure and your margin.

▼
Blockchain keys
Keep public keys hidden

Don’t reuse addresses; prefer never-signed addresses; confirm multisigs off-chain (Buterin). Don’t panic-migrate.

Long-lived hardware
Agility is a requirement

Satellites, sensors, ISR platforms: hash-signed firmware and a field-replaceable key-exchange layer.

Everything
Inventory first

You can’t migrate what you haven’t found. Every roadmap — NSA, G7, BSI — starts here.

The take

The tree has one shape whichever threat arrives first: hashes where signatures allow, hybrid everywhere, the highest parameters, more than one mathematical family for long-lived secrets, and the ability to change all of it later.Pick the branch by what you protect, not by which threat you fear.

Sources: NIST FIPS 203/204/205 and SP 800-208; NSA CNSA 2.0; BSI TR-02102-1; Vitalik Buterin on X (8 Oct 2026). Illustrative decision guidance by the author — not security advice; validate against your threat model and regulator.
thorstenmeyerai.comin cooperation with vigilsar.com

What to do now

The practical steps are the same whether the threat turns out to be quantum, AI or both. That’s the good news: hedging against the AI threat costs little beyond what the quantum migration already requires.

Know your cryptography. Inventory every algorithm, key, certificate and protocol in use. Every roadmap — CNSA 2.0, the G7’s, BSI’s — starts here, and most organisations still haven’t finished.

Deploy hybrid. Combine post-quantum and classical schemes, as BSI requires, so a break in one doesn’t expose the other.

Use hash-based signatures wherever the use case allows. Firmware, software updates and long-term signing keys are the obvious candidates. SLH-DSA, LMS and XMSS rest on hash functions, which carry the least exploitable structure.

Choose conservative parameters. Use the highest parameter sets, as CNSA 2.0 already does, and evaluate less-structured options such as FrodoKEM for long-term confidentiality.

Diversify the key-exchange layer. Where possible, avoid depending on a single mathematical family. HQC, a code-based scheme NIST selected as a backup, is heading for standardisation; BSI has said it will recommend it once available.

Build for agility. The ability to replace cryptography quickly matters more than any single choice of algorithm.

Shrink exposure in the meantime. Use forward secrecy, rotate keys, avoid exposing public keys unnecessarily, and keep the most sensitive data off networks where it can be harvested.

Don’t panic-migrate. Buterin’s most practical sentence applies well beyond crypto wallets: “I personally have lost more money in botched migrations than I have lost in all hacks combined.” A rushed migration is itself a security risk.

The broader story

This is the part of the AI mathematics story that will matter most outside academia.

Mathematicians are arguing, with good reason, about who should be allowed to use these tools, how results should be released, and who will check them. An association of mathematicians has demanded a boycott; an advisory group at the Institute for Advanced Study has asked labs to stop testing open problems on internal models; Aaronson has called it the “Mathocalypse”. This publication has argued that nobody owns the open problems, and that the real bottleneck is checking, not producing.

But cryptography is where the question stops being academic. A proof of the Unique Games Conjecture changes theoretical computer science. A better algorithm for lattice problems would change who can read the world’s secrets. And unlike a maths paper, it might never be published.

The take

Nothing has been broken. The evidence this week shows AI overturning long-held beliefs about computational hardness by small margins, not collapsing the security of any deployed system. The sceptics, Lindell foremost among them, are right that there’s no evidence elliptic curves or lattices are about to fall.

But the map has still changed, and the new one looks like this:

Elliptic curves: on borrowed time, possibly shorter than the quantum countdown suggests. Lattices: unproven against AI, and the destination most of the world is migrating towards. Codes: the old conservative choice, just reminded that estimates move. Hashes: the safest ground available, not a guarantee.

For finance, intelligence and defence, the conclusion is the same whichever threat arrives first. Migrate now, migrate to hybrid, migrate to agility, and stop treating the deadlines as schedules. The quantum threat comes with a countdown you can watch. The AI threat may arrive as a silence — an empty folder where a paper should have been.

The organisations that come through this well won’t be the ones that guessed the right algorithm. They’ll be the ones that can change their algorithms fastest.


Sources: OpenAI’s mathematics release (6 October 2026) and GitHub repository; Scott Aaronson, “The Mathocalypse” (Shtetl-Optimized, 7 October 2026), including the catalogue of complexity results, the Williams–Alman 3SUM result attributed to an Anthropic model, the absence of cryptography and his sources on labs’ cryptographic testing; the withdrawal of the K3-surfaces Hodge manuscript as reported in that thread and consistent with OpenAI’s repository; Justin Drake’s “bunker mode” post on X (7 October 2026) and coverage by Cointelegraph, Decrypt and CryptoSlate, including the ~6 million BTC exposed-key estimate (Cryptopolitan); Vitalik Buterin’s post on X (8 October 2026); Yehuda Lindell’s response via cryptonews.net and Yellow; Isabel Foxen Duke via Decrypt; NIST FIPS 203, 204 and 205 (August 2024); NSA CNSA 2.0 requirements and timeline via its FAQ and published guides; BSI TR-02102-1 (2025-01 and 2026-01 editions) on hybrid requirements, FrodoKEM and end dates, and BSI’s 1 October 2026 advice on Classic McEliece, via postquantum.com; G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector” (13 January 2026); historical accounts of differential cryptanalysis (Biham and Shamir; Coppersmith, 1994) and of GCHQ’s early public-key work, declassified in 1997. The section “What I think is happening” is the author’s opinion and is presented as such; no evidence of a cryptographic break by any AI system has been published. Not security, legal or investment advice. Analysis and framing are the author’s.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

The Rise of Firewall for AI: Real-Time Threat Detection and Enforcement for GenAI

AIThis post was created with the assistance of artificial intelligence (AI).Generative‑AI systems…

About Thorsten Meyer

AIThis post was created with the assistance of artificial intelligence (AI).Short Bio…

The 90-Day Window Closed. Nobody Sent a Notice.

AIThis post was created with the assistance of artificial intelligence (AI).Why AI-driven…

Reality Check: Can “Taxing Robots” Fund Our Future?

Getting the details right on taxing robots could be crucial for our future, but the challenges and implications are complex—discover more to understand why.