Justin Drake is a core researcher at the Ethereum Foundation. Justin just reinvented the Bitcoin term “Bunker Mode”. First used by Adam Back in 2019.

Just in case you missed the memo, 2 days ago Justin shared the following with Bitcoin Twitter and every influencer and his dog has been recycling. Be warned this was an extended tweet, but it is important to read it in entirety, not just the sound bites or click baits
- massive warning to #Bitcoin whales to enter “Bunker Mode”
- cryptography protecting private keys could break in “months not years”
- mathematical super intelligence is upon us
NOTE: the above sound bites are usually written in capitals for maximum impact
Urgent Warning
Justin’s tweet has been compressed
”Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase).
Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets.
IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).
Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot.
Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time?
Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)
Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once.
Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.
I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026).
Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS.
Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security.
The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration. @drakefjustin October 8th 2026
FUD burger

Adam Back’s bio is cypherpunk, cryptographer, privacy/ecash, inventor hashcash (bitcoin mining), PhD Comp Sci, Co-founder Blockstream and @bstrco, a Satoshi candidate
Below is a reply to Justin, sorry but can’t find the tweet again to add the Twitter handle. But it sums up pretty well the general consensus and adds a bit more than Adam’s simple “FUD Burger” comment.
“You are making an enormous claim with basically no cryptographic evidence behind it. A practical classical break of ECDSA means fast elliptic curve discrete log solving, one of the biggest breakthroughs in the history of cryptography. You have not shown an attack, a paper, a benchmark, a toy result, or even a plausible mechanism. "AI did math", "some conjectures fell", "elliptic curves have structure", and "maybe governments hide things" do not get you to private key recovery on standard curves using GPU clusters in months.
Avoiding address reuse and keeping public keys unexposed is basic wallet hygiene, the kind of thing people have known for years. You are dressing that up as "bunker mode" and pretending the ECDSA threat model suddenly changed. Shor, Ewin Tang, OpenAI math results, and vague claims about hidden cryptanalysis do not form an attack path. If you are going to posture as a security researcher, bring an actual attack, a reduction, a benchmark, or even a credible technical argument. @????????0

Disclaimer: the above meme did not fit in the little box nicely so added again in case you want to use
NOTE: if you have sent sats from your wallet, reused your public address or is Satoshi era sats, your public address is (theoretical) quantum vulnerable.

Support Your Local Bloggers Grandson Stacking Sats

Solpick.io offers their faucet, surveys and gaming. You can level up by earning from surveys or wagering. Been using for over a year and had no problem withdrawing to exchanges or the Ledger Nano. Allows 5 free withdrawals per day, minimum of 0.00250000 SOL per withdrawal.
https://solpick.io/?ref=VEH2024
The other Solana faucet we use daily is
https://solfaucet.togatech.org/
This the “first-ever Solana mainnet faucet”. 0.00001 SOL paid each day to your wallet, no strings attached. Only pays to wallets that have the minimum rent-exempt balance of 0.00089088 SOL (does that count as an attached string?)