Ledger CTO advises those worried about AI breaking ECDSA and emptying Bitcoin to take a chill pill
Ledger CTO Charles Guillemet published a statement on October 9, advising those concerned that AI might break ECDSA at a very low cost in the coming months and empty Bitcoin to take a chill pill. He stated that there are no signs indicating such a breakthrough is imminent.
The first point is about scope. If asymmetric cryptography truly falls, Bitcoin would be the least of the problems: TLS would fail, banking systems would be compromised, secure communications would break down, and critical infrastructure would be more vulnerable to attacks. His analogy is that the house is already on fire while people are still worrying about the Wi-Fi password.
The second point addresses a mathematical result. OpenAI released hundreds of internally generated mathematical manuscripts on October 6, one of which, a preprint from September 23, claims to have broken the n log n barrier for integer multiplication algorithms, with an exponential improvement of 2 to the power of -182. Guillemet acknowledged that this is real mathematics but not a practical breakthrough, nor does it change the understanding of how to break ECDSA. By the standard of "if it hasn't been proven unbreakable, it can't be trusted," hashes are equally insecure.
The post was in response to a timeline dispute. Ethereum Foundation researcher Justin Drake warned that AI-assisted mathematical advancements could shorten the ECDSA risk from years to months, and based on this, discussed controlled migration of funds. Helius CEO Mert Mumtaz also refuted claims of imminent issues. Guillemet concluded that while it is important to keep an eye on research and take cryptographic risks seriously, one should not equate theoretical advancements with an impending cryptographic apocalypse. Currently, there is no public demonstration of AI recovering Bitcoin ECDSA private keys.
ECDSA is the elliptic curve signature used by Bitcoin to prove transactions are authorized by wallet holders. Quantum computers threaten public key cryptography with Shor's algorithm, which is another timeline; this debate is about whether models can first mathematically break this curve. Guillemet separates the two issues: research is worth watching, but low-cost liquidation in a few months is unfounded.
This is narrative-driven risk pricing, not on-chain attacks. The sellers interpret the OpenAI manuscript as a loss of private key security, while buyers see the same exponential improvement as unfeasible for hardware wallets and public chain technology leaders. Funds have not migrated due to this post. The beneficiaries are networks that continue to use existing signatures without needing immediate painful upgrades, while those under pressure are the proposals that cite "collapse within a month" as a reason for migration. If asymmetric cryptography truly fails, selling pressure would first appear in banks and TLS, not just in cryptocurrency prices.
Source: Public information
ABAB AI Insight
Bitcoin has used ECDSA on secp256k1 for transaction signing since 2009, and the Ethereum account system relies on the same type of elliptic curve. The real threat written into the standard timeline is quantum: Shor's algorithm can reverse-engineer private keys from public keys on sufficiently large fault-tolerant machines, which is why NIST has established post-quantum algorithms like CRYSTALS-Dilithium and Kyber. Drake inserting OpenAI's mathematical manuscript into this timeline changes the narrative from "quantum is still many years away" to "models may arrive first." Guillemet maintains the technical stance of a hardware wallet company: until private keys are demonstrated to be extracted, signatures remain unchanged.
Resources have not shifted to new algorithms. Ledger sells devices that keep private keys in secure elements; historical incidents have mostly occurred in supply chains and connection kits, not from ECDSA being mathematically broken. OpenAI's release is a manuscript, and the exponential improvement of 2 to the power of -182 does not even qualify as practical acceleration. Money remains in existing addresses. Whoever pushes for a full network migration first will have to bear the costs of address freezing, signature incompatibility, and user coin loss.
A comparable situation is how SHA-1 collisions were handled in the 2010s: after theoretical collisions were announced, browsers and certificate authorities provided years of replacement windows rather than invalidating all signatures the next day. Y2K also involved changing systems before waiting for the date. The crypto industry is still in an observational phase: research is being monitored, but protocols have not entered mandatory upgrades.
The essence is that technological replacement has not yet occurred, and pricing power is first occupied by narratives. The mechanism is that once public key cryptography truly fails, banks, web locks, and power grid communications will be simultaneously exposed; Bitcoin is just a padlock on the same lock. Framing low-cost liquidation within a month as the main risk equates to translating a network failure into price collapse. Guillemet separates the house on fire from the Wi-Fi password, shifting the migration budget from panic-driven to research tracking.