Binance Co-Founder Zhao Changpeng Gives Vitalik 99.99 Points in Math, Only 0.01 to Himself
Binance co-founder Zhao Changpeng gave Vitalik Buterin a score of 99.99 in math and rated himself 0.01 on October 8, suggesting that together they might accomplish something. He also mentioned that even if few understand it like he does, the lengthy post is worth reading. The post has been viewed over 1.2 million times.
He referenced Buterin's cryptographic warning from the previous day, advising against rushing to transfer funds to new wallets today, but emphasized the need to take seriously the risks posed by AI-accelerated mathematics, reducing exposure to quantum-vulnerable cryptography and cryptography that may be weakened by AI. The new risk areas he identified include ML-DSA, fully homomorphic encryption, and lattice-based cryptography.
The old assumptions were that elliptic curves would break, hash security would hold, and lattices would also be secure. He believes that AI mathematics could significantly undermine the specific security of lattices in the next two years. He drew an analogy to integer factorization, which went from naive 2^(n/2) to 2^(O(n^(1/3))), resulting in RSA keys needing about 400 bytes instead of 64 bytes. He questioned whether there are undiscovered structures in elliptic curves and lattices that humans cannot find but robots can quickly identify.
As a result, the Ethereum Lean roadmap has shifted over the past year to rely solely on hashes: no lattices, no ML-DSA, no Falcon, and no lattice-based commitments in zero-knowledge proofs. Signatures will use hash-based WOTS or SPHINCS. It is already known how to rely solely on hashes for signatures and proofs; the bigger issue is public key encryption, which, according to theorems, cannot rely solely on hashes and must have trapdoor structures. His inference is that to appear long-term secure, key sizes should be multiplied by 10. If AI brings 50 years of mathematics in two years, lattices will still exist but must be much larger; at that size, hashes will be more efficient where hashes can be used.
His personal checklist includes: prioritize hashes where possible; be more paranoid about lattice parameters, extending beyond blockchain to website access, encrypted communication, and anonymous networks; privacy protocols should not put encrypted notes on-chain; if not difficult, keep funds in addresses that have not yet transacted, but be cautious with migrations, as he has lost more money in failed migrations than all hacking incidents combined; multi-signature confirmations should be kept off-chain so that signers' signatures are not public; even if ECDSA fails faster, it will only degrade to the party collecting signatures, not allow anyone to take funds.
This is a forwarding of research positions, not a joint development announcement. Zhao Changpeng has not committed Binance or the BNB chain to change signatures. Buyers must decide whether to pre-exchange holders of unused addresses, while sellers are Ethereum researchers who write the risks of lattice cryptography into the roadmap. Funds have not been transferred due to the scoring. The beneficiaries are those who have moved to hash signatures in the Lean scheme, while projects that treat ML-DSA and fully homomorphic encryption as default secure are under pressure. He explicitly stated not to rush to move wallets today.
Source: Public Information
ABAB AI Insight
Ethereum's cryptographic roadmap has shifted from lattices to hashes over the past year. The Lean scheme has removed ML-DSA, Falcon, and lattice commitments, changing signatures to WOTS or SPHINCS. This is a counter-bet after NIST established lattice algorithms as post-quantum standards: the standard assumes lattices can withstand quantum attacks, while Buterin assumes AI will find shortcuts in the structure similar to number field sieves. The number field sieve reduced RSA from exponential to sub-exponential, causing key sizes to swell to about 400 bytes. He applies the same template to lattices, suggesting a buffer of multiplying key sizes by 10.
Zhao Changpeng's 0.01 points do not mobilize Binance's signature system. He is forwarding reading recommendations. The real resources lie in Ethereum clients and wallets: unused addresses, off-chain multi-signatures, and encrypted notes not placed on-chain. Buterin himself noted that the money lost in failed migrations exceeds all hacking incidents combined. Thus, the checklist places "do not move today" at the top.
A comparison can be made to the transition from SHA-1 to SHA-2 in the 2010s, where browsers provided a multi-year window, and the Bitcoin community's discussions on Shor's algorithm have yet to enforce address changes. The difference this time is equating two years of AI mathematics to fifty years of human mathematics. The industry is in a wait-and-see phase: the roadmap has changed, but no mandatory on-chain upgrades have been announced.
The essence is preparation for technological replacement, not the replacement itself. The mechanism is that structured mathematical objects are more easily dismantled by new tools, while the design goal of hashes is to lack exploitable structure. Public key encryption cannot exist without trapdoors, making website locks and encrypted communication more challenging to rely solely on hashes than blockchain. The scoring has transmitted this judgment from researchers to exchange founders, without becoming a joint laboratory.