🔍 Read the full analysis: How Finance And Defence Are Preparing For Quantum Computing And AI on ThorstenMeyerAI.com
Get everyday essentials delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
TL;DR
An October 6 release of AI-generated mathematical manuscripts has renewed debate about whether advances in algorithms could challenge cryptographic assumptions before quantum computers arrive. No cryptographic protocol has been reported broken, and the manuscripts include claims that still require verification. Finance, intelligence and defence organizations face a harder migration question: how to prepare when the timing and nature of a potential AI-driven threat are unknown.
OpenAI published 722 mathematical manuscripts on October 6, prompting renewed scrutiny of whether AI could find algorithms that weaken cryptographic systems used by finance, intelligence and defence. The publication does not show that any encryption or signature scheme has been broken: the results are claims requiring review, and the report says the release contained no cryptography results.
The manuscripts were grouped into 372 families and were produced by an unreleased internal model from roughly 4,000 problems, according to the source report. It says the model used about three hours of ChatGPT Pro compute per result on average. Some submissions concern well-known mathematical problems, while other reported results relate to computational complexity—the study of how quickly problems can be solved.
Those complexity claims have drawn attention because cryptographic security often depends on certain calculations remaining infeasible. The report points to claims involving faster methods for integer multiplication and Fourier transforms, as well as a result on the 3SUM problem. Separately, Virginia Vassilevska Williams and Josh Alman published work on a faster 3SUM algorithm, with the key idea attributed in the source to an Anthropic model. These developments do not themselves demonstrate an attack on deployed cryptography.
The source report also says OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a sign error was identified. That episode illustrates the distinction between generating mathematical work and establishing that it is correct. The report attributes to computer scientist Scott Aaronson the observation that cryptography was conspicuously absent from the 722 manuscripts, while saying AI companies have discreetly tested models against important protocols. Those tests are not described in enough detail to establish what was tested or what results were obtained.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Why Crypto Migration Plans Face New Questions
The immediate concern for organizations is not evidence of a present-day break; it is that AI could change the assumptions behind security planning. The quantum threat has a recognizable technical target: a sufficiently capable, error-corrected quantum computer running Shor’s algorithm could threaten RSA and elliptic-curve cryptography. An algorithmic advance made with AI could run on ordinary computers and might be difficult to detect if its discoverer kept it secret.
That difference matters to banks, governments and militaries choosing how quickly to replace systems and which standards to adopt. A migration plan built around a visible quantum-computing timetable may not account for an unexpected classical algorithm. But the possibility described in the report remains speculative: no evidence presented there shows that current post-quantum standards have been defeated.
For finance, a failure in public-key cryptography could threaten authentication, transactions and stored assets. For intelligence and defence, the stakes include protected communications and the confidentiality of information collected today. These sectors cannot wait for certainty before planning, but they also need verified evidence before treating a theoretical risk as an operational compromise.
quantum computing cryptography books
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Quantum Standards Meet AI Uncertainty
Governments and companies are already preparing for quantum computers because Shor’s algorithm is known to threaten widely used public-key systems if sufficiently powerful machines are built. In August 2024, the U.S. National Institute of Standards and Technology standardized ML-KEM for establishing encryption keys, ML-DSA for digital signatures, and SLH-DSA, a signature standard based on hash functions. The source describes the first two as lattice-based.
The source report frames AI as a different kind of risk, not a demonstrated replacement for the quantum threat. Quantum hardware progress can be assessed through public research and engineering milestones. A mathematical technique, by contrast, could be developed privately and applied using existing computers. The report raises questions about whether advances could affect lattice-based systems, but does not provide evidence that they have. Hash-based cryptography is presented as a possible area of resilience, not as a guarantee against every future attack.
Public warnings have also come from the cryptocurrency sector, where some public keys are visible on blockchains. On October 7, Ethereum Foundation researcher Justin Drake urged the industry to plan calmly for a possible protective “bunker mode,” including moving funds to addresses whose public keys have not been exposed. The report says Ethereum co-founder Vitalik Buterin later cautioned against rushing to move funds, while drawing attention to possible risks involving lattices and related systems.
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Has Been Shown
The central unknown is whether AI systems can produce a practical algorithm that weakens a cryptographic standard, and whether any such result already exists privately. The source report gives no technical findings from the alleged protocol tests, and it does not identify protocols tested, performance results or independent reviewers. It also does not establish that the mathematical claims in the manuscripts have been independently verified.
It remains unclear how likely or how soon an AI-enabled attack might be, whether any such attack would work against deployed keys, and which standards could be affected. The report’s warning about lattices is a concern about assumptions, not a confirmed vulnerability. Likewise, the withdrawal of one mathematical claim after an error shows why review is necessary; it does not invalidate all the other work.
The scale and timing of exposure across finance, intelligence and defence are also not specified. The report cites cryptocurrency holdings with exposed public keys, but that figure does not establish that those funds can currently be stolen. No evidence supplied here confirms an active attack or a change to official migration guidance.
As an affiliate, we earn on qualifying purchases.
Verification and Migration Decisions Ahead
The next step is independent mathematical and security review of the AI-generated results, alongside clearer disclosures about any tests of real cryptographic protocols. Until credible evidence of a break is published and reproduced, organizations should distinguish research warnings from confirmed vulnerabilities.
Finance, intelligence and defence agencies will need to track both quantum hardware and advances in classical algorithms as they update cryptographic inventories and migration schedules. NIST’s established standards remain part of the current response to quantum risk; the source report does not say they have been withdrawn or replaced. Further assessment will be needed to determine whether key sizes, implementation choices or timelines should change.
For cryptocurrency users, Drake’s and Buterin’s comments reflect different levels of urgency, not a verified incident requiring immediate action. The practical outlook will depend on what researchers can reproduce, whether any vulnerability affects deployed systems, and whether standards bodies or government security agencies issue updated guidance.
As an affiliate, we earn on qualifying purchases.
Key Questions
Has AI broken a cryptographic system?
No break is confirmed in the source material. The mathematical manuscripts and warnings have prompted scrutiny, but they do not demonstrate that a deployed encryption or signature system has been compromised.
What is the difference between the AI and quantum risks?
A sufficiently capable quantum computer could use Shor’s algorithm against RSA and elliptic-curve cryptography. The AI concern is that a model might help discover a new algorithm that runs on ordinary computers; the report presents this as a possibility, not an established attack.
Which post-quantum standards are mentioned?
NIST standardized ML-KEM for key establishment, ML-DSA for digital signatures and SLH-DSA, a hash-based signature standard, in August 2024. The source does not report that these standards have been broken.
Should cryptocurrency holders move their funds now?
The source reports that Justin Drake urged planning for a possible protective mode, while Vitalik Buterin said he did not recommend scrambling to move funds immediately. It describes no confirmed attack, so the comments should not be treated as evidence that exposed funds are currently at risk of theft.
What evidence would change the assessment?
A reproducible attack, independent verification of a relevant algorithm, or formal guidance from standards bodies and security agencies would clarify the practical risk. The report does not provide those confirmations.
Source: ThorstenMeyerAI.com
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
