🔍 Read the full analysis: How Defence And Finance Depend On Cryptography In A Changing Tech Era on ThorstenMeyerAI.com
Get hardware and tech essentials delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
TL;DR
A report on AI-generated mathematical work has prompted discussion about whether new algorithms could weaken cryptographic systems used in finance, intelligence and defence. No cryptographic break has been demonstrated, and experts cited in the report disagree about how urgent the risk is.
A reported release of 722 AI-generated mathematical manuscripts has revived debate about the assumptions behind cryptography used across finance, intelligence and defence. The report says the work includes results on computational problems relevant to cryptographic security, but no cryptographic system has been shown to be broken; the concern is that future algorithms could weaken assumptions on which current and planned systems rely.
According to the source, OpenAI published the manuscripts on October 6, grouped into 372 families and generated by an unreleased internal model working on roughly 4,000 problems. The source says the model used an average of about three hours of ChatGPT Pro compute per result. The manuscripts include claims about the Unique Games Conjecture, Hilbert’s tenth problem over the rationals and a zero-free region for the Riemann zeta function. These are reported mathematical claims, not all independently verified results.
Some of the results drawing attention concern the speed of computation. The source points to work on integer multiplication and Fourier transforms below the n log n threshold, as well as a result for 3SUM that it says challenges a long-standing expectation about the problem’s runtime. It attributes the 3SUM work to Virginia Vassilevska Williams and Josh Alman, and says an Anthropic model supplied a key idea. Computer scientist Scott Aaronson reportedly noted that cryptography was absent from the published set, while saying AI companies have begun testing internal models against important protocols.
The report distinguishes the established concern about quantum computers from the newer, less defined AI-related possibility. A sufficiently capable quantum computer running Shor’s algorithm could threaten RSA and elliptic-curve cryptography. By contrast, the proposed AI risk is that a model might help discover a more efficient algorithm on ordinary computers. No such cryptographic algorithm is identified in the source, and the report does not establish that lattice-based standards have been weakened.
The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence
For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.
Now: on borrowed time — possibly shorter than the quantum countdown suggests.
Now: unproven against AI — and the destination most of the world is migrating to.
Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.
Now: safest ground available — not a guarantee.
~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)
Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model
“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”
ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.
The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.
“No evidence whatsoever” that elliptic-curve assumptions are close to failing.
Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.
Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).
Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.
No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.
Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.
Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.
Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.
“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.
Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.
Every algorithm, key, certificate, protocol.
PQ + classical, as BSI requires.
Firmware, updates, long-term keys.
Highest sets; evaluate FrodoKEM.
More than one mathematical family; HQC coming.
Swap algorithms without rebuilding.
Forward secrecy, rotation, hidden keys.
Buterin: lost more in botched migrations than in all hacks.
Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.
Risks for Finance and National Security
Cryptography protects sensitive communications, financial transactions, identity systems and the integrity of digital records. A demonstrated method for defeating widely used public-key systems could create immediate risks for institutions that depend on secure authentication and encrypted information. The source emphasizes that finance, intelligence and defence would all have to assess exposure, though it does not document a specific breach or operational impact.
The practical concern is not that AI has already defeated encryption, but that a useful algorithm could be discovered without a visible hardware milestone. Quantum-computing progress can be tracked through public research and engineering indicators. A mathematical breakthrough might remain private, leaving other governments, banks and military agencies unaware that an assumption has changed. That uncertainty makes the issue relevant to security planning, while the absence of a demonstrated break argues against treating the warning as proof of immediate compromise.
Preparation also carries costs. Replacing cryptographic systems involves software, hardware, operational procedures and compatibility testing across large organizations. If a threat is overstated, hurried changes can introduce errors; if a real weakness goes undetected, delayed migration could leave sensitive systems exposed. The report therefore points to a need for careful review rather than an immediate, blanket change to cryptographic infrastructure.
As an affiliate, we earn on qualifying purchases.
Quantum Migration Meets a New Concern
Governments and technology firms have been preparing for the possibility that large, error-corrected quantum computers could break some public-key cryptography. In August 2024, the US National Institute of Standards and Technology standardized ML-KEM for key establishment and ML-DSA for digital signatures, both based on lattices, alongside SLH-DSA, which uses hash functions. These standards form part of the post-quantum migration discussed in the source.
The report says the new concern differs because it could involve algorithms running on conventional computers rather than a future quantum machine. It raises the possibility that mathematical structures used by lattice-based systems might prove less resistant than expected. That is a possibility discussed by the source, not evidence that the standardized systems are currently vulnerable. Cryptographic security relies on problems believed to be difficult; it is not generally established by proving that no faster method can exist.
Cryptocurrency has become a public arena for this debate because blockchain transactions can expose public keys, and holdings can be visible on public ledgers. The source reports that Ethereum Foundation researcher Justin Drake urged planning for a possible “bunker mode” and moving funds to addresses whose public keys have not been exposed. Ethereum co-founder Vitalik Buterin, however, cautioned against a rush to move funds and raised questions about the security assumptions behind lattices and related methods.
quantum-resistant encryption hardware
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
No Cryptographic Break Has Been Shown
The source does not identify a new algorithm that breaks RSA, elliptic-curve cryptography or any post-quantum standard. It also does not provide independent validation that AI has found a practical cryptographic attack. The mathematical manuscripts themselves remain subject to checking: the source reports that OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a sign error was identified.
It is unclear whether the AI work will lead to verified advances in cryptanalysis, whether any private models have found relevant techniques, or whether organizations have evidence of undisclosed vulnerabilities. The source’s comparison between quantum and AI risks is an analysis of possible threat paths, not a confirmed timetable. Its estimates about exposed cryptocurrency keys and the potential speed of an attack should be treated as claims reported by the source, not proof of a present exploit.
cryptography textbooks for professionals
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Verification and Security Reviews
The immediate next step is independent scrutiny of the mathematical claims and any proposed cryptographic implications. Researchers and standards bodies would need to test whether a new method is correct, practical and applicable to real systems before treating it as a security break. The source gives no timetable for such findings and does not announce a change to NIST’s standards.
Organizations responsible for sensitive systems can use the debate to review their cryptographic inventories, migration plans and procedures for responding to newly discovered weaknesses. That is different from advising users to move funds or replace systems immediately. Further public results, peer review and statements from standards bodies or affected institutions will determine whether the concern develops into a specific, verifiable security issue.
As an affiliate, we earn on qualifying purchases.
Key Questions
Has AI broken a major cryptographic system?
No break is reported. The source describes concerns about what AI might help discover, but does not identify an algorithm that defeats RSA, elliptic-curve cryptography or a post-quantum standard.
What did OpenAI publish?
The source says OpenAI published 722 mathematical manuscripts on October 6, organized into 372 families and generated by an unreleased internal model. The results are claims requiring mathematical checking; the source reports at least one withdrawal after an error was found.
How is the proposed AI risk different from the quantum threat?
A sufficiently capable quantum computer could use Shor’s algorithm against RSA and elliptic-curve systems. The AI concern described here is that models could help discover faster algorithms that run on conventional computers. The source presents this as a possibility, not a demonstrated attack.
Should cryptocurrency users move their funds?
The source reports that Justin Drake called for planning, while Vitalik Buterin said he did not recommend users scramble to move funds immediately. The article does not provide individualized financial guidance. Cryptocurrency and other digital assets can be volatile and carry a risk of loss.
Are post-quantum standards such as ML-DSA known to be vulnerable?
No vulnerability is established in the source. It raises questions about assumptions behind lattice-based systems, including ML-DSA, but gives no verified method for breaking them. NIST standardized ML-DSA in 2024 as part of post-quantum cryptography efforts.
Source: ThorstenMeyerAI.com
Columbus Day / Indigenous Peoples' Day Picks
long weekend sales
As an affiliate, we earn on qualifying purchases.
