NoFOMO
搜索 中EN 登录 注册

最高第 1 名 已下榜

Justin Drake呼吁进入掩体模式

以太坊研究员Justin Drake呼吁区块链行业规划“掩体模式”,建议大规模迁移资产到从未签过交易的新地址。

名次变化

要点

  • Justin Drake 呼吁区块链行业冷静开始规划“bunker mode”,并建议将资产有控制地大规模迁移到新地址,即公钥仍隐藏在哈希之后的地址。
  • 他建议持有者——先从大型且成熟的持有者开始——考虑把大部分资金转移到从未签署过交易的地址;签署交易时,也应把剩余资金转移到新地址。
  • Drake 表示,现在有理由为 ECDSA 在 qday 之前被攻破的可能性做准备,最坏情况下是几个月而非几年,即在一周内用大型 GPU 集群等现有硬件快速恢复私钥。
  • 他提到整数乘法的 n log(n) 上界、3SUM 猜想以及 May 对 Erdős 单位距离猜想的反驳,并称昨天的 OpenAI 发布表明数学超级智能已经到来。

要点和反应摘要由 AI 依据本页推文整理,请以原推为准。 我们怎么用 AI

原推

Justin Drake @drakefjustin 16.6万 粉丝

Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
1.6万点赞 2,011转发 1,321回复 475.6万浏览

在 X 上查看 收藏

X 上的热门回复

X 上的反应: 回复以质疑为主。有人称这是不负责任的 FUD,或在没有密码学证据的情况下提出巨大主张,指出 OpenAI 的数学论文与 secp256k1 在几个月内失守无关;也有人表示没人会去黑中本聪的钱包,因为那会毁掉所盗资产的价值。

登录后查看 X 上的 5 条热门回复

来自 @Barabazs_, @tridder46290, @stephanlivera 等,已过滤广告,附中英文翻译。

免费注册 已有账号?登录

讨论 0

还没有人讨论,来说第一句。

推荐信源

觉得我们漏了哪个一手信源,或者该关注什么话题?告诉我们。审核通过后,所有人的榜单都会覆盖到它。

@用户名,或者主页链接