Hundreds Of Proofs, And A Conspicuous Gap
On 6 October 2026 OpenAI published a GitHub repository of mathematical manuscripts written by an unreleased internal model. Its README counts 719 manuscripts grouped into 372 families, and says about 42 percent of the top-line results come with a Lean formalization, a machine-checked proof. OpenAI also warns that some unformalized results could contain errors.
Computer scientist Scott Aaronson wrote on 7 October that one subfield is conspicuously missing from the list: cryptography. He added that his sources say AI companies have started, quietly, to test whether their newest internal models can break important cryptographic protocols and primitives, and that it would be better to get ahead of that before everyone else works it out.
That is a secondhand claim from one expert, not a result. It still moved fast. Within a day Ethereum Foundation researcher Justin Drake had asked the blockchain industry to prepare for what he called bunker mode.
Evidence Versus Alarm: Who Said What
Five voices have spoken so far, and they disagree about how much the missing cryptography results mean.
| Voice | Position | Basis |
|---|---|---|
| OpenAI | 372 result families, 719 manuscripts | About 42 percent of top-line results formalized in Lean |
| Scott Aaronson | Cryptography absent, labs quietly probing it | Unnamed sources |
| Justin Drake | Prepare for bunker mode | Speculative argument, no attack shown |
| Vitalik Buterin | Do not scramble, but hedge lattices | Ethereum roadmap already favours hash-based signatures |
| Yehuda Lindell, Coinbase | No evidence elliptic-curve assumptions are failing | Decades of unbroken assumptions |
The summary is simple. Nobody has shown an attack. What exists is an absence in a list, a secondhand report about lab testing and an argument about what a much faster mathematician could do to assumptions that have held for decades.
Why A Post-Quantum Plan Is Not Enough
The EU's coordinated post-quantum roadmap, produced by the NIS Cooperation Group, expects member states to have national transition plans and first pilots by 31 December 2026, to finish high-risk use cases by the end of 2030 and everything by 2035. Its trigger is quantum computers, not AI.
The mainstream standardised replacements for today's public-key schemes, ML-KEM and ML-DSA, are lattice-based. Buterin wrote that humans may have missed mathematical shortcuts in lattice systems, much as decades of work improved factoring, and that Ethereum's roadmap therefore leans toward hash-based signatures where they can do the job. He also noted that websites, VPNs and messaging cannot simply switch to hashes.
The practical lesson is narrower than the alarm. Which algorithm you pick matters less than how fast you can swap it, because a migration that takes years was designed for a threat arriving on a known date, not for one that might arrive as a paper.
What To Do This Quarter
Start with an inventory of where your organisation uses public-key cryptography: TLS certificates, VPNs, code and firmware signing, document signatures, single sign-on tokens and any hardware security modules. Record the algorithm, the key lifetime and who can change it. The EU roadmap lists exactly this as an early step, so the work serves both audits and engineering.
Then ask each vendor one question in writing: can you change the algorithm without replacing the product? Prioritise anything that must stay confidential or trustworthy for ten years or more, and ask whether hash-based signatures are an option for firmware and document signing.
Do not rush migrations in response to this week's posts. Buterin himself warned that botched migrations have cost him more than all the hacks he has seen combined. Wait for a published attack, and make sure that when one comes, swapping is a configuration change and not a project.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: An AI Agent Broke In. Reporting It Had No Deadline | Claude Built the Exploit OpenAI Never Patched



