Community Trust ScoreVerified
Haseeb Qureshi isn’t buying the bunker strategy. The managing partner at Dragonfly pushed back hard on what he calls “cryptographic doomerism” — a term he used to describe the idea of simply moving tokens to fresh addresses and hoping for the best.
Why It Matters
The discussion surrounding the vulnerabilities of Bitcoin addresses and the efficacy of the "bunker mode" highlights broader concerns about the security of cryptographic algorithms used in the industry, particularly as advancements in technology could threaten their integrity. Qureshi's rejection of a passive approach to security underscores a critical need for proactive measures within the crypto community, especially as significant amounts of Bitcoin remain vulnerable. This debate may influence market sentiment and investment strategies as stakeholders weigh the risks associated with existing cryptographic standards against emerging threats.
The debate got loud fast. Ethereum researcher Justin Drake had been warning the industry that the elliptic curve digital signature algorithm, better known as ECDSA, could be cracked sooner than anyone wants to admit. ECDSA is basically the lock on every crypto wallet. Drake’s alarm came after an OpenAI report laid out just how quickly AI is getting good at mathematics — the kind of mathematics that underpins cryptographic security. His read on the situation: vulnerabilities could emerge within months, not years. So his recommendation was that users start gradually moving holdings to new wallets where public keys aren’t exposed. Call it a slow, careful retreat.
Qureshi says that’s not enough.
His argument is pretty straightforward. Moving coins to a fresh address only protects them as long as they stay put. The moment other coins get compromised and hit the market in volume, those untouched assets could become worthless anyway. You’ve secured the coins but not the value. That’s the core problem with what he calls bunker mode — it’s reactive, not structural, and it doesn’t fix anything at the network level.
Qureshi’s Proposed Fix: Cryptographic Recovery Mode
What Qureshi wants instead is something he calls “Cryptographic Recovery Mode.” The idea is a hash-based backup signature scheme that users can attach to their existing addresses. If AI — or a quantum computer, for that matter — managed to break the underlying cryptographic signatures, network validators could still enforce recovery using that backup. It’s a fallback built into the system rather than a workaround bolted on top.
It’s a bigger ask. It requires buy-in at the protocol level, coordination among validators, and probably years of development. But Qureshi seems to think the alternative — patching wallets one by one while the threat grows — is worse.
The numbers give some sense of why people are nervous. Glassnode put 6.26 million Bitcoin in vulnerable addresses right now. That’s over 31% of the entire supply. Of that figure, around 4.33 million BTC are at risk because of address reuse, and another 1.94 million are exposed due to their address format. Glassnode co-founder Rafael Schultze-Kraft broke it down further: nearly 1.8 million BTC sit on exchanges, and 57% of all exchange balances are at risk. Those aren’t small numbers. That’s a massive chunk of the market sitting in formats that weren’t designed to withstand what AI might be able to do soon.
Buterin Urges Caution, No Consensus in Sight
Ethereum co-founder Vitalik Buterin weighed in too, though more carefully. He acknowledged that AI-enhanced mathematics is a real threat worth taking seriously. But he pushed back on the idea of rushing to move funds to new wallets. His position was measured — the risks are real, the industry should think hard about them, but hasty moves can create their own problems. Don’t panic, basically.
And that’s kind of where the debate sits right now. Nobody’s really in agreement. Drake wants users moving funds. Qureshi wants a protocol-level recovery system. Buterin wants the industry to slow down and think. Three serious people, three different reads on urgency and method.
What everyone does seem to agree on: ECDSA is the weak point. And AI’s ability to attack it is moving faster than the industry’s ability to defend it. Drake’s concern isn’t hypothetical — it’s grounded in documented progress from OpenAI on AI-driven mathematical reasoning. The gap between “theoretical risk” and “actual threat” may be narrowing faster than most of the market has priced in.
The broader context matters here too. Quantum computing has been a known long-term threat to cryptographic security for years. Blockchain developers have been working on quantum-resistant algorithms, though progress has been uneven. What Drake’s warning adds is a shorter fuse — AI might get there before quantum does, and the industry’s timeline assumptions may be badly wrong.
No clear plan exists yet. No coordinated response. Qureshi’s Cryptographic Recovery Mode is a proposal, not a deployed solution. Drake’s recommendation to migrate wallets is sensible but incomplete — it doesn’t solve the problem at scale if millions of coins stay put. And Buterin’s caution, while reasonable, doesn’t move the ball forward.
The 6.26 million BTC sitting in vulnerable addresses aren’t going anywhere on their own.
Frequently Asked Questions
What is Haseeb Qureshi’s “Cryptographic Recovery Mode”?
It’s a proposed hash-based backup signature scheme that users can link to their addresses, allowing network validators to enforce asset recovery if AI or quantum computing breaks existing cryptographic signatures.
How much Bitcoin is currently at risk from cryptographic vulnerabilities?
Per Glassnode, 6.26 million Bitcoin — over 31% of total supply — sit in vulnerable addresses, with 4.33 million at risk from address reuse and 1.94 million exposed due to address format.





