explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR: claim, evidence, status
  • What did Aaronson actually write?
  • Why would labs test this at all?
  • What did Justin Drake and Vitalik Buterin say?
  • Claimed vs. verified
  • How would we know if the claim were true?
  • What builders can do now
  • How this connects to the bigger picture
  • Open questions
  • Related reading
← Back to blog

explainx / blog

Can AI Break Cryptography? What Is Claimed vs. What Is Verified

AI Security, Cryptography, OpenAI, AI Math, Policy

Scott Aaronson says AI labs are quietly testing whether models can break cryptography. Here is what is claimed, what is verified, and what to do.

Oct 8, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
Can AI Break Cryptography? What Is Claimed vs. What Is Verified

Short answer: nobody has shown that an AI model can break any widely used cryptographic scheme. What exists is a claim, relayed by computer scientist Scott Aaronson on October 7, 2026, that AI companies have "started, gingerly and discreetly" testing whether their newest internal models can. Ethereum researchers took that seriously enough to call for precautions. This post sets out who said what, what is verified, and what is not.

It sits directly after OpenAI's release of hundreds of AI-written math manuscripts, which we covered in OpenAI's 722 math manuscripts: what to check and the eight results that matter. If you want the background on why labs may sit on results, see our earlier post on the rumor that labs are hoarding solved math problems.

TL;DR: claim, evidence, status

table · 2 cols
QuestionAnswer
What is claimed?AI labs have begun testing whether internal models can break important cryptographic protocols and primitives (Aaronson, citing unnamed sources).
Is there a reported break?No. Nothing in the sources names a broken scheme, a lab, or a model.
Who is saying it?Scott Aaronson, a theoretical computer scientist, on his blog Shtetl-Optimized.
Who reacted?Ethereum Foundation researcher Justin Drake urged "bunker mode"; Vitalik Buterin backed precautions and flagged lattice schemes.
Is it verified?The claim is single-sourced and anonymous. The context (OpenAI's math release) is real and public.
What should builders do?Inventory cryptography, plan for algorithm agility, avoid panic migrations.

What did Aaronson actually write?

Aaronson's post "The Mathocalypse" (published October 7, 2026 on Shtetl-Optimized) is mostly a reaction to OpenAI's math release. He lists results he finds striking, including a claimed proof of the Unique Games Conjecture with a Lean certificate, and says the model was tried on roughly 8,000 problems and solved about 5% of them, with around three hours of compute per problem. He also contrasts OpenAI's habit of releasing raw proofs with the approach of having humans write a digested version.

The cryptography point is an update appended to the post. He observes that cryptography is "extremely conspicuous by its absence" from OpenAI's list of papers. He then writes that "my sources tell me that the AI companies have now started, gingerly and discreetly, investigating whether their latest internal models can break" important cryptographic protocols and primitives, and adds that if they can, it would be good to get ahead of it before the rest of the world works it out.

Three details matter for how much weight to give this:

  • It is anonymous. No lab, person, model or date is named.
  • It reports an investigation, not a result. The sentence is conditional throughout: "if they can".
  • The headcount differs inside the post. The body speaks of 372 results while the update cites 376 papers, a reminder that even the numbers around this release are still being tallied.

One more caveat: the post's epigraph is a quote from Omer Reingold about complexity classes, shared with permission. It is not the origin of the cryptography claim, so be wary of summaries that attach his name to it.

Why would labs test this at all?

It is a natural thing to try. Cryptographic security is built on a short list of mathematical assumptions: factoring and discrete logarithms for RSA and elliptic curves, hardness of lattice problems for the newer post-quantum standards, and the behavior of hash functions. A model that can discover real new mathematics, as OpenAI says its does, is also a candidate tool for cryptanalysis.

There is also a responsible-disclosure logic. If a lab found a weakness, the usual norm in security is to notify maintainers before publishing. Aaronson's own phrasing hints at this: getting ahead of things before the rest of the world works it out. That is consistent with how labs now handle cyber capability. Anthropic, for example, tiers access to its cyber-capable models; see our coverage of the Anthropic cyber verification program and of AI attack swarms finding zero-days.

None of that proves anything has been found. It explains why the claim is plausible to experts without being evidence.

What did Justin Drake and Vitalik Buterin say?

According to Cointelegraph's report on Drake's call, Drake posted on October 7 asking the blockchain industry to "calmly begin planning for 'bunker mode'". His proposal is a controlled migration of assets, starting with large and sophisticated holders, to fresh addresses whose public keys have never appeared on chain. The reasoning: an address that has never signed a transaction exposes only a hash of its key, so an attack on the signature scheme (ECDSA) has nothing to work backward from.

Buterin replied on X the same day. As reported by The Block, he did not recommend rushing funds to new wallets, but said keeping assets in addresses that have never signed a transaction makes sense if it is easy, and that "botched migrations" have cost him more than hacks. He also said there is a good chance the concrete security of lattices "will take serious hits from the next two years of AI math", naming ML-DSA and fully homomorphic encryption as areas of concern, and said the industry should prefer hash-based constructions where possible. These are his opinions, not findings.

Note what neither researcher claimed: that a break exists. Both framed the issue as risk management on a timescale of months to a couple of years. Several secondary outlets, including aggregators, compress this into headlines like "AI may break cryptography within 2 years"; treat that wording as a paraphrase of a risk assessment, not a finding. This is a security and mathematics story, and we are deliberately not covering market reactions.

Claimed vs. verified

table · 2 cols
StatementStatus
OpenAI released hundreds of AI-written math manuscriptsVerified: public repository and OpenAI announcement
Some results have Lean certificatesVerified in the repo, with scope caveats we detail in our Lean status post
Cryptography is absent from the released listReported by Aaronson; checkable by reading the repo index
Labs are privately testing models against cryptographyUnverified: anonymous sourcing
A model has broken a real primitiveNo evidence offered by anyone
Drake and Buterin recommend precautionsVerified: public posts as reported by Cointelegraph and The Block

How would we know if the claim were true?

Cryptographic breaks tend to become public in recognizable ways. Watch for:

  1. A preprint or lab post describing an attack, ideally with parameters and a reproducible script. The OpenAI math repo is the template: manuscripts plus machine-checkable artifacts.
  2. A NIST or IETF statement. The post-quantum standards process is public. An advisory about ML-KEM or ML-DSA would be the strongest sign.
  3. Independent cryptographers reproducing it. One lab's claim about its own model is not enough, as the Navier-Stokes dispute showed in our explainer.
  4. Verification norms. The AGMAI responsible-release proposal is relevant: it argues for how AI-generated math should be released and checked.

Absence of these is exactly why this belongs in a "claimed vs. verified" post rather than a news flash.

What builders can do now

You do not need a migration plan on Thursday. You need visibility.

  • Inventory public-key use. TLS certificates, SSH keys, code-signing, JWT signing, wallet and custody keys. Know which algorithm each uses.
  • Aim for crypto agility. Systems that can swap algorithms by configuration are much cheaper to defend than ones with RSA-2048 hard-coded in a firmware image.
  • Prefer conservative primitives where you choose. Hash-based signatures rest on fewer assumptions than lattices, which is the direction Buterin described, at the cost of larger signatures.
  • Do not rush key rotations. Buterin's warning about botched migrations applies to ordinary teams too. Rehearse, stage, and keep rollbacks.
  • Treat AI-generated attacks as a defender tool too. The same models can audit code and protocols; see our guide to an open-source security audit skill for agents.

How this connects to the bigger picture

Two trends are meeting. First, frontier labs are showing models that produce research-grade mathematics at scale. Second, labs are deciding what to publish and what to hold back for safety reasons. Cryptography is where those two collide most sharply, because a result that is a triumph in a journal is an incident in a production system.

It also changes how we should read silence. Aaronson's observation that cryptography is missing from the list is itself only an observation: it could mean nothing was found, nothing was tried, or something was found and withheld. The public record cannot distinguish these. That is the honest state of knowledge today, and it is why we label the lab-testing claim unverified.

Open questions

  • Which labs, if any, are doing this testing, and under what disclosure policy?
  • Would a lab publish a break, or notify standards bodies privately first?
  • How does AI-found cryptanalysis compare to the quantum timeline that migration plans are built around?
  • Will the 5% solve rate on open problems carry over to cryptanalysis, where problems are narrow and heavily studied?

We will update this post if a lab, NIST, or independent cryptographers say anything on the record.

Facts and quotes are accurate as of October 8, 2026, and come from the cited sources. The cryptography claim is anonymous and unconfirmed.

Related reading

  • OpenAI's 722 math manuscripts: what to check
  • OpenAI's eight headline math results and their Lean status
  • Are AI labs hoarding solved math problems?
  • AI did not solve Navier-Stokes: a PhD explainer
  • AGMAI: responsible release of AI-generated mathematics
  • Anthropic cyber verification program
  • Armadin AI attack swarms and zero-days
Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Oct 6, 2026

OpenAI "400 Math Papers" Rumor: What Is Verified and How to Check a Mass Release

On October 6, 2026, a small X account claimed OpenAI is about to release 400 papers on every math problem it has solved. OpenAI has not announced it. This post separates the rumor from the record (10 proofs in August, a 100-plus claim in September), explains why the replies were so hostile, and gives a checklist for judging a mass release of AI-written mathematics.

Sep 21, 2026

ChatGPT's __obi Cookie: How It Tracks You Across Other Websites

Security researcher Buchodi's Threat Intel disclosed that chatgpt.com sets a one-year, cross-site cookie called __obi that gets attached to requests on ordinary e-commerce and advertiser sites running OpenAI's ad pixel — the same mechanism Meta and Google have run for years, now applied to a chat product. The post hit #1 on Hacker News with 592 points and 315 comments.

Sep 18, 2026

GPT-6 Astra Cracked a 1941 Enigma Message and a 1918 WWI Cipher

Two separate builders reported GPT-6 Astra decoding historical ciphers that had sat unsolved for decades — an 82-character 1941 German Army Enigma message (MVUEH) and a 1918 WWI German naval radio transmission from a public list of 50 unsolved ciphers. One result got direct sign-off from a working Enigma historian; the other has an honest, unresolved question about why a message using an already-known key sat unsolved for so long. Here's what actually happened, and what's still unverified.