Loading...
Justin Drake's post is a warning about the security issues of encrypted asset addresses, mainly "addresses with exposed public keys" (both transferred and signed are considered; new addresses derived from the same set of mnemonic words, as long as they have not been signed, are considered not exposed). This set of judgments applies to Bitcoin ordinary addresses (starting with 1, bc1q) and external Ethereum accounts. Taproot (bc1p) exception: The public key is directly written in the output, which has not been used and has already been exposed. Satoshi Nakamoto's very early addresses were also an exception, and the public key was used as a lock at that time. Drake's concern this time is not that quantum computers have already come out. He is more concerned that AI is developing too quickly in mathematics now, and the situation will change prematurely. The assumption that 'once the public key is exposed, it will run naked' was something that should only be concerned about a few years later. According to his judgment, the worst-case scenario now is to pay attention within a few months, not years. Once there is a breakthrough in AI mathematics, there is a probability that a way will be found to deduce the private key from the public key before quantum computers mature. He called it ECDSA being 'broken'. According to his worst-case scenario, not in a few years, but within a few months, using the existing large GPU cluster, it would take about a week to calculate the private key from a publicly available public key. However, this is his judgment and warning, not a crack that has already occurred. So, what should we do for users? Start with large clients, exchanges, and institutional cold wallets, and transfer most of the funds to a new address that has never been signed before. In the future, if you really need to spend a sum of money, sign it and transfer the remaining money to another new address (which can be derived using the same set of mnemonic words). Don't worry. Moving across the entire network at the same time, handling fees, operational errors, and fishing can cause greater harm than the threat itself. In the early days, Satoshi Nakamoto had approximately 20000 addresses with exposed public keys, each containing 50 BTC. If such an attack really occurs, these addresses will be the more prominent first targets. A wallet with a position of less than 50 BTC and a public key that has been exposed, therefore has a layer of partial cover, but is ranked lower and not secure. The addresses whose public keys have not been exposed are not included in this batch of vulnerable targets. Why are unsigned addresses secure Because Bitcoin and Ethereum use elliptic curves (ECDSA) for signatures. The attacker wants to steal coins. According to the cracking path described this time, they need to obtain the public key first before they can deduce the private key. Bitcoin ordinary addresses and Ethereum external accounts, as long as they have never been signed, often only the address itself, which is the hash of the public key, can be seen on the chain, and the public key cannot be seen. The public key will only be displayed during the first signature and transfer. Signing off chain and being publicly disclosed can also be considered as exposure. Therefore, addresses that have never been signed can be used as temporary shelters: staying inside, attackers do not even have a public key, and the elliptic curve cracking system is powerless. Taproot and very early addresses that directly exposed public keys are not in this bunker.