@
drakefjustinToday I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
今天,我呼吁区块链行业冷静地开始规划“避险模式”。我个人建议启动一项有控制的大规模资产迁移计划,将资产转移到新的地址,即那些公钥仍然隐藏在哈希值后面的地址。
Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase).
持有者,尤其是资金量大且经验丰富的持有者,应该考虑将大部分资金转移到从未签署过交易的地址。当他们签署交易时,也应该将剩余资金转移到一个新的地址(该地址可能使用相同的助记词生成)。
Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets.
别着急。虽然我认为有必要采取行动,但仓促迁移弊大于利。也别惊慌。将资产转移到受保护的地址是一个简单的预防措施,无需新的加密技术或新的钱包。
IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).
我认为现在可以合理地做好准备,应对 ECDSA 在 qday 之前崩溃的可能性,最坏的情况是几个月而不是几年内就会发生。我所说的“崩溃”是指在现有硬件(例如大型 GPU 集群)上快速恢复私钥(例如在一周内)。
Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot.
近几日,人类的数学直觉受到了严峻的考验。许多长期以来被奉为圭臬、不容置疑的假设纷纷被推翻,其中包括整数乘法的 n log(n) 界限和 3SUM 猜想。事后看来,梅对埃尔德什单位距离猜想的意外推翻,正是对我们发出的警示。
Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time?
昨天 OpenAI 的发布清楚地表明,数学超级智能时代已经来临。有人说,有些周能带来几十年的进步。我们即将经历的这几周,数学进步的进程将达到几个世纪。我们神奇的 64 字节 ECDSA 签名会不会好得令人难以置信?难道一直以来,所谓的安全仅仅是依靠隐蔽性吗?
Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)
椭圆曲线似乎特别容易受到超级智能的影响。曲线蕴含着丰富的结构,可以运用诸如舒夫变换、弗罗贝尼乌斯变换和配对等精妙的技巧。(相比之下,哈希表的设计目的在于最小化代数结构。)
Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once.
此外,正如 Ewin Tang 所证明的那样,高效的量子算法有时预示着高效的经典算法的出现。我们应该对可能存在一种经典算法来替代 Shor 算法持开放态度,这种算法能够同时突破椭圆曲线和 RSA 的限制。
Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.
值得注意的是,OpenAI 发布的 722 项数学成果中,密码学方面的突破性进展明显不足。我亲眼目睹了美国政府审查学术界的量子密码分析成果。我认为,幕后干预是其根本原因。
I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026).
我敦促规模庞大、经验丰富的机构以身作则。Project11 的“风险列表”( bitcoin-risq-list.projecteleven[.]com )是追踪已泄露比特币公钥的绝佳工具。币安、Bitbank 、Robinhood 、Bitfinex 和 Tether 有机会加强其冷存储的安全性。下个月,我将在伦敦与机构进行现场问答( forum.ethereuminstitutional[.]org/london-2026 )。
Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS.
再次提醒,请不要操之过急。持有低于 50 个比特币的钱包可以部分免受“中本聪盾牌”的保护,即他暴露的 2 万个持有 50 个比特币的地址。像预言机和 L2 安全委员会这样的负载签名者应该考虑在每次签名消息时轮换 ECDSA 公钥,和/或使用基于哈希的方案(例如 SPHINCS )进行多重签名。
Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security.
安全退出“地堡模式”需要后人工智能时代的密码学。我倾向于全面采用基于哈希的密码学,并完全避免任何结构化的数学假设,无论是曲线、格还是同源矩阵。一个经过实战检验的哈希算法(例如 SHA 或 BLAKE 系列)就能提供可靠的后人工智能时代安全性。
The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
以太坊在 strawmap[.]org 上的路线图全面采用了基于哈希的密码学和端到端形式化验证,以此应对量子威胁。鉴于数学超级智能的出现,这些时间表现在必须重新审视并加快推进。我将力争最大限度地加快防御进程。
V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。
V2EX is a community of developers, designers and creative people.