AIThis post was created with the assistance of artificial intelligence (AI).

🔍 Read the full analysis: Why Finance And Defence Must Rethink Security In An AI And Quantum Age on ThorstenMeyerAI.com

Before you orderOffer from Amazon

Get privacy and security gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TL;DR

OpenAI published 722 mathematical manuscripts on Oct. 6, 2026, prompting renewed debate about whether AI could find algorithms that weaken cryptography. No cryptographic system has been shown to be broken, and experts disagree about how much the results say about practical security. Finance, intelligence and defence organizations face the challenge of preparing for both quantum computers and less visible algorithmic advances.

OpenAI published 722 mathematical manuscripts on Oct. 6, 2026, generated by an internal model, prompting renewed discussion about whether AI could find algorithms that weaken cryptography used by banks, intelligence agencies and militaries. The release has not demonstrated a break in any cryptographic system; the concern is that machines may help discover faster methods that challenge assumptions about which problems are hard to solve.

The manuscripts cover 372 families of mathematical results and were generated from roughly 4,000 problems, according to the source report. The report says the work used an unreleased model and averaged about three hours of ChatGPT Pro compute per result. Some claims concern famous open problems, but the results most relevant to cryptography involve possible improvements in computational efficiency.

Among the cited examples are claims involving integer multiplication and the Fourier transform, as well as a result for 3SUM running in about n^1.9992 time. The 3SUM result appeared in a paper by Virginia Vassilevska Williams and Josh Alman, with the report attributing the key idea to an Anthropic model. These are mathematical claims requiring scrutiny, not evidence that encryption has been defeated.

The source report also says OpenAI withdrew a claimed proof concerning the Hodge conjecture for products of K3 surfaces after a sign error was identified. That correction underscores the need for independent checking. Separately, computer scientist Scott Aaronson noted that cryptography was absent from the published manuscripts and said his sources reported that AI companies had begun discreetly testing models against cryptographic protocols. Those tests and their results have not been publicly detailed in the supplied material.

At a glance
analysisWhen: Developing; the manuscripts were publis…
The developmentOpenAI’s release of 722 AI-produced mathematical manuscripts has sharpened warnings that AI could challenge cryptographic assumptions alongside the established quantum-computing threat.
The Old Map Is Gone — ISR Briefing
AI Dispatch · ISR Briefing · 9 October 2026

The old map is gone: AI mathematics, quantum computers and the cryptography holding up finance and defence

For a decade the plan was simple: elliptic curves doomed by quantum; lattices safe; hashes safe. Nothing has been broken. But a second threat has arrived that doesn’t respect those borders — AI producing new mathematics faster than any human community, against assumptions that are believed, not proven.

The map — then and now
Elliptic curves
Then: doomed by quantum

Now: on borrowed time — possibly shorter than the quantum countdown suggests.

Lattices (ML-KEM, ML-DSA)
Then: safe

Now: unproven against AI — and the destination most of the world is migrating to.

Codes (Classic McEliece)
Then: the conservative fallback

Now: reminded estimates move — BSI advised against new deployments on 1 Oct 2026.

Hashes (SLH-DSA, LMS, XMSS)
Then: safe

Now: safest ground available — not a guarantee.

Nothing has been broken. The map changed because the threat model did.
Two threats, one migration
Quantum threat
AI-mathematics threat
Attacks
RSA & elliptic curves
Anything with exploitable structure — possibly the new lattice standards
Needs
Large error-corrected quantum computer
A better algorithm on ordinary computers
Warning signs
Visible: qubits, error rates, roadmaps
Possibly none — an algorithm can be found and kept secret
First to get there
Whoever builds the machine
Whoever has the best model — incl. states that never announce
What survives
Lattices, codes, hashes
Probably hashes; lattices need bigger keys
The quantum threat comes with a countdown you can watch. The AI threat may not.
The trigger — records broken, by slivers
Integer multiplication
< n log n

~n log0.9999999999999 n — a barrier many thought fundamental (OpenAI, claimed)

3SUM
n1.9992

Overturns a half-century conjecture. Williams & Alman; key idea from an Anthropic model

Cryptography
absent

“Conspicuous by its absence” (Aaronson) — labs reportedly testing crypto “gingerly and discreetly”

This week: shaved exponentssliver
A break: 2¹²⁸ → one GPU-weekcollapse
Remarkable mathematics — not a break. The open question: can AI compress the decades the number field sieve took into years? (conceptual, not to scale)
The crypto canary — four voices
Justin Drake · Ethereum Foundation
“Bunker mode”

ECDSA could break before Q-day, “in the worst case in months not years.” Move funds to never-signed addresses. ~6M BTC sit behind exposed keys.

Vitalik Buterin · Ethereum
“ML-DSA / FHE / lattices”

The new risk is the destination of the migration. Hash-only where possible; “much more paranoid” lattice params; ×10 key sizes long-term. Doesn’t recommend anyone scramble.

Yehuda Lindell · Coinbase
“The very definition of FUD”

“No evidence whatsoever” that elliptic-curve assumptions are close to failing.

Isabel Foxen Duke · BIP-360
Don’t treat it as a deadline

Classical breaks could reach “quantum-safe” schemes — but don’t treat a two-year scenario as a date.

Author’s view — what I think is happening
1974 → 1990 → 1994
Differential cryptanalysis

Known to IBM and the NSA designing DES (~1974); public via Biham & Shamir (~1990); confirmed by Coppersmith (1994).

early 1970s → 1997
Public-key cryptography

Invented at GCHQ — RSA- and Diffie–Hellman-equivalents — and kept secret for over two decades.

October 2026
An empty folder

No crypto in 722 manuscripts. Found and withheld? Not posed? Posed and failed? Indistinguishable from outside.

Opinion, not reporting: withholding is plausible, has precedent — and would be the responsible choice. Either way: “nothing published” cannot be read as “nothing found.” There is no evidence of any AI-driven break.
Defence & intelligence — the secrets that must last
Harvest now, decrypt later

Traffic recorded today is decrypted when a break arrives. For secrets that must last 25+ years, a break in 2035 is a break today. A state that finds one won’t announce it — it will mine its archives.

Key exchange can’t be hash-only

Signatures can be built from hashes. Encryption and key exchange need a trapdoor with structure — lattices, codes or group theory. Defence can only choose which structure, how much margin, how many combined.

Hedge
US · NSA CNSA 2.0
Germany · BSI TR-02102-1
Key exchange
ML-KEM-1024 only (highest params)
ML-KEM + FrodoKEM (less structured, tighter reduction)
Signatures
ML-DSA-87; LMS/XMSS for firmware
ML-DSA, SLH-DSA, LMS, XMSS
Hybrid with classical
Not required
Required — classical-only key agreement ends from 2031
Key dates
1 Jan 2027 procurement gate · 2030 firmware & networks · 2033 most systems · 2035 all
2031 onward: end dates for classical-only use
The NSA already does much of what Buterin advises — top parameters, hashes for firmware — but its key exchange rests on one lattice family. Europe’s more diverse, hybrid posture is a sovereignty argument worth making loudly. For 15-year ISR platforms and sensors: crypto-agility is a procurement requirement.
Finance — timelines built on the wrong countdown
G7 CEG roadmap publishedJan 2026
Critical systems migrated2030–32
Whole sector migrated2035
Deadlines are ceilings

Every date was set against quantum hardware forecasts with visible warning. The AI threat offers none.

Agility over destination

“ML-KEM everywhere” means starting over if lattices weaken. “We can swap algorithms” doesn’t.

Watch the canary

Blockchains show a classical break first — exposed keys and balances are public. Monitor dormant exposed addresses.

G7 Cyber Expert Group, co-chaired by the US Treasury and the Bank of England — six phases, non-binding, 2030–32 “challenging but prudent”.
What to do now — the same whether the threat is quantum, AI or both
Inventory

Every algorithm, key, certificate, protocol.

Hybrid

PQ + classical, as BSI requires.

Hash-based signing

Firmware, updates, long-term keys.

Conservative params

Highest sets; evaluate FrodoKEM.

Diversify key exchange

More than one mathematical family; HQC coming.

Build for agility

Swap algorithms without rebuilding.

Shrink exposure

Forward secrecy, rotation, hidden keys.

Don’t panic-migrate

Buterin: lost more in botched migrations than in all hacks.

The take

Nothing has been broken, and the sceptics are right that there’s no evidence elliptic curves or lattices are about to fall. But the map has changed: elliptic curves on borrowed time, lattices unproven against AI, codes reminded that estimates move, hashes the safest ground available. For finance, intelligence and defence the answer is the same whichever threat arrives first.The quantum threat comes with a countdown. The AI threat may arrive as a silence — an empty folder where a paper should have been. The winners will be those who can change their algorithms fastest.

Sources: OpenAI maths release (6 Oct 2026); Aaronson, “The Mathocalypse” (7 Oct 2026); Drake & Buterin posts on X (7–8 Oct 2026); Lindell, Foxen Duke via Decrypt, cryptonews.net, Yellow; ~6M BTC via Cryptopolitan; NIST FIPS 203/204/205; NSA CNSA 2.0; BSI TR-02102-1 (2025/2026) & 1 Oct 2026 Classic McEliece advice; G7 CEG roadmap (13 Jan 2026); DES/GCHQ history. Author’s-view section is opinion. No AI-driven cryptographic break has been published. Not security or investment advice.
thorstenmeyerai.comin cooperation with vigilsar.com

Security Beyond Quantum Readiness

The practical concern for finance, intelligence and defence is that a cryptographic migration plan could address one threat while missing another. Quantum computers running Shor’s algorithm could, if sufficiently capable, break RSA and elliptic-curve cryptography. AI-assisted mathematical discovery presents a different possibility: a more efficient algorithm might run on conventional computers and could be developed without a visible hardware countdown.

This distinction affects planning, not just technology choices. Banks and governments need systems that can be updated as standards change, inventories of where cryptography is used, and processes for evaluating new evidence. Defence and intelligence organizations may also need to account for the possibility that an adversary discovers or withholds a useful algorithm. The source material does not establish that such an algorithm exists; it describes a risk that is harder to observe and schedule against.

For organizations that handle sensitive information over long periods, the issue is whether data protected today could become readable later. The source report offers no evidence that current systems have been compromised. Its central implication is narrower: security assumptions should be tested and migration plans should not treat any mathematical approach as permanently safe.

Amazon

hardware security keys for two-factor authentication

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Post-Quantum Migration Plan

For years, planning for quantum risk has centered on replacing public-key systems such as RSA and elliptic-curve cryptography. A sufficiently powerful, error-corrected quantum computer could use Shor’s algorithm against them. That machine does not currently appear in the source material as an existing capability; quantum risk has instead been managed as a future threat.

In August 2024, the U.S. National Institute of Standards and Technology standardized three post-quantum cryptography algorithms: ML-KEM for establishing encryption keys, ML-DSA for digital signatures, and SLH-DSA, a signature scheme based on hash functions. These standards support migration away from vulnerable public-key systems. The new AI-focused concern questions whether mathematical assumptions behind some replacements could also be challenged; it does not show that the standards are broken.

Cryptocurrency has become a public test case because transactions can expose public keys and link them to valuable assets. On Oct. 7, Ethereum Foundation researcher Justin Drake called for the industry to plan calmly for “bunker mode,” advising users to move funds to addresses whose public keys have not been exposed. The source report estimates that about 6 million bitcoin are held in addresses with exposed public keys, but provides no detailed methodology for that estimate.

“Calmly begin planning for ‘bunker mode.'”

— Justin Drake, Ethereum Foundation researcher

Amazon

wireless security cameras with local storage

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

No Cryptographic Break Shown

The key unknown is whether AI systems can produce a practically useful algorithm that weakens a widely used cryptographic system. The manuscripts described in the source report do not establish that they can, and no break of RSA, elliptic-curve cryptography or the new NIST standards is reported. Mathematical claims still require independent verification, and the cited withdrawal shows that errors can survive initial presentation.

The source material does not identify which protocols AI companies have tested, what results they obtained, or whether any findings have been shared with standards bodies or affected organizations. It also does not provide a validated forecast for when either a capable quantum computer or a useful AI-assisted cryptographic attack might emerge. Drake’s suggested “months not years” scenario is his warning, not a confirmed timeline.

Amazon

quantum-resistant cryptography tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Verification and Migration Decisions

The next near-term step is independent review of the mathematical manuscripts and any further claims about algorithmic performance. For AI companies, the source material leaves open whether cryptography-focused testing will produce public results. For finance, government and defence, the immediate work remains practical: inventory cryptographic dependencies, continue post-quantum migration, and plan how systems can be updated if standards or threat assessments change.

Organizations should distinguish verified vulnerabilities from forecasts when deciding whether to act. Cryptocurrency users and institutions face different exposure and operational constraints, so the source material does not support a universal instruction to move assets or replace systems immediately. New evidence, public technical results and guidance from standards bodies will determine whether the current warnings lead to changes in security practice.

Amazon

cryptography and quantum computing books

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Has AI broken a cryptographic system?

No such break is reported. The mathematical manuscripts and warnings described in the source material raise questions about future algorithmic discoveries, but they do not show that encryption or digital signatures have been defeated.

What did OpenAI publish?

OpenAI published 722 mathematical manuscripts across 372 families on Oct. 6, 2026. The source report says an internal model generated them from roughly 4,000 problems; the claims require independent checking.

Quantum risk depends on building a sufficiently capable quantum computer to run algorithms such as Shor’s. The AI-related concern is that a new algorithm could run on ordinary computers and might be discovered without an observable hardware milestone.

Are post-quantum standards also at risk?

The source report raises questions about assumptions behind lattice-based methods, including ML-DSA, but does not show that any NIST-standardized post-quantum algorithm has been broken.

Should cryptocurrency holders move funds now?

The cited views differ: Justin Drake urged planning for “bunker mode,” while Vitalik Buterin said he did not recommend scrambling to move funds immediately. The source material does not establish a current break or a universal action for all holders.

Source: ThorstenMeyerAI.com

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

MAI-Cyber-1-Flash Inside MDASH

Security officials report a confirmed cyber incident involving MAI-Cyber-1-Flash within the MDASH network, raising concerns about potential vulnerabilities.

CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload Of File With Dangerous Type Vulnerability Actively Exploited (CISA KEV)

A vulnerability in JoomShaper SP Page Builder allows unauthenticated users to upload arbitrary files, now actively exploited according to CISA KEV alerts.

Cybersecurity in Healthcare: Protecting Sensitive Data

Learning how to protect healthcare data is crucial for patient safety and compliance; discover essential strategies to strengthen your cybersecurity defenses.

Zero Trust Architecture Explained

Keen to understand how Zero Trust Architecture transforms cybersecurity by eliminating implicit trust and ensuring comprehensive protection?