Shorting the panic, buying the silence.
The market is obsessed with quantum computers. The narrative is predictable: Shor's algorithm will shatter ECDSA in ten years. The Bitcoin core developers will scramble to fork in a post-quantum signature scheme. The migration will be messy. The ledger will survive.
That narrative is a trap.

A leak from within a top-tier AI safety lab suggests the real threat vector is not a quantum chip in an IBM cold room. It is a large language model trained on cryptanalytic papers, given access to a cryptographic oracle, and instructed to find a shortcut.
Anthropic's encryption discovery is not yet public. The details are locked under NDA. But the signal is clear: if an AI can learn to break a lattice-based assumption faster than a classic algorithm, the entire post-quantum cryptography standardization effort is built on sand.
The ledger does not sleep, but the analyst must.
Let's be precise. Bitcoin currently uses ECDSA over secp256k1. A quantum computer with 1500 logical qubits could theoretically break it via Shor's algorithm. That machine does not exist today. The timeline for fault-tolerant quantum computing is still a decade away, conservatively.
But the National Institute of Standards and Technology (NIST) has already standardized several post-quantum algorithms. The most promising ones—Crystals-Kyber, Crystals-Dilithium, Falcon, SPHINCS+—are based on problems like Learning With Errors (LWE) and Short Integer Solution (SIS). These problems are assumed hard for classical and quantum computers alike.
The assumption is the weak point.
In 2025, I audited a zero-knowledge proof system that relied on the hardness of a structured lattice problem. The protocol seemed sound. But during a deep dive into the proof reduction, I realized the underlying lattice problem had a hidden linear structure. The team had assumed security against a generic quantum adversary, but a cunning classical attack exploiting the structure could break it in polynomial time.
I learned a hard lesson: cryptographic assumptions are not axioms. They are bets on computational complexity. And AI changes the terms of the bet.
During my PhD at KTH in Stockholm, I studied the limits of zero-knowledge proofs. A professor once told me: "Cryptography is the art of turning intractable problems into trust. But the definition of intractable is a moving target." At the time, we worried about quantum computers. Today, I worry about models that can internalize a cryptographic problem and search the space of attack vectors faster than any human cryptanalyst.
The core insight of the Anthropic discovery—if real—is that transformer-based models can be fine-tuned to perform a specific kind of mathematical reasoning that mimics the search for a short lattice vector. This is not a general AI that invents a new attack. It is a narrow AI that automates a specific cryptanalytic step, accelerating the discovery of vulnerabilities by orders of magnitude.
The implications for blockchain are direct. Every smart contract, every L2 bridge, every ZK-rollup that relies on a post-quantum signature scheme for its long-term security is now on a ticking clock. The clock is not set by quantum computing. It is set by the compute budget Anthropic or any other lab is willing to spend on training a specialized cryptanalyst model.
Yield is a lie; liquidity is the truth. The liquidity of security assumptions is now in question.
Let's examine the practicalities. The article claims that AI may threaten post-quantum cryptography before quantum computers break Bitcoin's current signatures. This is a critical reframing.
Bitcoin's current signature scheme is ECDSA. To break it, you need Shor's algorithm running on a fault-tolerant quantum computer. That is a hardware problem.
Post-quantum signature schemes like SPHINCS+ or Dilithium are based on problems like hash-based or lattice-based hardness. To break them, you need a new algorithm. That is an algorithm problem.
AI excels at algorithm discovery. AlphaFold solved protein folding, a problem deemed intractable for decades. AlphaTensor discovered faster matrix multiplication algorithms. There is no reason to believe that a similar architecture, trained on LWE problem instances, cannot find a heuristic attack that reduces the effective security level from 256 bits to, say, 80 bits.
80 bits is not safe. Not for a settlement layer holding trillions of dollars.
Risk is not a number; it is a narrative. The narrative has shifted.
Here is the contrarian angle. Most analysts will dismiss this story as FUD. They will point to the lack of peer-reviewed evidence. They will argue that Anthropic has not published anything. They will claim the market will ignore it.
They are wrong to ignore it. They are also wrong to panic.
The real play is not to short Bitcoin or to buy some obscure quantum-resistant token. The real play is to recognize that the cryptographic infrastructure of crypto is about to enter a phase of accelerating uncertainty.
This uncertainty is an opportunity. The opportunity is not in betting against the current technology. It is in positioning for the upgrade cycle.
When a new signature scheme is needed, the projects that have already integrated a modular signature abstraction will be ahead. The ones with a flexible multisig architecture, the ones that separate the signing logic from the core protocol, the ones that can execute a emergency hard fork—those are the survivors.
The squeeze is not an event; it is a mechanism. In this case, the squeeze is on all projects that have bet their long-term security on a single, untested post-quantum assumption without a fallback plan.

Let me be specific. If you hold a large position in a L2 that uses a STARK-based proof system, you should check the cryptographic assumptions of the STARK. Many STARKs rely on the hardness of the tentering problem. If an AI model can reduce the complexity of that problem, the entire rollup's security margin collapses.
During the Terra/Luna crash, I saw over-leveraged institutions get wiped out because they assumed the peg would hold. The assumption was the risk. The same logic applies here. The assumption that NIST's standardized algorithms are safe against AI-driven cryptanalysis is the next bubble waiting to pop.
I am not saying the assumptions will break tomorrow. I am saying that the timeline is now a function of AI compute, not quantum hardware. That changes everything.
The market will not price this in until there is a concrete demonstration. A proof-of-concept. A model that finds a valid signature for a given Dilithium public key faster than brute force. Once that demonstration exists, the panic will be swift.
Shorting the panic means preparing for that moment. It means increasing allocation to protocols with robust upgrade mechanisms. It means diversifying across different signature families. It means not trusting any single cryptographic assumption with all your capital.
The squeeze is a mechanism, not an event. The mechanism here is the forced re-evaluation of all post-quantum security budgets.
My advice is clinical. Do not panic sell. Do not chase after the first "quantum-resistant" token you see. Instead, do your own due diligence on the cryptographic stack of your primary holdings. Ask the developers: "What is your plan if Dilithium or SPHINCS+ is shown to have a practical vulnerability revealed through AI search?" If they cannot answer, reduce your exposure.