AI could crack crypto’s defenses before quantum computers do, Buterin warns
Ethereum’s co-founder warns that AI-driven mathematical breakthroughs could undermine wallet security—and weaken even cryptography designed to withstand quantum attacks.

Spend less time finding cybersecurity news. Get more out of it.
Metacurity delivers the cybersecurity news, analysis, and insight that would take you hours—and sometimes days—to assemble yourself.
Every weekday, we sift through thousands of news articles, press releases, filings, court documents, and research reports, including details that vendor announcements and PR pitches leave out. We tell you what changed, why it matters, and what deserves your attention. Minimal vendor marketing. No outrage bait. No SEO filler.
A paid subscription gives you:
- The full Metacurity archive: Every newsletter, searchable and browsable.
- Our weekly long-reads roundup: The best cybersecurity writing from across the industry, selected and vetted to make your reading time count.
- Specialized reports and analysis: Periodic deep dives that go beyond the daily headlines.
- A direct role in sustaining independent journalism: Your subscription helps keep our editorial priorities focused on readers and the cybersecurity community.
If Metacurity saves you time, helps you spot an important development, or gives you a clearer understanding of the industry, please consider becoming a paid subscriber. Your support keeps that work going.
Subscribe today—and thank you for reading and supporting Metacurity.
Ethereum co-founder Vitalik Buterin has backed a new warning that advances in artificial intelligence could undermine the cryptography used in today’s blockchains before quantum computers do.
Buterin was responding to a post from Ethereum researcher Justin Drake urging the industry to prepare for “bunker mode,” as AI could eventually make it possible to break the elliptic curve digital signature algorithm (ECDSA) used to secure cryptocurrency wallets. Drake said users should begin a gradual migration of funds to fresh wallets where their public key is not exposed.
“I don’t recommend anyone scramble to move their funds to new wallets today,” Buterin wrote. “But we should take the risks to cryptography from AI-accelerated math seriously.”
Drake said his concerns came after OpenAI released hundreds of new mathematical findings across a variety of topics such as algebra, theoretical computer science and mathematical logic on Tuesday, revealing how quickly AI has been advancing in mathematics.
Last month the company used a team of 10,000 autonomous AI agents working in parallel to solve the Navier-Stokes equation, one of the most famous and difficult unsolved problems in mathematics and physics, in just 88 hours.
“Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen,” said Drake, adding that elliptic curves could be especially vulnerable to superintelligence.
“Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimize algebraic structure.)” he said.
Buterin, however, extended the concern to lattice-based cryptography, warning that systems believed to resist quantum attacks could also be weakened by AI-driven mathematical advances.
“So far most people have been in the mode of thinking ‘elliptic curves broken, hashes safe, lattices safe,’” he wrote. “But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.”
Buterin said this is a major reason why Ethereum’s lean roadmap has been going in the “hash-only” direction.
Dragonfly managing partner Haseeb Qureshi also supported taking precautions, describing Drake’s warning as “a very sober call.” (Felix Ng / Cointelegraph)
Related: Shtetl Optimized, Hacker News, r/accelerate, r/singularity, Lobsters, CoinDesk, Unchained, The Block, Blockchain.News, Bitcoin Insider, CoinGape, CryptoPotato, The Crypto Times
The FBI has moved to seize two websites accused of operating a disturbing online marketplace for stolen intimate images and videos, with investigators claiming the sites offered massive collections of explicit material obtained without victims' consent.
Federal authorities sought control of the domain names NudeLeaksTeens.com and NLTVIDS.com as part of an investigation into alleged cybercrime, nonconsensual intimate images, and the sexual exploitation of minors.
According to court documents, an FBI task force officer alleged there was probable cause to believe the domains were being used to facilitate multiple federal offenses.
Investigators said NudeLeaksTeens, referred to as NLT in the affidavit, had been operating since at least February 2024 and advertised hacked and stolen sexually explicit images and videos depicting young women and girls. The material was allegedly packaged into individual "albums" and larger "collections" that customers could purchase.
According to investigators, albums were typically labeled with a victim's first and last name and could include identifying information such as social media handles, dates of birth, phone numbers, and email addresses.
One collection allegedly advertised approximately 6,200 private nude files taken from hacked Snapchat, Instagram, TikTok, and Facebook accounts. Investigators said their review of that collection also uncovered child sexual abuse material involving an identified minor.
Another package allegedly included material involving 1,915 girls and totaled 172GB. Investigators were also able to follow the money.
The affidavit states NLT previously accepted payments through Coinbase Commerce. Records obtained during the investigation allegedly included customer information, including names, subscriber information, and details about the content purchased. (Ashlyn Walker / RADAR)
Related: Justice Department, CyberScoop
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020.
30-year-old Raheim Hamilton (also known online as "Sydney" and "ZeroAngel") owned and operated Empire Market from August 2017 until its abrupt shutdown in 2020 amid persistent extortion-based DDoS waves, which prompted exit-scam claims after users weren't given time to withdraw funds from their escrow accounts.
Between June 2016 and July 2017, Hamilton also sold on AlphaBay (a notorious dark web marketplace that shut down in 2017) under the "ZeroAngel" username.
Empire Market operated as a hidden service on the dark web accessible only via TOR browsers and was modeled and advertised as an AlphaBay clone.
Together with co-defendant Thomas Pavey (aka "Dopenugget"), who also pleaded guilty last year to a federal drug conspiracy charge, Hamilton facilitated more than 4 million transactions between vendors and buyers.
While the cybercrime market also sold counterfeit currency, stolen account credentials, computer hacking tools, and personally identifiable information, drug sales represented the most prevalent activity, totaling nearly $375 million over the site's lifespan with over 166,000 listings for controlled substances alone.
At its peak in August 2020, the marketplace had roughly 1.68 million unique registered users, including more than 5,000 vendors and nearly 360,000 buyers.
When he pleaded guilty in January, Hamilton admitted that Empire Market was designed to help users avoid law enforcement detection and launder money, as all transactions were conducted in cryptocurrency to maintain the users' anonymity. (Sergiu Gatlan / Bleeping Computer)
Related: Justice Department
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.
Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn.
He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud in connection with an alleged ransomware decryption scheme that prosecutors say ran from June 2018 to June 2023.
The US Attorney's Office told BleepingComputer that Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond.
According to the indictment, Pinhasi owned and operated MonsterCloud LLC, a Florida-based ransomware remediation company that advertised tools and decryption techniques for recovering encrypted data without paying cybercriminals.
Prosecutors allege that Pinhasi and his co-conspirators had no such proprietary decryption technology and instead contacted ransomware operators, paid them for decryption keys, and then used those keys to restore customers' files.
The indictment acknowledges that some MonsterCloud contracts disclosed that the company might communicate with or pay cybercriminals. However, those contracts allegedly stated that MonsterCloud would contact attackers only if it could not decrypt a customer's files by other means.
Prosecutors claim that dealing with cybercriminals was usually MonsterCloud’s first step in obtaining decryption keys and recovering files. (Lawrence Abrams / Bleeping Computer)
Related: Justice Department, Help Net Security, Jerusalem Post, The Register, The Stack
UK clothing giant Asos has told its customers that hackers are in possession of detailed profiles of potentially millions of the online store's users.
It issued the update after BBC News told the retailer it had been contacted by cyber criminals who said this week's breach went beyond the "basic contact details" Asos previously said might have been accessed.
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.
So too are the searches customers have made on the website. Terms like "reclaimed vintage", "glamorous wide fit" and "Asos petite" are visible in the data.
The risk to individuals is now higher, and customers are being warned about potential impersonation scams.
In its email to customers, Asos confirmed data profiles were taken but said no bank details or passwords were accessed.
"Please remain cautious of unexpected messages or calls claiming to be from Asos," it said. (Joe Tidy / BBC News)
Related: BBC News, Reuters, Bleeping Computer
A cyberattack on Arizona’s court system stole personal information for more than a million people and is believed to have started when a court employee clicked a malicious link in an email.
The Arizona Supreme Court said the information was copied for 1.3 million people with unpaid court fees, fines, and restitution payments for traffic and criminal violations dating back as far as 30 years.
Those leading the attack also took records of nearly 30,000 active and inactive orders of protection and 150,000 reports dating back to 2010 from a foster care board that makes recommendations in cases where parents are alleged to be unfit or unable to care for a child.
The court’s technology staff shut down the attack on a backup server about two hours after spotting it on Sept. 24. Since then, the court has notified those affected by the breach. (Associated Press)
Related: CyberInsider, Bloomberg Law, The Record, Security Week, KOLD, GovTech, Insurance Business, ABC15
DC Frontier Inc., a Tokyo-based subsidiary of SoftBank Group Corp., announced that a glitch occurred in its IDCF Cloud service for local governments and companies on the day, due to unauthorized access from a third party.
While the company did not disclose the clients of the service, many websites, including those of Ibaraki Prefecture, east of Tokyo, the Tokyo city of Kodaira, Tobu Zoo in Saitama Prefecture, north of Tokyo, and Jiji Press Ltd., became unable to be viewed or updated.
According to IDC Frontier, the failure occurred at around 3:40 a.m., as an automatic shutdown system was activated following a ransomware attack. The service network was blocked to prevent secondary damage and data leaks.
The company is developing an alternative environment while investigating the cyberattack in detail.
IDC Frontier offers cloud services in three independent regions in eastern Japan and one in western Japan. The glitch occurred in one of the three eastern regions. (JiJi Press)
Related: The Asahi Shimbun, Japan Wire by Kyodo News, SBS News
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn't properly disclosed ties to China.
The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024.
The complaint accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers' security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers.
The suit also claims TP-Link allegedly concealed facts about its "past and ongoing ties to the People's Republic of China," accuses it of having a supply chain that's reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence.
According to the states' attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China.
The complaint alleges that only 0.5 percent of components used at TP-Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China."
The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link's assurances about its supply chain's security.
The complaint cites 2025 testimony from former NSA cybersecurity director Rob Joyce that TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers is at least 60 percent. (Connor Jones / The Register)
Related: Nebraska.gov, How-To Geek, Ars Technica, Gameranx, Tom's Hardware
David J. Rush, a former CIA officer who the authorities say stashed hundreds of gold bars in his home, admitted in court to a far larger web of deception, including a $145 million scam involving luxury real estate and providing sensitive intelligence to a foreign government official.
The shocking details of the case were revealed in federal court in Alexandria, Va., where Rush pleaded guilty to a single count of wire fraud, which could earn him up to 20 years behind bars.
The new details of his crimes, however, far surpassed what had been previously known about the unusual case, even as they in some ways deepened the mystery of an episode at the heart of America’s intelligence community that has been cloaked in secrecy.
Those crimes included his admission in court that he had shared the identity of a human source with a foreign government, a grave violation of what is among the CIA's most highly protected secrets.
John Ratcliffe, the CIA director, said Rush had “abused his position and betrayed the public trust and should be held fully accountable for his actions.”
Rush, a 49-year-old former intelligence officer, was arrested in May after investigators found roughly 300 gold bars stashed in the basement of his Virginia home. US officials have previously said he created a fake classified program — one that only a few people were permitted to know about — that allowed him to accumulate the bars, worth more than $40 million.
In court on Tuesday, a federal prosecutor, Kevin Hakala, described far more sweeping and potentially consequential crimes beyond the gold bar scam. In all, the schemes totaled more than $193 million in fraud. (Devlin Barrett / The New York Times)
Related: Justice Department, ABC News, Fortune, NBC News, NPR, TechCrunch, The Guardian, Military.com, News Nation
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.
Hackers gain access to exposed endpoints by using previously leaked credentials, or logins obtained from infostealer logs, credential stuffing, and password spraying attacks.
They then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes.
According to the FBI, " the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates." Some groups benefiting from this are INC/Lynx ransomware and Payload ransomware.
The FBI warned that remediation may require more than patching and resetting Fortinet passwords, suggesting restricting external access, terminating all active VPN sessions, enforcing MFA, and reviewing logs for unauthorized changes and suspicious activity.
They also recommend enforcing PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline. (Bill Toulas / Bleeping Computer)
Related: IC3.gov, CyberScoop, The Register, Security Affairs, Cyber Security News, Infosecurity Magazine, Help Net Security
Researchers at Lumen Technologies’ Black Lotus Labs say malware called PoeLLM that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April.
The poem, which a threat actor wrote and posted on a GitHub repository, seems innocuous.
The poem, which a threat actor wrote and posted on a GitHub repository, seems innocuous, but it’s driving a stealthy piece of malware researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.
Researchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect affecting Ivanti’s secure mobile gateway product, Sentry. That discovery uncovered a sweeping exploit-scanning and cryptocurrency-mining botnet linked to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg and Gitea.
The malware contains functionality that can allow for remote code execution, potentially allowing a threat actor to abuse AI models on victim servers, along with public-facing services for downstream compromise. (Matt Kapko / CyberScoop)
Related: Lumen, The Register, Help Net Security, Shattered.io

Researchers at ESET report that a cyberespionage group that they track as UAC-0099 and is linked to Russia's military intelligence group called Sandworm has spent the past two years steadily refining a custom downloader used against Ukrainian organizations, researchers found.
The downloader tracked as Matchboil appears to have been in development since at least April 2024. Each new iteration is more sophisticated than the last.
Matchboil has affected various sectors in Ukraine, including multiple transportation companies, a manufacturer and an energy company.
Eset began investigating Matchboil in February after two samples uploaded to VirusTotal communicated with a domain previously attributed to the UAC-0099. The samples led researchers to additional variants dating back to previous years.
The malware obtains identifiers of the victim machine, such as CPU information and motherboard serial number stored in the firmware, to keep track of victims during command-and-control communication. Later versions collected additional details such as the username, MAC address, computer model, and manufacturer. (Tiffany Wang / Infosecurity Magazine)
Related: WeLiveSecurity, Help Net Security

Rest in Power: Margaret Hamilton
Margaret Hamilton, a profoundly influential computer scientist best known for leading the software engineering team at MIT’s Instrumentation Lab during NASA’s Apollo program, died on Sep. 30 at age 90.
A computing pioneer who authored over 130 publications, Hamilton helped to establish software engineering as a dedicated discipline. She worked at MIT from 1959 until the mid-1970s, after which she became a successful computing entrepreneur and CEO.
Her life’s work was recognized with many awards and honors, including the 2016 Presidential Medal of Freedom from President Barack Obama, whose citation noted: “Hamilton defined new forms of software engineering and helped launch an industry that would forever change human history. Her software architecture led to giant leaps for humankind, writing the code that helped America set foot on the moon.” (Janine Liberty / MIT News)
Related: BBC News, New York Times, ITPro, Agence France-Presse, The Sun, GB News, The Guardian, Wall Street Journal, People
Best Thing of the Day: Let's Hope the US Congress Is Not Entirely Worthless
The US Senate passed a healthcare cybersecurity bill that was introduced in the wake of the ransomware attack on Change Healthcare, which exposed the sensitive healthcare information of 190 million people.
Worst Thing of the Day: AI-Driven Cars
AI engineers at a startup called Axiom successfully used OpenAI’s GPT-6 Astra to navigate a vehicle up to the take-out window at an In-N-Out burger so they could collect their food.
Bonus Worst Thing of the Day: Co-Op's Dystopian Employee Tracking Turn
The UK's Co-op grocery chain has become the latest employer to place workers under AI surveillance with an automated listening technology that rates every phone call some of them make to customers.