Short answer: No, AI cannot currently break Bitcoin's cryptography. Ethereum co-founder Vitalik Buterin rejected a claim on September 7, 2026 that AI could cut Bitcoin's value in half within two years by weakening SHA-256 hashing or proof-of-work security, calling the odds "extremely low" — he says roughly 90% of his own net worth is effectively positioned against that scenario. But the debate around it points to a real, separate problem: AI is already being used to make crypto scams, phishing, and smart contract exploits faster and harder to spot.
The exchange itself is a good stress test for how crypto investors should think about "AI risk." On one side, angel investor Liron Shapira put a 50% probability on Bitcoin losing more than half its value within two years, tying the forecast to AI advances undermining network security. Buterin, who understands cryptographic security about as well as anyone in the industry, called the premise unlikely and pointed out that even successful attacks at the network layer could largely be handled through software updates rather than the kind of broad social consensus a full protocol rewrite would need. That is the FUD version of AI risk. The real version is quieter and already costing people money.
What Buterin Actually Said
Buterin's response, reported September 7, 2026, addressed a specific claim: that AI progress could compromise the cryptographic primitives Bitcoin depends on — SHA-256 hashing and elliptic-curve digital signatures — badly enough to crater the asset's price. He rejected that outcome as highly improbable and noted that Bitcoin can absorb network-layer attacks through targeted fixes, without requiring the kind of contentious, chain-wide coordination that a deeper cryptographic failure would demand.
This is a narrow, testable technical claim, not a general statement that "AI is safe for crypto." Breaking SHA-256 or elliptic-curve cryptography with current or near-future AI would require a fundamental leap in either classical computing or practical quantum computing — neither of which current AI systems provide a path to on their own. Conflating "AI is getting more capable" with "AI can break 256-bit hash functions" is the exact error Buterin was correcting.
The Risk That's Already Real: AI-Accelerated Social Engineering
While the cryptographic doom scenario stays theoretical, three AI-enabled attack patterns are already operating against crypto users today.
Deepfake and voice-clone impersonation
AI voice cloning and video generation tools have made it cheap to impersonate founders, exchange support staff, or even people a victim knows personally, asking them to move funds or share a seed phrase. This does not require breaking any cryptography — it targets the human decision at the wallet, which is always the weakest link in an otherwise secure system.
AI-written phishing at scale
Large language models let scammers generate convincing, personalized phishing messages and fake project communications in volume and in multiple languages, with none of the grammar mistakes that used to be an easy tell. This directly compounds the presale and IDO scam patterns we already track — see our crypto presale scam checklist for the red flags that still apply, AI-generated pitch or not.
Faster smart contract exploit discovery
AI code analysis tools can scan open-source and even unverified contract bytecode for known vulnerability patterns faster than manual review, and attackers use the same tools defenders do. This raises the bar for how quickly a launchpad or project needs to have its contracts audited before funds are exposed — a gap we cover in how DEX analytics and credit modeling secure your next IDO.
Why the Distinction Matters for Your Decisions
Treating "AI could break Bitcoin's cryptography" and "AI makes scams more convincing" as the same risk leads to two mistakes in opposite directions. Overweighting the cryptographic doom scenario can push someone to panic-sell a core holding based on a probability Buterin — someone with direct expertise and direct financial exposure — considers extremely low. Underweighting the social-engineering risk does the opposite: it leaves people confident that "the blockchain is secure" while ignoring that the actual attack surface is their own inbox, DMs, and browser extensions.
Neither of these is new in kind. What changed is speed and scale. A scam that used to take a team days to localize and personalize can now be generated in minutes, in a dozen languages, with a cloned voice attached. The defense against that is the same discipline it always was, applied more consistently: verify identity out of band, never approve a transaction because a video or voice call sounded convincing, and treat urgency itself as a red flag.
Applying This to a Practical Checklist
- Never move funds or share credentials based on a call, video, or DM alone — verify through a separate, previously known channel, regardless of how convincing the voice or face looks.
- Assume phishing content will be well-written — the days of "bad grammar = scam" as a filter are over. Judge based on the request, not the writing quality.
- Check audit status before funding, not after launch — AI has sped up exploit discovery on both the attacker and defender side; an unaudited or recently-audited-only-once contract carries more risk in 2026 than it did a few years ago.
- Separate technical risk from narrative risk — before reacting to a claim like "AI could crash Bitcoin," check whether it is a specific, testable technical mechanism or a probability estimate from someone without domain expertise in the relevant cryptography.
- Keep position sizing rules set before you're under pressure — the same volatility-management discipline applies whether the trigger is a real exploit or a viral AI-doom headline. Our guide to staying calm during extreme crypto volatility covers the mechanics of not reacting on impulse.
One limitation worth being upfront about: this is not an exhaustive AI-risk audit, and cryptographic assumptions are not permanently fixed — sufficiently mature quantum computing remains a longer-horizon threat to current signature schemes, separate from anything AI language or reasoning models can do today. Buterin's comments addressed the near-term AI-driven scenario specifically, not the multi-decade quantum question, and the two should not be blended together either.
Frequently Asked Questions
Can AI actually break Bitcoin's encryption?
Not with current technology. Bitcoin relies on SHA-256 hashing and elliptic-curve signatures, and breaking either at scale would require a fundamental leap in classical or quantum computing that current AI systems do not provide a path to. Vitalik Buterin called the probability of AI compromising this security "extremely low" in comments reported September 7, 2026.
Why did Vitalik Buterin respond to this specific claim?
Angel investor Liron Shapira put a 50% probability on Bitcoin losing more than half its value within two years, attributing the risk to AI potentially undermining proof-of-work security. Buterin rejected the premise, noting that network-layer attacks could largely be addressed through software updates rather than a full protocol overhaul, and stated that around 90% of his net worth is effectively positioned against the crash scenario.
What AI-related crypto risks are actually real right now?
AI-generated phishing content, deepfake voice and video impersonation of founders or support staff, and faster automated discovery of smart contract vulnerabilities. None of these require breaking cryptography — they target human judgment and code-level bugs, which is why security practices matter more than ever even though the blockchain layer itself remains sound.
Does this mean quantum computing is also not a threat to Bitcoin?
Quantum computing is a separate, longer-horizon question from the AI-language-model risk Buterin addressed. Sufficiently advanced quantum computers could theoretically threaten current elliptic-curve signature schemes, but that is a different technology track with a different timeline, and it should not be conflated with the AI-cracks-SHA-256 claim.
How should investors adjust their security habits because of AI?
Verify high-stakes requests through a separate, previously trusted channel instead of trusting a call or video alone, stop using writing quality as a scam filter, check a project's audit status before funding rather than after launch, and keep predefined position-sizing rules so a viral AI-risk headline doesn't trigger an impulsive decision.

