Subscribe Now
Trending News

Blog Post

THEY TOLD YOU YOUR COINS WERE SAFE. ROBINHOOD IS 100% EXPOSED, REVOLUT 99%, BINANCE 83% – AND THE FIX IS CALLED ‘BUNKER MODE’
News

THEY TOLD YOU YOUR COINS WERE SAFE. ROBINHOOD IS 100% EXPOSED, REVOLUT 99%, BINANCE 83% – AND THE FIX IS CALLED ‘BUNKER MODE’ 

An Ethereum researcher just told every Bitcoin holder on earth to move their coins. And the exchanges holding yours cannot follow that advice, even if they wanted to.

On Wednesday, Ethereum Foundation researcher Justin Drake posted a warning on X that has nothing to do with Ethereum and everything to do with the coins sitting in your exchange account.

He called it "bunker mode."

Move your Bitcoin. Slowly. Quietly. To addresses you have never spent from. Because in his worst-case scenario, AI does not need a quantum computer to work backward from your public key to your private key. It needs months, not years.

Here is the part nobody is putting in the headline. The custodians cannot do it.

The same day, Glassnode published numbers showing more than 6 million Bitcoin – 31.2% of every coin that exists – sitting behind public keys that are already visible onchain. Robinhood: 100% exposed. Revolut: 99%. Binance: 83%. Grayscale: 49%. Coinbase: 10%. Fidelity: about 2%.

The companies that tell you your coins are "safely stored" are running the worst address hygiene on the network. And the fix – moving to a fresh address – is free for you and structurally impossible for them.

Quick Summary

  • Ethereum researcher Justin Drake called on the blockchain industry Wednesday to plan for "bunker mode": a gradual move of funds to fresh addresses, warning AI could break the signatures guarding bitcoin and ether "in months, not years" in a worst-case scenario.
  • His concern is elliptic-curve cryptography, the math behind Bitcoin and Ethereum wallet signatures. Public keys are supposed to be a one-way street. Drake says the curves follow tidy patterns a powerful enough AI could learn to exploit, recovering private keys on ordinary computers – no quantum machine required.
  • No practical attack has been demonstrated, and none appeared in the research CoinDesk reviewed. This is a warning, not a breach. Treat it that way.
  • Glassnode: over 6 million BTC – 31.2% of circulating supply – sit behind public keys already visible onchain. That is up 222,000 BTC ($18.2 billion) since Glassnode’s May report, while total supply grew by only 64,000 BTC.
  • Exchanges accounted for 123,000 BTC of that increase and now hold 1.79 million BTC behind visible public keys.
  • Custodian exposure, per Glassnode: Robinhood 100%, Revolut 99%, Binance 83%, Grayscale 49%, Coinbase 10%, Fidelity roughly 2%. US, UK and El Salvador government holdings show no exposure under this methodology.

What Happened

Drake’s post landed Wednesday and asked the industry to "calmly start planning for bunker mode," urging large holders to begin moving funds to fresh addresses.

To understand why that is a big deal, you have to understand one thing about how Bitcoin works. A wallet uses a secret number – your private key – to authorize payments. A related public key lets the network check those approvals. Generating the public key from the private key is easy. Going backward, from the public key to the secret, is supposed to take an impractical amount of computing work.

Drake’s argument is that AI might find a shortcut through that wall. Not by brute force, and not with quantum hardware – by learning patterns in elliptic curves that humans have not found.

What triggered it: on Tuesday, OpenAI released 722 mathematical manuscripts produced by an unreleased model tested on roughly 4,000 research problems. Some findings came with computer-checkable proofs. The model is the same one OpenAI said had solved Navier-Stokes, one of the seven Millennium Prize problems. Within a day, an outside researcher re-ran the computer check on one result – a new limit on how fast computers can multiply large grids of numbers, a question mathematicians have chewed on since 1969 – and it held.

Drake’s point is that hash functions are built to scramble information with as little pattern as possible, while elliptic curves are tidy. Tidiness is what machine learning eats.

And AI-assisted attacks on crypto are not hypothetical anymore:

  • In December 2025, Anthropic researchers showed frontier models could write working exploits against simulated copies of real DeFi contracts.
  • In late July, a volunteer group called the Bitcoin Red Team used AI models to sweep 390 Bitcoin software projects in about 27 hours, logging nearly 5,000 possible flaws, 85 of them rated critical.
  • On July 30, an attacker began draining Coldcard hardware wallets through a five-year-old firmware bug, taking at least 1,367 BTC. Maker Coinkite said it suspected AI helped find the flaw.
  • Days later, BTCPay Server confirmed attackers had stolen funds from merchants’ Lightning nodes through a flaw first surfaced in an AI-assisted audit.
  • On August 27, Core Lightning’s developers issued an emergency warning after AI-generated bug reports turned up real vulnerabilities in their software.

Nobody has broken a Bitcoin key. But the pattern is clear: the tools that find the bugs are getting better faster than the tools that patch them.

Why This Matters for Bitcoin

The crypto press will read this story as "AI can steal your Bitcoin." That is not the story.

The story is address hygiene, and it has been sitting in plain sight for years.

Public keys become visible onchain in two main ways: address reuse, and certain output types – early pay-to-public-key outputs and Taproot. Once a public key is onchain, it is onchain forever. You cannot un-publish it.

This is why "never reuse an address" is not a fussy nerd rule. It is the single cheapest security upgrade available to any Bitcoin holder, and it costs nothing but a fresh address per transaction.

Which brings us back to the custodians.

A self-custody holder can move coins to a brand-new address tonight. A custodian cannot. Deposit addresses are public by design. Cold wallets are shared, reused, and audited by third parties. Exchanges added 123,000 BTC to the exposed pile in five months – not because they are reckless, but because the business model is a giant shared wallet.

So when you read "31.2% of all Bitcoin sits behind exposed public keys," you are mostly reading about custodial holdings, not about paranoid self-custody users rotating addresses.

The Love Is Bitcoin Takeaway

Watch what happens next. This warning is going to be repackaged within a week as an argument for trusting someone else with your coins. "AI is coming for your keys. Let a professional hold them."

That is backwards, and here is the proof.

The coins most exposed to this threat are the ones held by the institutions selling you safety. Robinhood’s exposure is 100%. Revolut’s is 99%. Binance’s is 83%. Those are not numbers that describe careful key management. Those are numbers that describe address reuse at industrial scale.

Meanwhile, the defense Drake is recommending – move to a fresh address you have never spent from – is exactly what self-custody is good at, and exactly what a custodian cannot do on your behalf.

We have been saying the same sentence for a decade: not your keys, not your coins. What is new is that the threat model just changed from "your exchange might blow up" to "your exchange’s public keys are already sitting on a public ledger with 100% of its coins behind them."

If that does not make you check where your Bitcoin actually lives, nothing will.

What Beginners Should Do Next

You do not need to panic. You do need to do four boring things.

  • Learn how Bitcoin wallets work, and specifically the difference between a public key, a private key and an address.
  • Stop reusing addresses. Every withdrawal to a fresh address costs you nothing.
  • If you have coins sitting in an old address that has already spent, sweep them to a new wallet you control. That is the entire "bunker mode" advice, minus the drama.
  • Understand custodial versus non-custodial wallets, and know which one you are actually using right now. If you cannot export a private key, you are not self-custodial.

FAQ

Can AI actually steal Bitcoin right now?
No attack on Bitcoin or Ethereum wallet keys has been demonstrated, and none appeared in the research reviewed by CoinDesk. Drake’s warning is a preparation call, not a report of a breach.

What is "bunker mode"?
Moving your coins gradually to fresh addresses that have never been used, so that no public key tied to your holdings has ever appeared onchain.

Why do exposed public keys matter?
Because if someone can derive your private key from a public key, they can spend your coins. Public keys become visible through address reuse and through certain output types such as early pay-to-public-key outputs and Taproot.

Does this affect Bitcoin the same way as Ethereum?
Both rely on elliptic-curve signatures. On Ethereum, any account that has ever sent a transaction has already revealed its public key. On Bitcoin, exposure depends on address reuse and output type.

How much Bitcoin is exposed?
More than 6 million BTC, or 31.2% of circulating supply, according to Glassnode. That is up 222,000 BTC since May 2026.

Which custodians have the highest exposure?
Per Glassnode’s methodology: Robinhood 100%, Revolut 99%, Binance 83%, Grayscale 49%, Coinbase 10%, Fidelity about 2%.

Can an exchange fix this for me?
Not on an individual basis. Deposit addresses are public by design and exchange cold wallets are shared. Address rotation is a self-custody advantage.

Is this a quantum computing story?
Partly. Drake’s argument is that AI may find a mathematical shortcut that arrives before quantum computers do – which would compress the timeline everyone has been planning around.

Is this financial advice?
No. This article is for education only.

Final Thoughts

The uncomfortable part of this story is not the AI. It is the asymmetry.

A researcher says "move your coins to fresh addresses." You can do that this afternoon for the cost of a transaction fee. Robinhood, sitting at 100% exposure, cannot do it for its customers at all. Neither can Revolut at 99%, or Binance at 83%.

The safest thing you own is also the only thing you can actually protect.

Coupon: LOVEISBITCOIN
https://loveisbitcoin.com/bull

So here is the question. If the institutions holding billions in Bitcoin are the most exposed players on the network, and the fix is something only you can do for yourself – why are you still paying them to hold your coins?

Sources: CoinDesk (Justin Drake "bunker mode" coverage, October 8, 2026), Glassnode exposed-supply data via CoinDesk, OpenAI’s released mathematical manuscripts.

This article is for education only and is not financial advice.

Previous

THEY TOLD YOU YOUR COINS WERE SAFE. ROBINHOOD IS 100% EXPOSED, REVOLUT 99%, BINANCE 83% - AND THE FIX IS CALLED 'BUNKER MODE'

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal