Atlas360
Technology

Researchers frame AI cryptography fears as an open question

OpenAI's math results do not establish a cryptography breakthrough, researchers said, leaving risks to digital security unresolved.

Jason Kwon
Researchers frame AI cryptography fears as an open question

OpenAI's math results do not establish a cryptography breakthrough, researchers said, leaving risks to digital security unresolved.

The distinction matters for institutions protecting financial transactions, medical information and personal communications, not just cryptocurrency holdings. In an October 10 newsletter, a16z crypto presented a discussion separating advances in mathematical reasoning from evidence that existing security methods have become vulnerable.

Dan Boneh, a professor at Stanford University and special research advisor at a16z crypto, said the published results included no cryptographic problems. Eddy Lazzarin, a general partner at a16z crypto, said they revealed neither a new vulnerability in elliptic curve cryptography nor reduced security for a particular cryptographic assumption.

Mathematical progress leaves security assumptions unresolved

The central issue is whether AI can discover efficient ways to solve problems that cryptographic systems assume are computationally difficult. Justin Thaler, a research partner at a16z crypto and associate professor of computer science at Georgetown University, said researchers generally believe efficient algorithms for those problems do not exist.

Greater intelligence would not remove that constraint, Thaler argued: “It cannot find the nonexistent algorithm.” That position is an assumption about the underlying mathematics, however, rather than a demonstrated guarantee that every deployed system is secure.

Boneh linked the difficulty of proving such assumptions to P versus NP, an unresolved computer science problem. He said the recent mathematical results did not approach resolving it, leaving cryptographers dependent on assumptions that researchers continue to test.

Those assessments come from a discussion organized by a16z crypto, with each of the quoted researchers holding an advisory, investment or research role there. They represent the participants' interpretation of the results, rather than an independent technical evaluation supplied alongside the newsletter.

Quantum preparations offer only partial protection

Lazzarin said preparations for quantum computing had already prompted safeguards against possible weaknesses in elliptic curve systems. In his assessment, some of that work would also be relevant if AI exposed vulnerabilities in the same methods.

Boneh cautioned that the overlap has limits: AI might also uncover weaknesses in designs intended to withstand quantum attacks. His warning describes a possible threat, not evidence that those replacement systems have been broken.

One response is cryptographic agility, the capacity to replace a security method when its reliability changes. Boneh pointed to internet connections combining elliptic curve and lattice-based techniques, describing arrangements in which the latter can preserve protection if the former fails.

AI testing could move before deployment

The researchers also described a defensive role for the technology. Boneh argued that automated attempts to defeat new designs could shorten the scrutiny needed to build confidence, while Thaler expressed optimism about using AI to identify implementation errors in complex systems.

For software developers, Boneh's proposed change is to bring that testing earlier, before products reach users rather than after deployment attracts outside examination. The newsletter supplied no measured detection rates or comparative testing results establishing how reliably models perform that task.

If AI makes testing more effective without defeating foundational assumptions, the participants' argument points toward better-reviewed software rather than a wholesale replacement of cryptography. If researchers instead demonstrate a practical attack, Boneh's emphasis on adaptable designs becomes more consequential; the unresolved issue is which methods would be affected and whether deployed systems could switch safely.

More stories

Latest news