FULL STORY

AI vs. Public Key Crypto: From Warning to Walkback

Cryptographer Matthew Green sparked fears that AI could break public key cryptography, fueling wider anxiety as AI solved major math problems. He later clarified his warning targeted only standardized schemes, not the end of cryptography.

2026-10-08 ~ 2026-10-09 · 3 episodes · 21 posts

Episode 1 · Cryptographer Matthew Green warns AI could break public-key encryption (2026-10-08, 12 posts)

Renowned cryptographer Matthew Green offered a rare and sobering assessment in an October 8 discussion with kmad, Matthew Pines, and others: as LLM math reasoning capabilities surge, public-key cryptography could stop working. He clarified he mainly meant encryption itself, not the entire public-key cryptosystem.

Confirmed

  • Green confirmed that major AI labs do employ cryptanalysts and are not dismissive of the field, though he is unsure whether they have produced new cryptanalytic results.
  • He believes core mathematical problems such as module LWE, discrete logarithms (including ECDLP), and even RSA may lose enough of their security margin as attack methods improve.
  • He cautioned that if AI-assisted cryptographic breakthroughs do occur, they should be disclosed carefully — breaking LWE, ECDLP, and similar problems would have far-reaching consequences.
  • @burnytech, who summarized the discussion, stressed this is a warning about the long-term security of classical encryption.

Why it matters

  • Green asked: we already live in an era where machines outperform humans on long-unsolved math problems, so why be so confident humans have analyzed these problems exhaustively — he considers that confidence itself overconfident.
  • If AI truly accelerates attacks on these foundational problems, the public-key underpinnings of the internet, including TLS and encrypted communications, would need to migrate to post-quantum schemes. The warning sounds an early alarm for cryptographers and industry to prepare.

Episode 2 · AI Math Breakthroughs Raise Concerns Over Public-Key Cryptography (2026-10-08, 2 posts)

After AI systems solved several long-standing math problems, cryptographers including Matthew Green voiced concern that undisclosed novel attacks on public-key cryptography may already exist, urging close attention to guidance from DoD, NSA, and NIST.

Episode 3 · Cryptographer Matthew Green Clarifies "Public Key Crypto Is Broken" Panic: The Real Worry Is Standardized Schemes (2026-10-09, 7 posts)

After a casual tweet from cryptographer Matthew Green sparked widespread panic that "public-key encryption might be broken," he posted a series of follow-ups clarifying what he actually meant. He made it clear: this does not mean the end of cryptography, is not a descent into Minicrypt, and is absolutely no reason to abandon TLS, send Bitcoin seed phrases in plaintext, or switch to Telegram—encryption is good, keep using it.

Confirmed

  • Green stressed the original tweet was written quickly and offhand; he is not worried about public-key cryptography as a whole or the underlying principles of public-key encryption.
  • What actually worries him is standardized public-key encryption and some signature schemes, because nearly all of them rest on a handful of hard problems—currently mainly MLWE and ECDLP, supplemented by other lattice-related problems.
  • He explained that "losing public-key encryption" really means: new cryptanalysis results will soon emerge that significantly improve attacks on standardized schemes (e.g., 128-bit security levels).
  • A milder consequence: some schemes previously considered "good enough" at 128-bit security would no longer meet the bar, possibly offering only 96 or 108 bits of actual security.
  • He also suggested that the questions coming from frontier labs might have leaked some hints, and noted that human analysis is not the gold standard.

Why it matters

  • This sounds the alarm for re-evaluating standardized cryptographic schemes: the entire public-key ecosystem's single reliance on a few mathematical hard problems means one breakthrough could ripple across widely deployed protocols.
  • Green's clarification helps curb overreactions (like abandoning TLS or moving to insecure communication), while reminding the community to focus on diversity in post-quantum and lattice-based schemes.