zkMesh+ Exclusive Clip – Benedikt Bünz on the threat of AI
Wednesday, 1 July 2026 · 1 min read · Listen to the episode ↗
Benedikt Bünz makes the case that AI represents a structural threat to cryptography, not just a tool for finding implementation bugs. He describes a recent instance in which using Gemini and OpenAI tools helped him identify an attack on a hash-to-elliptic-curve-point construction within roughly a day, a result later confirmed and improved by elliptic curve specialist Yusuf.
Benedikt Bünz argues that AI poses a threat to cryptography that extends well beyond finding implementation bugs, potentially reaching the level of breaking fundamental primitives such as lattice-based constructions or hash functions. He does not dismiss as impossible an AI-assisted discovery of a fast algorithm for discrete logarithms or a break of elliptic curves, describing such an outcome as shocking but not ruled out.
Bünz described a concrete recent case in which AI tools meaningfully accelerated the discovery of a vulnerability in a hash-to-elliptic-curve-point construction that had been presented at a cryptography conference. He used Gemini and OpenAI tools to analyze the suspicious construction, and within roughly a day of multitasking the AI produced an initial attack on it. An elliptic curve specialist named Yusuf independently confirmed the attack, substantially improved it, and identified an elegant fix. Bünz noted that he believes he would have reached the same result without AI given sufficient focused time, but the tools compressed the timeline in a meaningful way.
Bünz stated plainly that researchers who do not adopt AI tools will fall behind on research productivity. He went further, suggesting that at some point the human in the loop may no longer be necessary in cryptographic research, though he offered no firm timeline or certainty on when or whether that threshold is actually reached.
The episode frames AI not merely as a productivity aid but as a variable that could shift the threat landscape for cryptographic security itself. The combination of accelerated vulnerability discovery and the possibility of attacking foundational mathematical assumptions means the risk is structural, not just operational. Bünz treats this as a live concern rather than a distant hypothetical, even while acknowledging the uncertainty involved.
This summary was generated from the episode transcript and can contain mistakes.