Docs / Why Bunker Mode

Hide your keys behind a hash.
Calmly.

In October 2026, Ethereum researchers publicly asked the industry to start planning for "bunker mode": keeping funds in addresses whose public key has never been revealed. This page explains the idea in plain words, what is fact and what is a scenario, and how each Bunker Mode tool maps to it.

01 — The short version

  1. Your address is a hash of your public key. On Ethereum and on modern Bitcoin address types, the address alone does not reveal the public key.
  2. The first time you sign, the public key becomes public. Any signed transaction from the address (a send, an approve, a swap) reveals it on-chain, and some off-chain signatures can reveal it too.
  3. If the math behind ECDSA weakens, exposed keys are the first targets. An attacker needs the public key to try to recover the private key. A never-signed address gives them only a hash.
  4. Bunker mode = keep the bulk of your funds in addresses that have never signed, and after you do sign from one, move what's left to a fresh address. No new wallet or new cryptography is needed.
  5. Don't rush. A rushed migration (wrong address, poisoned address, bad multisig config) loses far more money today than any future attack. Plan, test, then move.

02 — Where this comes from

On 7–8 October 2026, two widely shared posts by Ethereum researchers laid out the argument. Below is our summary in our own words. Read the originals under Sources.

The scenario: ECDSA could break before quantum computers do

  • The worry: the elliptic-curve signatures that protect most wallets (ECDSA) might break before "q-day" (the day quantum computers can break them), in the worst case within months.
  • What "break" means here: recovering a private key from a public key in about a week, on hardware that exists today, such as a large GPU cluster.
  • Why now: AI-assisted mathematics has recently overturned long-held conjectures. Elliptic curves carry a lot of algebraic structure (the kind exploited by tricks like Schoof's algorithm, Frobenius maps and pairings). Hash functions are designed to have as little structure as possible.
  • A second route: an efficient quantum algorithm sometimes foreshadows an efficient classical one, so a classical counterpart to Shor's algorithm can't be ruled out.

Lattices are not automatically safe either

  • Many people assume "elliptic curves broken, hashes safe, lattices safe". The follow-up argued that lattice-based schemes (ML-DSA, FHE) are a new area of risk from AI-accelerated math.
  • The analogy: factoring naively takes about 2n/2 time. Decades of work (number field sieves) cut that to 2O(n1/3), which is why RSA keys are about 400 bytes instead of 64. Structured problems may hide similar shortcuts that AI finds first.
  • That is why Ethereum's lean roadmap has gone "hash-only" for signatures and proofs (WOTS, SPHINCS-style schemes): no lattices, no ML-DSA, no Falcon.
  • Public-key encryption can't be built from hashes alone, so where structure is unavoidable the suggestion is to use much larger keys (roughly 10×).

Multisigs and load-bearing signers

  • For multisigs, the ideal rule is that each signer changes their key after each operation.
  • Gather signatures off-chain where possible, to shorten the window between "signature revealed" and "key no longer active".
  • Load-bearing signers (oracles, L2 security councils) can rotate keys with every signed message and/or co-sign with a hash-based scheme such as SPHINCS+.

What is fact, and what is a scenario

  • Fact: a public key is revealed when an address signs. Never-signed addresses only show a hash.
  • Fact: no practical attack that recovers ECDSA private keys has been published.
  • Scenario: that ECDSA, or lattices, could be weakened soon by AI-driven or quantum methods. Serious researchers think it's worth preparing for. Nobody can promise when, or whether, it happens.
  • Our view: moving to fresh addresses is cheap hygiene if done carefully. Doing it in a panic is the bigger risk.

03 — From idea to action: the tools

Every Bunker Mode tool exists because of one line of the argument above.

"Keep funds in addresses that have never signed."
Bunker Check + Bunker Bot: SEALED or EXPOSED for every address you own, across 7 EVM chains plus Solana and Bitcoin, with a score and a migration plan.
"Exposure isn't only your own transactions."
Deep Scan: finds signatures revealed through gasless swaps, Safe co-signing and Snapshot votes, which basic nonce checks miss.
"When you do sign, move the rest to a new address."
Pre-Sign Check + Bunker Guard: warn you before a signature exposes a vault address.
"Don't rush. Rushed migrations lose funds."
Migration Safety pre-flight: fresh-address check, look-alike (address-poisoning) warning, type-to-confirm and a test send first.
"Multisig signers should change keys after each operation."
Safe Rotation Planner: shows which Safe owners are exposed and drafts a rotation to sealed signers.
"Exit the bunker with hash-based cryptography."
PQ Lab: a real SPHINCS+ signature verified by a contract on Ethereum mainnet, plus a curve vs lattice vs hash comparison.
"Don't tie your old and new addresses together."
Private Migration (opt-in page, via RAILGUN): reach a fresh address without linking it on-chain to the old one.
"Push for defensive acceleration."
$BUNKER: 1% of every trade in ETH goes to the treasury that funds independent audits.

04 — FAQ

Does receiving funds expose my address?

No. Receiving never reveals your public key. Only signing does.

Does an approve or a swap count as signing?

Yes. Any transaction sent from the address reveals its public key, whatever it does. So can some off-chain signatures (permits, gasless orders, votes). That's what Deep Scan looks for.

Is a new address from the same seed phrase OK?

Yes. Each derived address has its own key pair, so a new one starts sealed. Keep your seed phrase offline and never type it into any website, including this one.

Is my Solana address protected?

No. A Solana address is the public key, so there is no hash in front of it. Bunker Check always marks Solana addresses EXPOSED.

My address has nonce 0 on Ethereum. Am I safe?

Not necessarily. The same key controls the same address on every EVM chain, so a single transaction on Base or BNB Chain exposes it everywhere. Signatures used by others (for example a gasless swap) also expose it. Run a full check.

Should I move everything today?

No. Plan first: list your addresses, run the check, do a small test send to the fresh address, then move. Speed causes losses; calm doesn't.

Does Bunker Mode ever ask for my wallet or keys?

The checks never connect your wallet and never ask for a seed phrase or key. The only page that connects a wallet is the opt-in Private Migration page, which says so at the top.

05 — Glossary

Public key
The half of a key pair that others can see. Revealed when you sign.
Address
On Ethereum, the last 20 bytes of a hash of the public key.
SEALED / EXPOSED
Our labels: SEALED = public key not yet revealed; EXPOSED = it has been.
ECDSA
The elliptic-curve signature scheme behind most wallets.
q-day
The hypothetical day a quantum computer can break ECDSA.
Lattice cryptography
A family of "post-quantum" schemes (e.g. ML-DSA). Structured math, so possibly vulnerable to AI-found shortcuts.
Hash-based signature
Signatures built only from a hash function (WOTS, SPHINCS+). Big, but with minimal mathematical structure.

06 — Sources

The researchers who wrote these posts are not affiliated with Bunker Mode and do not endorse it or $BUNKER. The summaries above are ours. Read the originals for their exact words.