“I think we might lose public key cryptography.” ~Matthew Green
The above is from Matthew Green, yesterday, who is a cryptographer at Johns Hopkins. OpenAI released over 700 mathematical proofs as a github repository yesterday. They’ve since withdrawn 3 of them.
The reaction from mathematicians has been frustration and some anger and sadness, and there’s much debate about the role of AI in math. I’d encourage you to read the first few messages on this Hacker News thread for context.
You can’t argue with outcomes, and the repository they released includes LEAN proofs that provide a very high degree of confidence in the logical validity of each proof. Some mathematicians are calling this “the most significant moment in mathematical history”.
Meanwhile we continue to work with Mythos and cyber capable OpenAI and Anthropic models at Wordfence, and this is giving us a first hand look at how models compare to our human capabilities. Wordfence Argus continues to find extremely severe vulnerabilities, many of which are making their way through the confidential disclosure process. And Wordfence PRISM continues to give us broad coverage across the plugin and theme ecosystem.
The Web is built on the assumption that some math problems are too hard to solve within a reasonable amount of time. Specifically, we have a system called public key cryptography that lets two strangers establish a secure channel of communication that someone else can’t listen in on, and the security of that channel relies on the assumption that the stranger can’t solve a hard math problem in less than several thousand years, given our current state of computational resources, and our current knowledge of math.
It’s that last bit that’s concerning. The current state of math just jumped forward by around 700 proofs in a day. A former OpenAI employee commented on X that 81% of all math discoveries in the past 3 years were released yesterday.
We’re entering a new uncertain era where the pace of innovation continues to accelerate to something our species has never seen before. The math solutions we’ve implemented have thus far been reliant on breakthroughs happening slower. For example, we’ve been working on quantum computing for some time and have expected it to make certain kinds of encryption vulnerable. And so we came up with a post-quantum algorithm called ML-KEM which is more resistant to quantum attacks. And we had time to do this.
With the pace of math innovation accelerating to unexpected levels, we may find ourselves in a situation where overnight the current cryptographic algorithms we use are vulnerable to attack and need to be replaced or upgraded. In the face of opposition from some mathematicians, if OpenAI doesn’t make math breakthroughs, Anthropic will, and if they don’t DeepSeek, Z.ai and other companies will. And the reality is that they are all working on math, and other hard problems, as a demonstration of capability to help sell their models.
Cybersecurity is built on math, and if public key encryption falls and we don’t have a replacement ready, the Web grinds to a halt. Your WooCommerce or Shopify store can’t do business because your customers can’t securely transact. Your business goes away, overnight, because credit card numbers and other payment tokens can no longer securely cross the network.
If AI can break cryptographic algorithms, then AI can develop new algorithms, just like humans did, that are more resistant to attack. We may also need to upgrade the rapidity with which we can patch which algorithms are used in applications, so that we’re able to rapidly deploy new validated cryptographic algorithms as they emerge. In other words, we need to adapt our infrastructure to accommodate the new much faster, and accelerating pace of innovation in math and computer science.
If you’re not a mathematician or AI engineer and are running a business on the Web, my suggestion would be to maintain situational awareness on developments in cybersecurity and how AI is impacting it, and get into a healthy daily routine of updating your software and systems as needed. As these problems are solved, it may simply be a case of updating. If a new way of doing things emerges, it may take a bit more effort.
The good news is that we’re all in this together. We run an ecommerce site here too, which relies on public key encryption, just like yours. If public key encryption falls overnight, the amount of energy, motivation, coordination and available resources to fix it is massive. At Wordfence we’ll certainly keep our customers apprised in real-time of developments and changes they need to make.
ADDENDUM:
“Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I’ve witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.”
Justin Drake (a bitcoin security researcher) on X suggesting that strong cryptographic algorithms may already have been broken or weakened, and we’re not hearing about it due to government censorship which has some precedent.
The post Cybersecurity Imperatives Will Demand AI Math appeared first on Wordfence.