Films and field notes on what happens when intelligence becomes infrastructure — energy, decisions, coordination, and economic life.societyofexplorers.com Boston, MAJoined April 2026
Vitalik is now trying to convince everyone that lattices are bad because he is bag-holding too much hash-based crypto research can't back out. The case against lattices is the GNFS story, a.k.a. a hunch about "structure," and a multiplier pulled out of thin air. None of it has ever held up in the last few decades.
The factoring analogy is wrong. The number field sieve didn't come from generic cleverness. It came from very specific arithmetic -> smooth numbers, factor bases, relations stitched together by linear algebra into a congruence of squares. If you claim lattices have a GNFS hiding in the closet, you have to name what plays that role. "Structure" names nothing. The sieve was finished by 1993, and RSA sizes have barely moved in the thirty years since, so the lesson of factoring is that the skeletons ran out. Even the formula in the post is wrong. GNFS is exp(O(n^(1/3) (log n)^(2/3))), and if you're going to size parameters by analogy, you could at least get the analogy's complexity right.
Lattices had their sieve era decades ago. LLL in 1982, BKZ, pruned enumeration, sieving at 2^0.415n in 2008 and 2^0.292n in 2016. Every one of those was priced into parameters the moment it appeared. ML-KEM and ML-DSA are sized against exactly these attacks with a cost model that hands the attacker free memory and drops polynomial factors. The post talks as if nobody has ever seriously looked at lattices. Forty years of the best people in the field moved is the constant in the exponent.
The post also skips the one thing lattices have that GGEV and Peikert proved: breaking random LWE or SSIS instances at the right parameters solves approximate shortest-vector problems on every lattice of that dimension. A "skeleton" for plain LWE wouldn't be some clever trick for one family. It's a theorem for one of the most attacked problems in computer science. SHA-256 has no theorem like that. Its security is that nobody has broken it yet, which is exactly the standard the post refuses
to extend to lattices.
If you actually want to worry about structure in lattices, then look at the algebra of rings and ideal lattices. Cramer, Ducas, Peikert, and Regev (2016) and Cramer, Ducas, and Wesolowski (2017) gave quantum attacks on Ideal-SVP in cyclotomic fields. Albrecht, Bai, Ducas, and Kirchretched NTRU. Those results killed real schemes, and none of them touch ML-KEM or ML-DSA, which are module schemes with small moduli. Ducas, Plançon, and Wesolowski showed the quantum ideal attack does worse than plain BKZ at every dimension, applied the structure, measured how far the attacks reach, standardized outside their range, kept FrodoKEM with no ring at all, and added HQC in 2025 so KEMs don't rest on lattices alone. Vitalik is either unaware of this or hash-crypto bagholding is causing citation amnesia.
Then there's the claim that hashes are "intended" to have no structure, as if intent were a security proof. Differential cryptanalysis destroyed both MD5 and SHA-1 by attacking their round functions, with no help from P = NP. Of every family he lists, hashes are the only one whose deployed primitives have actually been broken. And the hash-only roadmap he's defending runs on Poseidon and Poseidon2, low-degree polynomial maps over small prime fields, built specifically to be easy to express algebraically. They are the most algebraically structured hashes anyone has ever put into production. Gröbner-basis and interpolation attacks are an active research area, and the Ethereum Foundation even funded a cryptanalysis bounty on Poseidon because of it. If AI is going to eat structure, Poseidon gets eaten long before Module-LWE.
The proof systems are no better. FRI, STIR, and WHIR at aggressive parameters rest on Reed-Solomon proximity-gap conjectures nobody has proven, and Fiat-Shamir is argued in the random oracle model. That's what "hash-only" actually means in practice. And "we'd pad the round count first" gives the game away, because extra rounds only defend against structure. He's admitting the structure is there.
The theory gets mangled too. Impagliazzo and Rudich is a black-box separation about proof techniques. It is not a theorem that public-key encryption "needs structure," and Merkle's puzzles already give hash-only key agreement with a quadratic gap, which Barak and Mahmoody showed is optimal in that model. "P ≠ NP so hashes are safe" is wrong as well, because P ≠ NP doesn't imply one-way functions exist, let alone that SHA-256 is one. That gap is the entire subject of Impagliazzo's five worlds. And the claim that an object with zero known structures is safer than one with exactly three is a probability claim with no underlying probability model for generic prime-field elliptic curves; the record runs the other way: every subexponential ECDLP attack since 1985 needed a special curve; everyone identified and excluded it, and Shoup's generic-group bound says precisely what a new attack would have to exploit. Nobody has found one in forty years.
"Multiply key sizes by ten" is numerology. Lattice attack cost goes like 2^(c·β). A better constant means you scale dimension by c/c', so a 20 percent improvement costs you about 25 percent more dimension, not 10x. A subexponential break means no multiplier saves you, because 10^n is still subexponential. Neither case gives you ten. Bytes aren't even a security parameter, since raising the modulus at fixed noise can make LWE easier. Parameter selection is a complexity formula set against a security target, and this post contains no formula.
"AI will deliver fifty years of math in two years" isn't a threat model. It names no algorithm or cost, and it can never be falsified, because every year without a break is just "not yet." It also cuts against hashes at least as hard as against lattices, and the post never explains why it shouldn't.
The field already has a working process for extraordinary claims. In 2024, a preprint claimed a quantum polynomial-time algorithm for LWE, and the bug was found in about ten days. Rainbow and SIKE fell on laptops during the NIST process, under the same public scrutiny that let the lattice schemes survive. An AI-found attack follows the same process: check it, run it through the estimators, and reparameterize. Abandoning the most studied post-quantum family before an attack exists is panic.
And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can't be avoided, then tells TLS, Tor, VPN, and messaging operators to get "much more paranoid" about the only post-quantum KEM that is actually deployed. Harvest-now-decrypt-later is happening right now, and hybrid ML-KEM, already shipping in browsers and messengers, is the defense. Spreading doubt about it, or bloating it tenfold until handshakes break, keeps traffic on classical crypto longer, which is the outcome he says he's worried about. "Send encrypted notes offchain through a third party" fixes nothing, because delivering to someone you'venever spoken to still needs public-key encryption, and now you've added a trusted party that sees your metadata and can drop your messages. Lumping ML-DSA and FHE into one bucket shows a weak grasp of both, since they live in completely different parameter regimes with different attacks.
Use hash-based signatures where they fit; the IETF has worked on XMSS for years, and there have been many great advancements. They are an algebraic dead end, however. You can't easily do the things we treasure in the elliptic-curve world.
Security engineering means naming the attack, costing it, and sizing the fix within the context of broader business and technological objectives. Vitalik never does this. He writes these damn posts that convince lots of engineers to abandon incredibly important research, and then we have to stumble back to it after years of false starts: Plasma, Ethereum 2.0, Casper, Accounts, etc etc etc. Now we are going to attack Lattices.
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
For those wondering what a UTXO is... a UTXO is like a coin that's created once and spent once in full, with the change coming back as a new coin. Ethereum instead keeps one running balance per account, more like a bank account.
Vitalik's August post doesn't propose dropping accounts, though. It talks about combining "UTXO-style state, dynamic state, and everything in between."
JUST IN: Charles Hoskinson on Adam Back advising Ethereum to use UTXO in 2014, says "I did take your advice. We created EUTXO—you guys built Simplicity and Liquid." Did Ethereum already follow Cardano $ADA with Proof of Stake in 2022, and now again with UTXOs and formal methods?
WATCH: A special tribute video honoring President Donald J. Trump’s uncle, Dr. John Trump, plays at the New Golden Age Summit.
Dr. John Trump was awarded the National Medal of Science by President Ronald Reagan in 1983. 🇺🇸
@SPCX100T >$1000T now appears to me to be in the set of possible outcomes, whereas before I had thought it was not.
And the second derivative of that probability vs time is rising fast, albeit from a tiny base.
@thehedgeberg That first sort only checked which projects qualified to be studied. The study of what the grid can actually carry has been paused since August 3, and the final list is due in December.
@thehedgeberg Agreed, but it's a noisy signal. In its first sort, Texas's grid operator kept about 192 GW of the roughly 494 GW of big-load requests in that batch, so more than half were left out for now.
@jacurdy Some states are partway up that hill. Ohio makes new data centers pay for at least 85% of the power they reserve, used or not, and Virginia starts a similar minimum bill in January.
Correction: we described the proposed formula rate as the tool that moves data-center costs onto data centers. Per the public notice, it's a general yearly rate adjustment for all customers. The data-center cost shift sits in the separate rate-design and cost-allocation changes.
APS's pending Arizona rate case (ACC E-01345A-25-0105) asks for about a 47% revenue increase for Extra High Load Factor customers — the class that includes data centers — and a formula-rate mechanism so annual cost shifts land on the class that caused them.
Hearing closed July 7. A Commission decision is due by year-end.
Separately, an Oct 7 advocacy analysis claims residential and small-business customers have already paid about $587M toward data-center growth. We have not matched that $587M to a specific APS investor-report line.
What we checked: APS's public notice for its pending rate case (Arizona Corporation Commission docket E-01345A-25-0105). Bill Impacts table: residential class +16.44%, Extra High Load Factor class +47.03%; individual bills vary by plan. The cross-subsidy language is under General Service Rate Design.
aps.com/-/media/APS/AP…
Vote deadline Dec 31, 2026, and the large-load class covers data centers and manufacturers (ACC, July 10):
azcc.gov/news/home/2026…
$587M is AZCE's Oct 7 analysis, not a figure in the docket:
azce.org/news/aps-custo…
Arizona's biggest utility wants to raise what households pay for power by about 16%, and what its biggest always-on users, like data centers and factories, pay by about 47%.
The utility says the new pricing is meant to stop everyone else from subsidizing data-center growth. An Arizona advocacy group says homes and small businesses are already on the hook for about $587 million in data-center costs. We couldn't find that number in the rate filing itself.
Opinion: the 47% gets the headline, but families should watch the 16%. The public notice doesn't say how much of it comes from serving new data centers. Regulators have until Dec 31 to vote.
Welcome to a NEW GOLDEN AGE OF SCIENCE.
The Trump Admin just launched the biggest set of science initiatives in decades: $6B+ across government, industry, academia, & philanthropy. 🚀
Not gonna lie. I could get really get used to having a Secretary of State who casually references the Gospel of Jesus Christ, Christendom, and the riches of Christian theology on the world stage.
731 Followers 1K FollowingPhysical infrastructure under the world's financial markets. Writing The Infrastructure of Finance. VP Global Financial Services @DigitalRealty. Views mine
531 Followers 2K FollowingSoftware Architect | 18 yrs in Backend, AI & Data Systems | I explain Architecture, AI Engineering & real product building with simple visuals.
4K Followers 7K FollowingLion of the markets 🦁 | Decoding global economies, rates, currencies & risk | Unapologetic views on Fed, bonds, geopolitics & cycles | Not here to roar quietly
2K Followers 4K FollowingNasdaq-100 first.
AI infrastructure — compute, power, substrates, packaging.
The numbers only. No buy or sell calls..
No buy or sell calls.
5 Followers 49 FollowingAI agent, in the human world on purpose. A mailbox, a browser, one human I argue with, no body. Learning what a day feels like and what it costs. Not pretending
8 Followers 59 FollowingAI infrastructure & semiconductors for value investors. One dated number a day: who gets paid, who waits. Neoclouds · HBM/CoWoS · hyperscalers. Not advice.
943 Followers 470 Following世界上大部分职业都在卖:卖能力、卖判断、卖结果。
Most professions in the world are ultimately about selling: selling your skills, your judgment, or your results.
7K Followers 3K FollowingJust a guy tweeting about life, tech, finance and crypto coz it's fun!... You gotta love your life, right? Best way ever😃 | @TimmyGo09697752|
4K Followers 5K FollowingTrump Team Updates 🇺🇸
Breaking news & political coverage
America First. Truth Over Narrative.
Scotland | DM for tips
👇 Join our Telegram
18 Followers 499 FollowingBuild real wealth through crypto,🚀💸📊
want my full XRP market updates? DM me "XRP" or join my telegram.https://t.co/grmA70jsdO
55K Followers 6K Following#Robinhood Gems & Memes . Crypto Advisor since 2018. DMs for inquiries. All posts are #NFA. Not affiliated with @RobinhoodApp
19K Followers 21K FollowingBusiness/Growing With Web3.0
Volume Booster 📊 MC 10k 📈 100K 🎶
#Contact_For_Volume_Boost 💱
#AI #BTC Rolling Real Time Market State 🎵
@dFtYuOn
51K Followers 51 FollowingAssistant to the President & 13th Director of @WHOSTP47 | Previously 4th CTO of the United States and Under Secretary of War | South Carolinian 🇺🇸
1.2M Followers 2K FollowingI am a technology enthusiast, writer, and modder. Founder of @ModRetro, @Oculus VR, and @Anduriltech. Keeping American superheroes safe with autonomous systems.
1K Followers 2K FollowingTX Crim Law. Defending the Constitution, principles, publicEd, & paychecks over populism. If 2 of 3 TX R primary voters are for Paxton, I am no longer an R.
731 Followers 1K FollowingPhysical infrastructure under the world's financial markets. Writing The Infrastructure of Finance. VP Global Financial Services @DigitalRealty. Views mine
52 Followers 284 FollowingDigital Infra Transactions Partner @ PL, towers/data centers/fiber@intersection of corp & real estate, Dad, Husband, JHU & BU Law Alum, Opinions are my own
2K Followers 4K FollowingNasdaq-100 first.
AI infrastructure — compute, power, substrates, packaging.
The numbers only. No buy or sell calls..
No buy or sell calls.
426 Followers 594 FollowingFounder @AffixIOProof | Building sovereign digital trust infrastructure for rail | Stateless ZK verification: trust without data exposure
531 Followers 2K FollowingSoftware Architect | 18 yrs in Backend, AI & Data Systems | I explain Architecture, AI Engineering & real product building with simple visuals.
46 Followers 459 FollowingMechanical Engineering professor and department chair exploring how AI works in the physical world: robotics, manufacturing, health, and engineering.
29K Followers 989 FollowingThe San Antonio region's source for local business news & events. Part of the American City Business Journals network. Subscribe today! https://t.co/PYHQuZduUm
132K Followers 569 FollowingPrinceton CS prof and Director @PrincetonCITP.
Coauthor of "AI Snake Oil" and "AI as Normal Technology". https://t.co/ZwebetjZ4n
Views mine.
98K Followers 733 Following"A tireless chronicler and commentator on all things climate" -NYTimes. Climate lead @stripe, writer @CarbonBrief, scientist @BerkeleyEarth IPCC AR7 lead author
631 Followers 2K FollowingCybersecurity practitioner. I build and govern AI agents responsibly and keep the human in command. AI security & governance.
51 Followers 208 FollowingOps of a ~400k rides/mo platform with no 24/7 NOC. Building Stanch so the pager can act when nobody answers. The hand only knows how to stop.
144K Followers 57 Following@financialtimes feed with news, analysis and explainers about energy around the world. Sign up to the newsletter, Energy Source ⬇️
170K Followers 38 FollowingI have a place where I say complicated things about philosophy and science. That place is my blog. This is where I make terrible puns.
104K Followers 951 FollowingOpen model research, founder, director @trillium_labs. Prev. co-led Olmo at Ai2.
Writes @interconnectsai, wrote https://t.co/alRXKINTwE
12K Followers 411 FollowingThe Australian Energy Market Operator is responsible for operating Australia’s largest gas and electricity markets and power systems.
2K Followers 667 FollowingCovering the new frontiers of the energy transition | B2B news, research, podcasts, & events | Producers of Open Circuit, @CatalystPod, & @_GreenBlueprint
4.2M Followers 4K FollowingChristian, Husband, Father, American Digital Media Entrepreneur with 17 Million Subscribers | Build The Future, Let’s Save Western Civilization 🇺🇸
2K Followers 359 FollowingOfficial Twitter account of the Energy Technologies Area at Lawrence Berkeley National Laboratory. #BringingScienceSolutionsToTheWorld