Cryptographer Matthew Green: 15% Chance Public-Key Encryption Falls to AI
Green warns that AI's ability to find unexpected breaks is outpacing the standards process by orders of magnitude, and only advance preparation can cushion the shock.

Cryptographer Matthew Green: 15% Chance Public-Key Encryption Falls to AI
Cryptographer Matthew Green posted on a social platform on 2026-10-09 that he believes there is a 1% chance humanity lives in a "Minicrypt" world—where public-key encryption is mathematically impossible—and a further 15% chance that existing public-key encryption algorithms will lose trust at the functional level. The remarks were cited and summarized by Simon Willison in his blog newsletter.
Green points out that the core tension lies in the order-of-magnitude gap between the speed at which AI produces "surprises" and the speed at which humans replace cryptographic standards. Even with the most advanced AI assistance, the cycle for standards iteration remains far slower than the evolution of attack capabilities. He stresses that only by completing preparatory work in advance is it possible to recover from such sudden shocks.
Minicrypt is a hypothetical world proposed by cryptographer Russell Impagliazzo, in which public-key encryption cannot exist. Green has long worked in cryptography and security research; this statement is a personal judgment, not based on any specific disclosed attack results.
Source: https://simonwillison.net/2026/Oct/9/matthew-green/
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-10-10
- Last updated
- 2026-10-10
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

South Korea's President Confirms AI Role in Attacks on Seven Financial Firms: A Look at the Attack Chain

NVIDIA Open-Sources Agent Security Platform: Another Piece in the Agent Security Infrastructure, from Testing to Deployment

Robinhood Lets AI Agents Trade Without Per-Order Approval — and Clients Bear the Losses
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

