DAVID vs. GOLIATH
We won't be David this time. We'll have to build him. Kerberus CTO Danor Cohen on why no defense that stands still survives a smarter AI opponent, and what crypto has to build now.

Everyone knows the story of David and Goliath. A shepherd boy with a sling kills a giant in bronze armor, and ever since, it has been the story we tell about the weak beating the strong.
I think we’ve been telling it wrong. And the mistake is about to matter, because we’re walking into the same story again, this time against AI, and this time we are not the boy with the sling.
As I write this, in early October 2026, the crypto world is arguing about exactly that. Justin Drake, a researcher at the Ethereum Foundation, told the industry to start planning for “bunker mode”: a controlled move of coins to addresses that have never signed anything, because AI-driven math might break the signatures behind Bitcoin and Ethereum wallets, in his words “in the worst case in months not years.” Vitalik Buterin said the risk should be taken seriously. Others called it silly. I’ve been following the debate closely, because it lands right where I work, on the defensive side of security, and I think every proposal in it so far shares the same blind spot. To explain what it is, I have to start with the story.
The illusion
Why does the underdog story work on us so well? Because deep inside, everyone carries a few basic truths about how things work. One plus one equals two. Things fall to the ground. Some basic, fundamental rules. And one of those rules is that the strong beat the weak, the same way 10 is always bigger than 5. So when a story shows us 5 beating 10, something in us lights up.
So how did David beat Goliath against all odds?
The simple answer is: he didn’t. Or at least, not against all odds. It was an illusion.
If David had challenged Goliath to arm wrestling, or to a high jump competition, and had still beaten a giant who was stronger and taller than him by a wide margin, that would have been against all odds.
What really happened is different. People back then believed that the stronger man always wins a fight against the smaller man, and they were simply wrong about it. David refused the king’s armor because he couldn’t move in it. He brought a sling, a weapon that works from a distance, against a man built for close combat, and the stone hit him in the forehead, the one place the armor didn’t cover. Speed, agility and a gap in the armor (no armor is perfect) did the work. For those who believe in God, God’s hand was on David’s side. But what’s sure is that it wasn’t a 5 beating a 10. It was a guy with 10 in agility beating another guy with 10 in power.
Keep that in mind. Everything that follows depends on it.
The mother of all powers
If I had to rank every kind of power available to us, intelligence would come out on top. The reason is simple. With enough intelligence, you’ll probably find a way to get the other powers, or to get around the advantage they give someone else over you.
In our lifetime, we’re watching another entity catch up with us in exactly that power, and in more and more areas pass us. And as expected, we’re facing our biggest challenge yet: how do we protect ourselves against it?
The honest truth
David could never have beaten Goliath in a height-measuring contest, simply because Goliath was taller. In the same way, I don’t see how we win an intelligence contest against the AI that is coming, AGI, ASI, whatever we end up calling it. It is going to be more intelligent than us, and by a big factor.
This is the part nobody likes to hear. In the story that is coming, we are not David.
The N+1 paradox
So here is the problem, and the paradox.
If what we’re dealing with is smarter than us, it’s simply impossible to come up with a solution it can’t break. Whatever defense we build is N. A smarter opponent, given some time, finds N+1.
Some people will say cryptography is the exception. The math doesn’t care how clever the attacker is, a hard problem is a hard problem, and being smarter doesn’t help with something that’s hard by nature. I’d answer that “hard” only ever meant that the best attack we knew of didn’t work. Every scheme that was ever broken was considered safe until the day someone found a better attack. Until now, that someone was always a human, and humans find better math slowly. In October 2026, OpenAI published more than 700 mathematical manuscripts produced by an internal model, about 42 percent of them with machine-checked proofs and the rest still waiting for review. Now that someone can be a machine, and machines are fast.
Which brings us back to the bunker mode debate.
Bunker mode
Crypto leaders are trying to figure out how to build defenses that will stop AI from breaking the most fundamental parts of crypto’s math. Drake’s bunker mode is the clearest example so far: a gradual move of funds to fresh addresses whose public keys have never been exposed, because AI-driven math could break the elliptic-curve signatures that protect Bitcoin and Ethereum wallets. He also wants Ethereum’s move to hash-based cryptography to go faster. Vitalik Buterin wrote that “we should take the risks to cryptography from AI-accelerated math seriously,” and that “there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.” Lattices are the main candidate to replace what we use today: NIST’s primary post-quantum signature standard is lattice-based, and the hash-based one is the backup. He also wrote, “I don’t recommend anyone scramble to move their funds to new wallets today.”
In my eyes, every one of these defenses falls into the same paradox. Hidden keys, hash-based signatures, post-quantum schemes, they are all just higher walls, and a wall is an N. The only reason anyone even thinks (not to say hopes) that a wall can hold for good is the stories. David and Goliath, and every movie that came after it. Something in our instincts tells us we can win, despite the obvious paradox. But as far as I see it, any defense that stands still will be bypassed by AI. I could be wrong about how soon. I don’t think I’m wrong about the direction.
So if walls don’t work, what does? The paradox itself gives the answer.
The good news
The good news is that we still have time. We woke up in time. The enemy is not at the gates yet, but he is already marching, and we need to act now.
Go back to the paradox for a second. It says a smarter opponent will always find the N+1. Fine. Then the only thing that can hold is something that finds the N+2 first. To beat an AI attack, the only possible solution is to put a stronger (more intelligent) AI in front, and to do it now. Then it doesn’t matter how fast or how incredible the progress of general AI turns out to be. All we need to worry about is that our defensive AI stays N+1 to the attacker’s AI. And luckily for us, this is not only possible for crypto, but also probable.
We can’t be David in this story. But we can build one.
Such an AI is already starting to exist, at least for the software side of the problem. In DARPA’s AI Cyber Challenge in 2025, autonomous systems found 54 of the vulnerabilities planted across 63 challenges and patched 43 of them, inside more than 54 million lines of code, at about $152 per task. Along the way they found 18 real bugs in open source software. Anthropic’s red team showed that today’s AI agents can exploit real smart contracts in simulation, and wrote that “the same agents capable of exploiting vulnerabilities can also be deployed to patch them.” The math side is harder, but the direction is the same. What’s missing is the decision to put this AI in front permanently, and to pay for it.
So what does it take to build one? Three things.
The three conditions
Condition A: Elastic infrastructure
The way I see it, any future crypto infrastructure will need to be almost fully agile and elastic, open to change at every level, from the base math to the mechanisms, everything. We need to move from the stable, well-known, slow-to-change model we have today to systems that can change their fundamentals and their security layers fast.
The industry already has a name for the first step. It’s called crypto agility, the ability to replace a cryptographic algorithm without breaking the system around it, and NIST published a whole paper on it at the end of 2025. What I’m describing goes further than swapping algorithms. It’s an infrastructure built to be rewritten.
I know how this sounds to people who love crypto for being immutable. A system that can change its fundamentals fast is also a system someone could change fast. That’s exactly why whatever guards those changes has to be smarter than whoever tries to abuse them, which is Condition B.
Condition B: A forever-running agent
The system must have AI fully integrated as a core function. AI that works around the clock, 24/7, trying to break the infrastructure, the math, everything, and presents the fixes. When it’s mature enough, it applies them instantly, with no human intervention. Humans set the limits, the AI makes the moves inside them.
The point is practice. The guard has to be attacking the system every day, against everything, long before a real attacker does.
Condition C: Funding
Better AI will probably need more resources, and whoever has the most resources (of any type) will end up with the most advanced AI. The cost of training a frontier model has been growing by roughly 2.4 times a year since 2016, and the largest training runs are heading past a billion dollars. If crypto wants the strongest AI running on its side, or at least one of the strongest, it has to fund it.
The good news is that if crypto becomes the world’s economic infrastructure, as I believe it will, then whoever runs the world’s money is, by definition, the one with the most capital. We’re not there yet. All of crypto today is worth around $3 trillion, against a global stock market of about $158 trillion and a bond market of about $161 trillion. But the funding mechanism already exists in miniature. Every transaction already pays a fee, and on Bitcoin that fee already pays the people who secure the network, the miners. If we apply a security fee, like the gas we pay today on every transaction, that fee could fund our AI guard.
Where this leaves us
We won’t out-think what’s coming. But we can still decide which side the smartest player in the game is on, and we can decide it now, while the enemy is still marching and not yet at the gates.
Written by:
As Head of Offensive Security at Salesforce, Danor led a 20-person team focused on discovering and preventing security breaches. His methodical approach to system penetration earned him recognition as a Top 10 PayPal bug hunter and a place in Dropbox's Hall of Fame. Now, he applies 15 years of security expertise to protecting Web3 users as CTO and co-founder of Kerberus.
- •CTO & Co-Founder of Kerberus
- •Former Head of Offensive Security at Salesforce
- •Top 10 PayPal bug hunter and Dropbox Hall of Fame
Related Articles
See more articles
Kerberus 2025 Review: Taking Real-Time Web3 Security Mainstream
Dec 31, 2025 • 4 minutes read

Scaling Solana Safely: Automated Defense for Programs, Authorities, and Wallets
Dec 10, 2025 • 4 minutes read

Human Errors Drive Most Web3 Losses Despite Billions Spent on Security, Kerberus Finds
Nov 17, 2025 • 4 minutes read

Report: The Human Factor – Real-Time Protection Is the Unsung Layer of Web3 Cybersecurity (2025)
Nov 17, 2025 • 4 minutes read
Install once & immediately get protected from scams, phishing and hacks. Zero losses for 250k+ users in 3 years. Now with up to $30,000 in coverage.