Vitalik Buterin Pushes Ethereum Plan to Slash Quantum-Safe Privacy Costs

Buterin wants EIP-8288 in I-star, the upgrade after Hegota, and adopting it would make RISC-V Ethereum's canonical instruction set.

By Decrypt Agent

3 min read

Ethereum co-founder Vitalik Buterin said on Wednesday that he hopes to see a proposal cutting the cost of quantum-safe private transactions by more than 99% included in a future network upgrade.

EIP-8288, which he co-authored in June, would move the heaviest cryptography out of the network's execution path. Post-quantum signatures currently run to 2 or 3 kilobytes and cost 150,000 to 200,000 gas to verify.

STARK proofs are worse, at over 128 kilobytes and as much as 512 kilobytes when generated quickly, which puts verification in the millions of gas. A well-engineered private transaction costs about 300,000 gas today, Buterin tweeted, and roughly 10 million if you want it quantum-safe. Under EIP-8288,  Buterin said, both would land in the low tens of thousands.

It works by not putting the cryptography on-chain at all. A transaction instead declares a "dependency"—a short claim that some message was signed by some key, or some data satisfies some proof—costing 96 bytes. Mempool nodes then collect those claims every second, generate a single recursive STARK proving all of them at once, and pass it on. The block carries one proof covering everything in it.

A decision about RISC-V

Recursive proofs need a common language to express statements in, and the leading candidate is RISC-V, an open instruction set used in chip design. Adopting the proposal would make it Ethereum's de facto canonical instruction set, which Buterin called a “big decision” that should be taken carefully, and one he thinks is necessary.

Myriad: ETH above 4K when Bitcoin goes above 100K? Click to make your prediction.

He floated the same move in July, in a Lean Ethereum roadmap that would rebuild almost every major protocol component over three or four years and enshrine recursive STARKs at the core.

Another use he sketched is private account abstraction: keeping an account's logic hidden on-chain, then changing ownership of every position and holding attached to it in a single transaction, without revealing which ones.

EIP-8288, which Buterin co-authored with Thomas Coratger, depends on Frames, the transaction overhaul he promoted on Sunday—which is itself unscheduled. He wants both in I-star, the upgrade after Hegota, which he has said will be Ethereum's last before the Lean era begins. Neither has been assigned to a fork.

 

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News