Ethereum co-founder Vitalik Buterin wants a proposal that cuts the cost of quantum-safe private transactions by more than 99% included in a future network upgrade. EIP-8288 would move the heaviest cryptography off-chain by bundling proofs from an entire block into a single recursive STARK.
Vitalik Buterin said on Wednesday that he hopes to see a proposal cutting the cost of quantum-safe private transactions by more than 99% included in a future network upgrade. The plan, EIP-8288, would move the heaviest cryptography out of Ethereum's execution path.
Gas costs would fall from millions to tens of thousands
Post-quantum signatures currently run 2 to 3 kilobytes and cost 150,000 to 200,000 gas to verify. STARK proofs are heavier still, reaching over 128 kilobytes and as much as 512 kilobytes when generated quickly, pushing verification into the millions of gas.
Buterin tweeted that a well-engineered private transaction costs about 300,000 gas today, and roughly 10 million if made quantum-safe. Under EIP-8288, he said, both figures would land in the low tens of thousands.
The proposal works by keeping cryptography off-chain altogether. A transaction instead declares a "dependency" — a short claim that a message was signed by a key, or that data satisfies a proof — costing 96 bytes. Mempool nodes collect those claims every second, generate a single recursive STARK proving all of them at once, and pass it on, so each block carries one proof covering everything inside it.
A decision on RISC-V looms
Recursive proofs need a common language to express statements in, and the leading candidate is RISC-V, an open instruction set used in chip design. Adopting the proposal would make it Ethereum's de facto canonical instruction set, which Buterin called a big decision that should be taken carefully, though one he thinks is necessary.
He floated the same move in July, in a Lean Ethereum roadmap that would rebuild almost every major protocol component over three or four years and enshrine recursive STARKs at the core. He also sketched another use for the approach: private account abstraction, which would keep an account's logic hidden on-chain, then change ownership of every position and holding attached to it in a single transaction, without revealing which ones.
EIP-8288, which Buterin co-authored with Thomas Coratger, depends on Frames, the transaction overhaul he promoted on Sunday, which is itself unscheduled. He wants both included in I-star, the upgrade after Hegota, which he has said will be Ethereum's last before the Lean era begins. Neither proposal has been assigned to a fork yet.
Source: Decrypt
Trading involves risk.