Abstract: SNARKs leads Vitalik Buterin towards less than 10 times computing costs
FHE (fully homomorphic encryption) and iO (indistinguishable obfuscation) face higher practical efficiency thresholds.
Vitalik Butrin believes that the probability that SNARKs, FHE and iO will eventually achieve less than 10 times the computing overhead is overall 60%. Among them, SNARKs are most likely to achieve single-digit overhead before 2030, but this time point is not suitable for all three technologies. In addition, Buterin estimates that the probability that these three tools will end up close to 1+ε (i.e., with almost no overhead) in practical applications is 33%. Lower-cost SNARKs are expected to support Ethereum's higher Gas limit with a disproportionate increase in validator hardware. [TAG
Ethereum co-founder Vitalik Buterin gives a quantitative assessment of a long-standing cryptographic problem: How far are advanced privacy protection and verification tools from the cost of ordinary computing? In a September 6 post, Butlin noted that SNARKs (compact non-interactive zero-knowledge arguments), FHE (fully homomorphic encryption), and iO (indistinguishable obfuscation) end up with a 60% probability of being less than 10 times computationally expensive.
He measures this overhead in terms of total energy consumption and amortized computation costs, and gives each of the three techniques a 33% probability of approaching 1+ε overhead (i.e., very low overhead in average real-world computation).
Butrin is optimistic about the possibility of SNARKs, FHE and iOs achieving low overhead
Ethereum co-founder Vitalik Buterin said he believes that the probability that SNARKs, fully homomorphic encryption and indistinguishable obfuscation will ultimately be achieved with single-digit (single-digit) overhead is 60%. This distinction is important because the timeline is more urgent than the probability implied by the title. Butrin did not say that all three technologies would cross the threshold below 10 times by 2030, but pointed out that at least one technology could achieve single-digit spending by the end of the decade, and SNARKs was the most likely candidate.
SNARKs lead the way in driving computing costs down
SNARKs allow systems to prove that calculations have been performed correctly without having to repeat the entire process for each verifier. As a result, they have become the core of the Ethereum zero-knowledge expansion model. Zero-knowledge Rollups has adopted this approach, processing transaction batches outside of the Ethereum base layer and then submitting proof of validity to the main network, allowing the network to verify these transactions while maintaining Ethereum's security.
However, proof generation remains the main constraint. Complex proofs still require a lot of computing power, and some workloads rely on dedicated hardware. Still, Buterin said the efficiency gap is starting to narrow. In August this year, he highlighted research that showed that the proof cost of reasoning workloads for some large language models was nearly 10 times less. He also pointed to specialized hash functions where single-digit overhead has been achieved.
As certification costs fall, this improvement may have a direct impact on Ethereum's future architecture. The network's zkEVM roadmap envisions a validator verifying the proof of an entire block, rather than replaying each transaction independently. Therefore, sufficiently efficient proof generation may allow Ethereum to increase the Gas limit without proportionally increasing the validator hardware. This will make low-cost SNARKs increasingly important for scalability and verifier efficiency.
FHE and iO face higher practical efficiency barriers
While SNARKs focus on verification computing, FHE addresses a different challenge: privacy. It allows calculations to be performed directly on encrypted data without first revealing the underlying information. NIST describes FHE as a privacy-enhancing technology that can apply arbitrary functions to encrypted data without having to access a secret decryption key. For blockchain, this capability could support private automated market makers, secure lending markets and sealed auctions.
Ethereum's privacy roadmap directly identifies these scenarios. However, the computational cost of FHE is still much higher than ordinary plaintext processing. Therefore, achieving less than 10 times the overhead would be a significant step toward wider availability.
Indistinguishable confusion (iO) presents a more challenging puzzle. The technique aims to transform software while retaining its functionality, making equivalent obfuscated programs computationally indistinguishable. Although recent research has strengthened the theoretical foundation of iO, its actual costs remain extremely high. Butrin once described the computing cost of traditional structures as "galactic".
To reduce costs, his recent work explores methods including Diamond iO and local mixing. Diamond-type iOs reduce the theoretical burden but remain impractical, while local mixing takes a different path and its safety has not yet been proven.
Even so, each technique addresses a different part of a broader cryptographic problem. Cheaper SNARKs can make verifiable computing more routine, while FHE can extend private computing on shared data. At the same time, efficient iO helps protect the internal logic of executable software. However, at present, Buterin's 60% estimate is still a personal probability assessment rather than a promise from the Ethereum roadmap.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH