Ethereum co-founder proposes EIP-8288: Aiming to significantly reduce the running costs of anti-quantum cryptography
Ethereum co-founder Vitalik Buterin proposed EIP-8288, which aims to significantly reduce the running costs of anti-quantum cryptography on the Ethereum (ETH) network. The EIP was merged into the Ethereum EIP repository on September 9, 2026, introducing the recursive STARK aggregation framework. Butrin is pushing to include it in the I-star upgrade, a hard fork planned to follow the Hegota upgrade.
The problem: Anti-quantum signatures is costly
On today's Ethereum network, anti-quantum cryptography comes with heavy economic costs. Buterin estimates that highly optimized privacy transactions may currently require about 300,000 Gas, while the cost of implementing anti-quantum security may be as high as about 10 million Gas. These numbers make widespread adoption of post-quantum signatures almost impossible at current costs.
The proposal solves a problem that has been lurking in the Ethereum roadmap for years: post-quantum signatures are huge and costly to verify on-chain. Instead of having each transaction carry its own expensive proof, the scheme allows transactions to declare their quantum-resistant signatures and STARK proof as dependencies, and memory pool nodes batch combine them into a compact aggregate proof.
Working principle of EIP-8288
The proposal aims to move signature verification and proof generation out of Ethereum's main execution path, leveraging recursive aggregation within the memory pool to significantly reduce on-chain overhead. Ethereum nodes will periodically aggregate dependencies between transactions to generate recursive STARK certificates, and the block creator will then package these necessary certificates so that transactions are included in the block.
Under his proposed architecture, Butrin believes that these costs could fall to as low as tens of thousands of Gas, although these numbers are only his estimates, depending on how the cryptography is constructed and implemented. Buterin also pointed out that this approach helps make the RISC-V architecture the standard instruction set for recursive STARK transactions in the Ethereum ecosystem.
It is worth noting that the proposal is not an activated Ethereum upgrade; rather, it describes a possible change in how nodes handle signatures, certificates, and other computationally intensive dependencies before transactions are included in blocks.
The significance of the time node
This timing attracts attention. The Ethereum Foundation protocol cluster has set a deadline of December 2029, requiring the Ethereum basic layer to fully implement quantum-resistant capabilities in the execution, consensus and data layers, and said it will implement this self-imposed deadline until at least January 2027. EIP-8288 would be a meaningful step towards this goal, although it has not yet been confirmed whether it will be included in any plan's hard fork.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH