EIP-8288: Reducing the cost of advanced encryption for Ethereum through aggregated authentication
Thanks to the EIP-8288 proposal, the Ethereum encryption improvement plan co-written by Vitalik Buterin and Thomas Coratger is expected to significantly reduce execution costs. The proposal aims to integrate post-quantum signatures with STARK proof technology and is still in the draft stage.
Core Points
- Reduce costs: EIP-8288 is designed to reduce the cost of advanced cryptographic operations on Ethereum.
- Polymerization Verification: replaces thousands of separate verification processes with aggregated STARK certification.
- Post-quantum signature: makes verification of post-quantum signatures more cost-effective.
- Privacy Extension: Paves the way for new privacy application scenarios.
- Current status: The proposal is still in draft form and a specific deployment timetable has not yet been determined.
Replacing a thousand tests with one certificate: Solving storage and computing bottlenecks
A signature scheme that can withstand quantum computer attacks is currently too heavy on Ethereum. Existing research models take up approximately 2 to 3 KB of space per signature and consume 150,000 to 200,000 Gas units per verification. STARK proved to face even more severe challenges. Its data volume often exceeds 128 KB, and may even approach 512 KB to maintain the generation speed. If you verify directly on the Ethereum chain, the cost of a single verification is as high as millions of Gas units.
To this end, EIP-8288 proposes replacing a complete independent proof with a lighter cryptographic dependency. Its operating mechanism mainly includes four stages:
- Statement submission: The transaction initiates a claim (e.g. the validity of the signature).
- Evidence transfer: The user sends the corresponding certificate to the memory pool node.
- Recursive aggregation: The node combines these proofs into a common recursive STARK proof.
- Block Record: The block contains only one aggregated certificate and a 96-byte label for each dependency.
The memory pool node is expected to generate a new aggregation package every second, and the block builder can then integrate these packets into a final certificate and record them in the block header. Regardless of how many certificates are grouped during the aggregation interval, the amount of data related to STARK will remain at approximately 256 KB. At the same time, the original transaction can still be circulated separately on the Internet.
This operation does not eliminate the computational costs of cryptography itself, but instead shifts most of the work outside the blockchain, then requiring the network to verify only a single public certificate, greatly optimizing the efficiency of the use of resources on the chain.
Four New Application Prospects for Ethereum Cryptography
Under this architecture, Vitalik Buterin first saw a way to reduce the cost of post-quantum signatures. Ethereum will integrate mechanisms based on leanSPHINCS without having to store every complete signature data in a block.
Secondly, privacy agreements will also benefit. Users can prove the legitimacy of the operation without revealing all the details that make up the operation. Through the aggregation mechanism, the costs associated with STARK certification will be significantly reduced.
In addition, EIP-8288 also helps integrate new signature or certification systems. Users can encapsulate a cryptographic mechanism in a compatible STARK without having to impose its full format on the protocol.
Finally, Buterin proposed the concept of "private account abstraction." Users can change the ownership of various chain assets in a single transaction without publicly exposing the transferred assets. Such a feature will help with wallet recovery or rotation if keys are compromised, but it does not immediately protect all Ethereum accounts from quantum computers.
It is important to note that wallets and applications must proactively adopt new signature schemes. EIP-8288 provides only infrastructure support for low-cost verification.
Implementation Environment and Potential Risks
The system also requires a unified environment for writing and checking certificates. Based on available information, Buterin sees the RISC-V architecture as a leading candidate to fulfill this role.
The proposal was created by Vitalik Buterin and Thomas Coratger on June 3, 2026 and obviously relies on EIP-8141 that introduces transactions consisting of multiple execution frames. At present, the document is still in draft status, its aggregate verification key has not yet been defined, and the reference implementation part is also marked as "pending".
Its activation may change consensus rules and old nodes will reject transactions and blocks in this new format. Therefore, Ethereum needs to integrate EIP-8288 through network upgrades. Buterin hopes to include it in what he calls the "post Hegota fork"(or "I-star"), but this represents only a technology preference rather than a definite deployment timetable.
There are still many risks that need to be addressed. Security will depend on the reliability of Lean Ethereum circuits, hash functions, and STARK recursion. Therefore, developers must also take steps to limit denial of service (DoS) attacks. The EIP currently has parameters for each transaction to contain up to 16 leanSPHINCS signatures and one leanSTARK proof, which may evolve during discussion and testing.
In summary, EIP-8288 will open a new stage in Ethereum cryptography. However, before any activation, a functional implementation plan, strict audit results, and broad consensus among developers are still required.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH