Ethereum Foundation Targets Quantum-Resistant Ethereum (ETH) L1 by December 2029

The Ethereum Foundation targets a quantum-resistant ETH L1 by December 2029, spanning accounts, consensus and data layers, per its September 16 Reddit AMA.

(10:33 AM UTC)
4 min read
AI SummaryAI
  • Buterin estimates ECDSA signatures at ~4,000 gas versus 100,000-250,000 for SPHINCS+
  • EIP-8025 optional execution proofs under consideration for the Hegotá upgrade
  • Drake cites teams expecting most mainnet blocks proved in ~2 seconds by 2027
  • Decoupled consensus could cut finality from ~16 minutes to ~4 minutes initially
p9zt4hjs

Quantum-Resistant L1 by December 2029

The Ethereum Foundation's Protocol team has set December 2029 as its working deadline for a quantum-resistant Ethereum (ETH) layer 1 — a scope that reaches well beyond swapping out a single signature scheme. In a Reddit AMA hosted on September 16 by the Foundation's protocol researchers, the team mapped how the migration would touch every tier of the Ethereum network: user accounts need new signature mechanisms, the proof-of-stake consensus layer must replace BLS signatures and their aggregation, and the data-availability layer has to unwind its reliance on KZG commitments. Researchers were explicit that a core-protocol migration alone will not make wallets, rollups, bridges and applications quantum-safe — each system must audit and migrate its own cryptographic dependencies in parallel, and no single isolated upgrade completes the job.

The account-layer centerpiece is Frames, a transaction format that makes verification, execution and gas fee payment programmable. Combined with proposed migration paths, Frames would let accounts move off the original secp256k1 keys and swap signature schemes again later as post-quantum cryptography matures. Cost remains the sticking point: Vitalik Buterin framed the gap in the AMA, noting an ECDSA signature costs roughly 4,000 gas while a SPHINCS+-class post-quantum signature runs about 100,000 to 250,000 gas depending on parameters. Aggregating signatures before transactions enter blocks, and substituting proofs for raw data, are the follow-up work items meant to close that gap. The Foundation also cautioned that the 2029 date is conditional on research and implementation progress, that many AMA answers were personal views rather than settled policy, and that its restructured teams — Access Layer, Ethlabs and Ethereum Institutional — are meant to keep research, engineering and ecosystem communication moving in step across the multi-year effort.

EIP-8025 and Real-Time Proofs

Execution proving is where the quantum roadmap and Ethereum's scaling ambitions intersect. Both tracks lean on RISC-V-based zkVMs, so investment in proving systems and tooling compounds across them; over the past year the work has advanced through execution specifications, testing, client integration and open-source tooling. The near-term decision point is whether EIP-8025, which introduces optional execution proofs, can be included in the Hegotá upgrade to accumulate operating experience before verification of proofs ever becomes a default procedure. Justin Drake is bullish on real-time proving, arguing that the main performance risks have narrowed significantly and citing teams that expect to prove most mainnet blocks in roughly two seconds by 2027. Other researchers pushed back: rising gas limits, new precompiles and block-structure changes could inflate the proving burden, forced proving should be deferred if performance falls short, and state growth may become the scaling bottleneck before proving latency does. The decentralization trade-off is real — generating proofs may require specialized hardware while verification stays cheap — so researchers are studying lower hardware thresholds and distributed proving to keep builder and prover power from concentrating.

Privacy work builds on the same rails: Frames and FOCIL would let privacy applications ride the public mempool with protocol-level censorship resistance, though timelines diverged sharply — from possible native privacy transactions in 2027 to Drake assigning near-zero probability to a protocol-embedded privacy pool before end-2028, and L1 privacy gains would not displace privacy-focused Layer 2 designs. Formal verification is advancing as the safety net, with security proofs for signature schemes, zkVM circuit checks and EVM program verification already uncovering and fixing real bugs — a discipline where OpenZeppelin's smart-contract security footprint is newly institutional. On finality, Ben Edgington said the originally imagined single-slot path has ended but decoupled consensus could cut finality from roughly 16 minutes to about 4 minutes in an early phase, targeting one to two slots long term. Privacy skeptics and Vitalik's push on privacy frame the debate still to come. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

A Multi-Fork Roadmap, Issuance Unresolved

COINOTAG's read: the AMA's most consequential output is architectural. As laid out in the official discussion record and preserved in the original compilation thread, the next phase of Ethereum is not one upgrade but a sequence of coordinated hard forks aligning accounts, cryptography, execution proving, privacy and consensus — with EIP-8025's optional proofs as the first on-ramp, and node operators facing incremental client work rather than a disruptive cutover. That cadence is already live: developers have locked the Glamsterdam Sepolia testnet fork for Oct 6. The genuinely open question is economic, not technical — Drake and Anders Elowsson personally support adjusting ETH issuance because sustained staking incentives pressure non-staking holders toward exchanges and liquid staking tokens, yet the AMA produced no decision on any issuance reduction or staking cap, leaving that consensus battle for a later cycle.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.