FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T -0.3%24h Vol $153.2B +122%Fear & Greed 74/100Alts Index 57/100
BTC.D 58.4% -0.5%Stable.D 9.2% 0%ETH.D 11.4% 0%Others.D 21.0% +0.5%
SHFL$0.6630+69.75%•HBAR$0.1270+33.63%•QNT$237.40+26.15%•MARSCOIN$0.1593+25.11%•BTW$1.300+13.41%•ALGO$0.1333+12.12%•XDC$0.0361+11.77%•CASHCAT$0.1903+8.94%•IOTA$0.0552+8.55%•LINK$15.111+7.21%•
Q$0.0259-47.69%•USELESS$0.2405-19.17%•AR$4.225-15.08%•FARTCOIN$0.1681-14.63%•MET$0.3234-14.14%•RAY$1.913-13.77%•ZEN$6.890-13.01%•WLD$0.4918-12.45%•NEAR$4.815-11.86%•ARB$0.2024-11.69%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Vitalik Buterin Explained How Ethereum Could Make Private and Post-Quantum Transactions Cheaper Using Recursive STARKs

      • Vitalik Buterin proposed a new transaction processing model.
      • He explained how recursive STARKs will move part of the workload off the blockchain.
      • In his view, Ethereum can get rid of expensive cryptographic operations using STARKs.

      Ethereum co-founder Vitalik Buterin explained the concept behind EIP-8288 — a proposal that would add recursive aggregation of STARK proofs and cryptographic signatures at the mempool level to the network. 

      Buterin hopes to include this approach in the I-star upgrade, which is expected to take place after Hegota, as it could significantly reduce the costs of post-quantum signatures, private transactions, and new cryptographic schemes without having to change the EVM.

      How the Recursive STARK Mempool Will Work

      EIP-8288, authored by Vitalik Buterin and Tomas Koratje, was created on June 3, 2026. The proposal extends EIP-8141 with a new frame type that makes it possible to aggregate cryptographic signatures and STARK proofs off-chain, and then verify them with a single recursive STARK without needing to store all the original data directly in the block.

      Recall that EIP-8141 and the recursive STARK mempool became part of research into moving from sequential execution to splitting transactions into actions and dependencies.

      The mechanism will be based on so-called dependency frames — parts of a transaction that contain claims about its dependencies. For example, a frame can attest that a particular message hash is signed by a specific public key, or that certain data satisfies a condition defined by a verification key.

      When a transaction enters the mempool, network nodes will aggregate the received dependencies. Every notional 500 ms, a node will collect new transactions, remove expired ones, generate a recursive STARK that attests to all dependencies, and forward a new envelope for multiple transactions.

      According to Buterin, this will make it possible to limit bandwidth load: each node’s outbound traffic will consist of a single STARK of roughly 100-300 KB per cycle, plus the usual one-time broadcast of the transactions themselves across the network.

      After that, the block builder will effectively operate as another mempool node. It will receive transactions, generate its own STARK for the portion of dependencies it plans to include in the block, and attach that proof to the block.

      As a result, the total amount of data that will need to be stored onchain will be one STARK sized 100-300 KB plus 96 bytes per claim it attests to. Buterin called this concept Proof Singularity — an approach that, in his view, can already be implemented using existing technology.

      Post-Quantum Signatures and Privacy

      One of the key advantages of EIP-8288, Buterin believes, is making post-quantum cryptography cheaper. Right now, hashed post-quantum signatures can be around 2-3 KB and require roughly 150,000-200,000 gas to verify, whereas the proposed approach would avoid putting the signature data itself onchain.

      Buterin noted that this could make post-quantum signatures like SPHINCS- “ultra-cheap.” He suggests applying a similar principle to privacy protocols: today, a well-optimized private transaction costs about 300,000 gas, while post-quantum solutions may require around 10 million gas. By his estimate, EIP-8288 could potentially bring that down to a few tens of thousands of gas.

      Another advantage will be the ability to use new cryptographic schemes without making changes to the EVM. In particular, Buterin mentions Falcon, ML-DSA, and other lattice-, code-, and isogeny-based algorithms and schemes: they can be wrapped in a client-side STARK, while onchain costs would remain at the level of a few tens of thousands of gas.

      “Hopefully, Ethereum will never need “please support my favorite cryptographic algo” politics again,” Buterin wrote.

      Separately, the developer highlighted private account abstraction. This approach would make it possible to hide account logic and transfer ownership of the entire onchain state — including accounts, DeFi positions, and private protocol records — in a single transaction, without revealing which specific objects changed hands.

      In practical terms, EIP-8288 proposes moving computations and data that do not belong to the core “business logic” of transaction execution off Ethereum’s main execution path. These operations would be processed and parallelized at the mempool level, while the blockchain would store a compact proof of their correctness.

      For developers, this means changing the approach to signature verification and STARKs. Instead of directly verifying a cryptographic proof, the core transaction logic will check for the presence of a frame with the relevant claim as a dependency.

      At the same time, implementing EIP-8288 will require Ethereum to settle on a language, or ISA, to be used for recursive STARKs. For now, Buterin names RISC-V as the leading candidate, but the final choice, he says, requires careful consideration, as it could effectively mean adding RISC-V or another ISA as Ethereum’s canonical standard.

      EIP-8288 also предусматривает compatibility with FOCIL and uses Lean Ethereum tools for signatures and STARKs.

      Сообщение Vitalik Buterin Explained How Ethereum Could Make Private and Post-Quantum Transactions Cheaper Using Recursive STARKs появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud