📈 Get daily crypto insights that make you smarter about your money

Vitalik Buterin Wants to Move Ethereum Hard Math Out of Blocks: Recursive STARK Mempools Could Make Quantum-Safe Payments Nearly Free

Ethereum co-founder Vitalik Buterin has floated a new proposal that could slash the cost of quantum-safe transactions and private payments by moving heavy cryptographic work out of blocks and into the mempool — the waiting room where transactions sit before they are confirmed.

By Keisha Williams | September 10, 2026

In a September 9 post on X, Buterin pointed to EIP-8288, titled “A note on recursive STARK mempools.” He said he hopes the idea can be considered for I-star, the Ethereum upgrade fork that would come after Hegotá. The proposal is not an activated upgrade — it is a design sketch that could unlock what Buterin called “extreme amounts of power” if it survives review.

The Hook: Cheaper Security for Everyone

Here is the problem in plain English. The cryptography that keeps Ethereum safe today is fast and cheap. But the cryptography that would keep it safe against a future quantum computer is enormous — signatures so big and so slow to verify that using them on the main network would be wildly expensive for ordinary users.

Buterin’s answer: do the heavy math before transactions ever reach a block. Special network nodes would batch the expensive computations together and attach a single compact proof that everything checks out. The block then only needs to carry that small proof instead of repeating the work for every transaction. Think of it like a teacher checking one signed attendance summary from each row, instead of quizzing every student one by one.

How the Numbers Stack Up

According to Buterin’s estimates, some quantum-safe operations that could cost around 10 million gas today — roughly what a complex smart contract deployment costs — could potentially fall to the low tens of thousands of gas under the new design. For comparison, a simple token swap often costs less than that today.

  • Privacy transactions — highly optimized ones currently run around 300,000 gas, while a quantum-safe version could reach roughly 10 million gas. EIP-8288 could push both toward the low tens of thousands.
  • Proof size — the design would require roughly one STARK of 100 to 300 kilobytes plus about 96 bytes per statement being proven.
  • Quantum-safe signatures — SPHINCS-style signatures of around 3 kilobytes would stay off the chain entirely, with only a tiny proof of their validity recorded.

Those figures are Buterin’s own estimates, and they depend on how the final cryptography is built. But the direction is clear: make the safe option the affordable option, so users are never tempted to stay on weaker cryptography because it is cheaper.

The Core Conflict: Where Does the Work Happen?

Under the proposal, transactions could carry what Buterin calls dependency frames — bundles of statements that need to be proven, such as “this message was signed by this key” or “this data satisfies this condition.” Instead of every node independently redoing each computation, mempool nodes would collect transaction envelopes, drop expired ones, and generate a recursively aggregated proof — a proof of proofs — that gets broadcast to the network. A block builder then produces one final covering proof for the transactions it includes.

A STARK, by the way, is a kind of mathematical receipt: a tiny piece of data that proves a large computation was done correctly, without anyone having to redo it. “Recursive” means proofs can be stacked inside other proofs, so thousands of checks collapse into one.

The design choices are not settled. Buterin said RISC-V, a widely used open instruction-set architecture, is the leading candidate for describing the computations being proven, though the choice would require careful consideration. Bandwidth also matters: each node would broadcast roughly one 100 to 300 kilobyte STARK per time interval — he suggested 500 milliseconds as an example — alongside normal transaction data. The plan shifts costs from raw computation toward proof generation, verification, and network communication.

Why Quantum Safety Is Suddenly Urgent

The proposal lands the same week Ethereum’s protocol developers set December 2029 as a target for post-quantum readiness at the base layer, while narrowing the scope of the Hegotá fork around features including FOCIL and Frame Transactions. EIP-8288 is separate from that deadline, but it attacks one of the hardest parts of the puzzle: post-quantum cryptography is computationally expensive by nature.

Buterin said schemes like Falcon and ML-DSA, along with other lattice-based, code-based, or potentially isogeny-based systems, could theoretically be wrapped inside STARK proofs. That flexibility matters: instead of Ethereum needing to build native support for every new cryptographic standard at the protocol level, developers could submit their computation through dependency frames and prove it valid. New cryptography could arrive without constant changes to the network’s core rules.

Privacy Gets a Boost Too

The same architecture could make private transactions dramatically cheaper. Buterin also sketched a use for private account abstraction — users could change ownership across accounts, DeFi positions, and privacy-related notes without publicly revealing which specific objects were affected, while the network still verifies the resulting state.

This builds on a busy stretch for Ethereum privacy work. In August, a separate proposal explored letting privacy pools pay transaction fees directly, reducing the need for intermediaries to cover gas costs. That upgrade focuses on how private transactions pay their way; EIP-8288 focuses on cutting the cost of the cryptography itself.

What This Means For You

For regular investors and users, nothing changes today. EIP-8288 is a proposal, not a roadmap commitment, and it would need to clear questions around the dependency-frame design, the instruction set, proof-generation requirements, and node resource use before anything ships. Broader developer review is still required.

But if it lands, the payoff is practical: quantum-safe wallets and private payments that cost about as much as an ordinary transfer does now, instead of fifty times more. In a future where quantum computers loom over every older blockchain, being both safe and cheap would be a genuine competitive edge for Ethereum — and a quiet tailwind for every app built on top of it.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

13 thoughts on “Vitalik Buterin Wants to Move Ethereum Hard Math Out of Blocks: Recursive STARK Mempools Could Make Quantum-Safe Payments Nearly Free”

  1. moving STARK verification into the mempool is genuinely clever. the block real estate savings alone would matter once post-quantum sigs land and every tx balloons to kilobytes

  2. quantum safe txs going from 10 million gas to the low tens of thousands is a 500x drop. thats the gap between unusable and every wallet just supporting it by default

    1. its a design sketch for I-star though, comes after Hegotá, so were years out. watch people price it in tomorrow anyway lol

    2. and thats the difference between pq sigs being a hidden advanced toggle nobody clicks and wallets just shipping it by default

    3. 500x is the headline, the second order is better: wallets bundle into aggregate proofs so normal users never touch the expensive math at all. verification cost amortizes to nearly nothing

      1. the amortization math only holds if proving stays competitive tho. one or two dominant batchers and normal users are right back to paying rent on inclusion, just denominated in proof fees

  3. Every few months Vitalik posts something like this and half of twitter treats it as shipping tomorrow. It is a sketch for the fork AFTER Hegotá. Relax.

  4. The part that worries me is who runs the special batching nodes in the mempool. EIP-8288 moves the heavy math there, but nobody is answering what happens when those operators start censoring transactions.

    1. same fight happened with mev relays and the answer was fallbacks. nobody is forced to use a batcher, you can always pay full price and get plain verification. censorship costs you the discount, not the tx

    2. hopefully the same fix as relays: require multiple independent batchers per tx and bake operator diversity rules into the EIP before it leaves note stage. otherwise we rebuilt censorship as a feature

  5. recursive aggregation is the whole trick. one STARK covers thousands of mempool txs instead of each one paying for post quantum bloat. deserves the i-star slot on blockspace math alone

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,133.00-0.4%ETH$2,458.58-1.1%SOL$101.37-1.9%BNB$721.03-4.3%XRP$1.39-1.9%ADA$0.2113-3.9%DOGE$0.0858-4.6%DOT$1.11-10.2%AVAX$7.73-3.2%LINK$11.73-6.3%UNI$6.16-9.5%ATOM$1.86+0.9%LTC$53.00-2.6%ARB$0.1527-7.8%NEAR$2.47+6.7%FIL$0.8196-3.4%SUI$0.7708-5.0%BTC$78,133.00-0.4%ETH$2,458.58-1.1%SOL$101.37-1.9%BNB$721.03-4.3%XRP$1.39-1.9%ADA$0.2113-3.9%DOGE$0.0858-4.6%DOT$1.11-10.2%AVAX$7.73-3.2%LINK$11.73-6.3%UNI$6.16-9.5%ATOM$1.86+0.9%LTC$53.00-2.6%ARB$0.1527-7.8%NEAR$2.47+6.7%FIL$0.8196-3.4%SUI$0.7708-5.0%
Scroll to Top