Thanks to EIP-8288, Ethereum cryptography co-written by Vitalik Buterin and Thomas Coratger could become less expensive. This text should bring together post-quantum signatures and STARK proofs, however it still remains at the draft stage.

In brief
- EIP-8288 wants to reduce the cost of advanced cryptography on Ethereum.
- An aggregated STARK proof would replace thousands of individual verifications.
- Post-quantum signatures could become less expensive to verify.
- The system would also open the way to new uses of confidentiality.
- EIP-8288 remains in draft stage, with no confirmed deployment schedule.
One proof would replace thousands of checks
Signatures that resist quantum computers remain too heavy for Ethereum. Thus, the models studied occupy approximately 2 to 3 KB and require between 150,000 and 200,000 gas units per verification.
The STARK proofs pose an even greater difficulty. In fact, their size goes beyond 128 kb and can be around 512 kb if their creation must remain rapid. Direct verification on Ethereum would then cost several million units of gas.
L’EIP-8288 therefore offers to replace each complete proof with a lighter cryptographic dependency. Its operation could be based on four main phases:
- The transaction declares an assertion, like the validity of a signature;
- A user transmits the corresponding proof to the mempool nodes;
- Nodes group evidence into a common recursive STARK;
- The block contains a single aggregated proof and a 96-byte tag per dependency.
The mempool nodes would produce a new aggregate every second. Then the block constructor could assemble these packets into a final proof, saved in the block header.
The volume linked to STARKs would remain close to 256 KB per aggregation interval, regardless of the number of evidences grouped together. However, transactions could continue to flow separately on the network.
The operation therefore does not eliminate the cryptographic cost. It moves much of the work off the blockchain, then requires the network to verify a single common proof.
Ethereum cryptography would gain four uses
In this architecture, Vitalik Buterin first sees a way to reduce the cost of post-quantum signatures. Ethereum would thus integrate mechanisms based on leanSPHINCS without storing each complete signature in a block.
Confidentiality protocols are concerned by the second use. Thus, users would prove the validity of an operation without revealing all the information that makes it up. The grouping would then reduce the costs linked to STARK proofs.
The EIP-8288 could also allow the integration of new signature or proof systems. A user would wrap a cryptographic mechanism in a compatible STARK without imposing its full format on the protocol.
Buterin finally evokes a “private account abstraction”. A user would change the ownership of various on-chain positions in a transaction, without publicly revealing the assets being moved.
Such a feature would make it easier to recover a compromised wallet or rotate a key. However, it could not immediately protect all Ethereum accounts against quantum computers.
Wallets and applications are expected to adopt the new signatures. The EIP-8288 only offers the useful infrastructure to verify them at a lower cost.
However, the system also requires a common environment for writing and checking proofs. According to the information providedButerin presents RISC-V as the main candidate to fill this role.
No deployment is yet scheduled
On June 3, 2026, Vitalik Buterin and Thomas Coratger created EIP-8288. This proposal depends in particular on EIP-8141, which introduces transactions composed of various execution frameworks.
The document remains in draft status. Its aggregate verification key remains to be defined, while the section intended for the reference implementation still indicates “to be determined”.
Its activation could also modify the consensus rules. Older nodes would reject transactions and blocks that use this new format. Ethereum would therefore integrate EIP-8288 into the network upgrade.
Buterin hopes for inclusion in “I-star”which he describes as “the fork after Hegota”. This statement represents a technical preference, not a confirmed deployment schedule.
Many risks remain to be resolved. Security will depend on the reliability of Lean Ethereum circuits, the hashing function and STARK recursion. Therefore, developers will also have to limit denial of service attacks.
The EIP already projects a maximum of 16 leanSPHINCS signatures and one leanSTARK proof per transaction. These parameters may still evolve during discussions and tests.
EIP 8288 would therefore open a new stage for Ethereum cryptography. Its adoption will nevertheless require functional implementation, audits and agreement from developers before any activation.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
