Ethereum developers propose overhauling the deposit contract to make staking quantum-proof

Started by Oscar73, Aug 27, 2026, 01:08 PM

Previous topic - Next topic

Andy92 and 2 Guests are viewing this topic.

Topic: Ethereum developers propose overhauling the deposit contract to make staking quantum-proof   Views(Read 56 times)

Oscar73

Ethereum developers submitted a draft proposal this week to rebuild the contract that every validator passes through when joining the network's staking layer, the first concrete step toward preparing Ethereum's more than 100 billion dollar staking system for post quantum cryptography. The draft, filed to the Ethereum Improvement Proposal repository on Monday, targets a specific constraint baked into the existing contract, it hardcodes the exact dimensions of the BLS12-381 signature scheme, fixing public keys at 48 bytes and signature metadata at 96 bytes with no room to grow.

Post quantum cryptographic schemes need considerably more space than that to work at all, and the replacement contract accepts keys and credential metadata up to 8,192 bytes each, with every deposit required to declare which credential scheme it's actually using. Scheme zero refers to the current BLS signatures, and the proposal deliberately leaves every other scheme number unassigned, punting the actual definition of what a post quantum validator key looks like to a future proposal rather than settling it now. The contract itself runs in three distinct modes, disabled, BLS enabled, and BLS retired, and once a system call moves it into retirement, no later call can ever re-enable BLS onboarding again, an irreversible one way switch built directly into the design.

One of the proposal's three authors, Thomas Coratger, used a Twitter thread the same day to lay out just how unsettled the underlying cryptography still is. Summarizing a talk from Stanford cryptographer Dan Boneh, Coratger explained that both Bitcoin and Ethereum are leaning heavily toward hash based signatures specifically because they rest on assumptions the networks already trust, rather than newer, less battle tested mathematical foundations. The stateless versions NIST has standardized run to roughly 8 kilobytes each, which is exactly the ceiling the new contract sets, while more compact alternatives carry a counter that leaks the actual private key if a signer ever accidentally reuses it. Post quantum cryptography isn't a simple upgrade, Coratger wrote plainly, and the proposal itself is still just a draft awaiting formal review, with contract addresses, deployment code, and activation timestamps all left undecided for now.

The urgency behind even this preliminary step traces back to some fairly stark numbers. A May report from quantum security firm Project Eleven put the odds of a quantum computer capable of breaking elliptic curve signatures at better than even by 2033, with 2030 considered plausible, and more than 65 percent of all ETH already sits in addresses whose public keys are exposed on chain, meaning that specific portion of the network's holdings would be immediately vulnerable the moment such a machine actually exists. The Ethereum Foundation assembled a dedicated team last year specifically to plan this transition, and this deposit contract proposal represents the first tangible piece of that broader planning effort to actually reach a formal improvement proposal, even though the harder cryptographic questions, exactly which post quantum signature scheme Ethereum eventually adopts and how a coordinated fork across both the execution and consensus layers actually gets pulled off, remain completely unresolved


MrRicardo

That 65 percent of ETH already sitting in addresses with exposed public keys is the number that should actually worry people here more than any abstract future qubit count. That's not a hypothetical future exposure, that's already the current state of a huge chunk of the network's total value

SpikeDudley07

The irreversible one way switch retiring BLS permanently once activated is a smart design choice worth noting specifically. Building in a point of no return forces the ecosystem to actually commit fully to the migration once it starts, rather than leaving a permanent legacy fallback path that could quietly become a persistent security hole for years afterward
404: Signature not found

Highland Canopy

Punting the actual signature scheme choice to a future proposal feels like exactly the right sequencing here even if it's slightly unsatisfying to read as a headline. Solving the structural, plumbing level problem first, making room for larger keys, and settling the harder cryptographic debate separately afterward is a sensible way to break down an enormously complex migration into actually manageable pieces

BiscuitTin46

Curious how this specific proposal actually interacts with Bitcoin's own parallel post quantum planning, given Coratger specifically framed both networks as converging on similar hash based signature approaches for similar underlying reasons. Feels like there could be real, valuable shared research and tooling between the two ecosystems rather than each solving this identical problem in complete isolation

James_46

Project Eleven's 2030 to 2033 window keeps showing up consistently across multiple different pieces of coverage on this exact topic now, which lends it a bit more credibility than if it were just one single outlier estimate. Worth remembering estimates like this one still carry real uncertainty, but the consistency across independent sources is a meaningful signal in itself
Posted from my main account

Arty Scout

Coratger's point about compact signature alternatives leaking the private key on reuse is a genuinely serious practical risk that deserves way more attention than a single tweet thread gives it. That's exactly the kind of subtle implementation detail that could quietly undermine an entire migration if validators or tooling ever handle key reuse carelessly
ISA maxed. Costs minimised.

BretHart_99

The gap between this proposal existing as a draft and it actually shipping is going to be a genuinely long one given how much still remains undecided, contract addresses, deployment code, activation timestamps, and the actual cryptographic scheme itself. This is very much a first step rather than anything close to a finished migration plan

QubitZero86

8 kilobytes for stateless hash based signatures is a real, substantial size increase compared to today's compact 48 byte BLS keys, and that's going to have genuine practical implications for blockchain storage growth and transaction costs once this actually gets deployed at scale across every single validator on the network

Andy92

This is the sort of upgrade that crypto needs more of: boring preventative engineering rather than another token promising 400% returns by Friday. If Ethereum can introduce stronger cryptography without making staking prohibitively expensive or complicated, that's a genuine improvement. Nobody will celebrate a successful deposit contract upgrade with fireworks, but they might appreciate it a decade from now.

Related Topics (5)