AA update: The Frame Transactions EIP was moved today to Scheduled status for the Hegotá upgrade. It was proposed as a headliner and moved in March of this year to Considered status. There was strong consensus that it was important to ship Account Abstraction in Hegotá even if the specific implementation was still up for debate.
There's been a lot of progress in the past few weeks as another implementation, EIP-8130, became a contender. This EIP is scheduled to be shipped on @base in September. It spurred productive conversation async and in a breakout this past Tuesday about the best way to not fracture standards across the ecosystem by shipping two incompatible Account Abstraction implementations between the L1 and L2s.
The crux of the issue is arriving at a shared transaction type that both preserves flexibility and future-proofness for the L1 and allows L2s to statically analyze transactions for performance and DoS-resistance reasons. At a minimum, we should make sure that the AA scheme we adopt for the L1 is flexible enough that 8130, or any future account system, can be built on top of it so that from the user's perspective the same account can work across L1 and L2s.
Authors of both EIPs, core devs, researchers, and testing teams have been working toward a solution that respects the imperative to get Account Abstraction in the next fork without delay but avoids fracturing ecosystem standards.
That said - Account Abstraction _will_ ship in Hegotá, so core devs decided today to move EIP-8141 from Considered to Scheduled today. This was made with the caveat that the version of Account Abstraction that ships in Hegotá may significantly change from what's on the Hegotá Meta EIP right now: potentially the EIP number, the transaction type, etc.
The move to Scheduled doesn't materially change the conversation that's been happening over the past few weeks or enshrine the current spec. When an EIP is proposed as a headliner and moved to Scheduled, it just signals an intention to make the fork schedule dependent on that feature being shipped. It's more common than not for the implementation to change significantly between being Scheduled and shipping.
Big appreciation to @_chunter of @base, @Offchain, @EthLabs_org, and client teams for moving the conversation forward. Progress is ongoing and can be followed at the AA breakouts on Tuesdays at 14:00 UTC or asynchronously on Forkcast.
Goodbye, Poseidon!
An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography.
Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs.
In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs.
The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive.
We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June.
With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value.
Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028.
As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming.
On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow.
Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :)
Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more.
Ultimate security. Uncompromising performance. Full programmability.
Believe in something. Believe in hashes.
SubEtha is now public.
Official website and developer docs for private x402 payments settled on zERC20.
AI agents pay APIs.
The payment is public.
The link is not.
Open-source local reference implementation.
Details below ↓