Vitalik Buterin Proposes EIP-8288 to Cut Quantum-Safe Privacy Costs 99%
In brief
- EIP-8288 moves heavy cryptography off Ethereum's execution path, cutting quantum-safe transaction costs by over 99%
- Proposal targets I-star fork and depends on Frames, a transaction overhaul Buterin promoted separately
- Adopting EIP-8288 establishes RISC-V as Ethereum's de facto standard for recursive proofs
The Cost Problem
Post-quantum signatures currently run to 2 or 3 kilobytes and cost 150,000 to 200,000 gas to verify. STARK proofs are worse, at over 128 kilobytes and as much as 512 kilobytes when generated quickly, putting verification in the millions of gas. Today, a well-engineered private transaction costs about 300,000 gas. Add quantum-safe protections and that bill jumps to roughly 10 million gas—a 33x increase that makes the technology impractical for most users.
How EIP-8288 Works
EIP-8288 works by not putting the cryptography on-chain at all. A transaction instead declares a dependency costing just 96 bytes. Mempool nodes collect those claims every second, generate a single recursive STARK proving all of them at once, and pass it on. Under this design, both private and quantum-safe transactions would land in the low tens of thousands of gas—a shift that makes quantum resistance practical.
RISC-V and Ethereum's Instruction Set
The proposal hinges on a deeper architectural choice. Recursive proofs need a common language to express statements in, and the leading candidate is RISC-V, an open instruction set used in chip design. Adopting EIP-8288 would make RISC-V Ethereum's de facto canonical instruction set—a big decision that should be taken carefully, Buterin said.
Buterin floated the same move in July in a Lean Ethereum roadmap that would rebuild almost every major protocol component over three or four years. He wants both EIP-8288 and Frames (a transaction overhaul he promoted separately) in I-star, the upgrade after Hegota, which he has said will be Ethereum's last before the Lean era begins.


