Ethereum developers have proposed EIP-8394, a draft upgrade to rebuild the network's validator deposit contract to support variable-length keys up to 8,192 bytes. This change lays the groundwork to secure Ethereum's $104 billion staking layer against future quantum computing threats. Current BLS signatures are vulnerable to quantum systems, which experts estimate could break elliptic-curve cryptography between 2028 and 2035. The proposal introduces a migration switch to eventually disable BLS-based deposits permanently.
EIP-8394 deposit contract redesign
- ▪Ethereum developers proposed a draft Ethereum Improvement Proposal, suggested to be numbered EIP-8394, to rebuild the validator deposit contract to support multiple signature schemes and variable-length public keys.
- ▪The proposed EIP-8394 contract redesign replaces the hardcoded BLS12-381 dimensions with support for keys and credential metadata of up to 8,192 bytes each.
- ▪The proposed EIP-8394 contract introduces an irreversible retirement mode that, once activated, permanently disables new deposits secured by existing BLS signatures.
- ▪The proposed EIP-8394 contract retires the deposit-processing system used since 2022, transferring deposits onto the newer framework handling withdrawals and validator changes.
Quantum computing threat timeline
- ▪A May 2026 report by quantum security firm Project Eleven estimated the odds of a quantum machine capable of breaking elliptic curve signatures at better than even by 2033, with 2030 possible.
- ▪Google Quantum AI estimated that approximately 1,200 logical qubits could break 256-bit elliptic-curve cryptography, lowering previous threshold estimates.
- ▪Estimates for 'Q-Day,' when quantum systems could break elliptic-curve cryptography, range between 2028 and 2035, with the Ethereum Foundation targeting 2029 for core quantum-resistant upgrades.
BLS signature vulnerability
- ▪A quantum attack on BLS signatures could allow attackers to forge validator signatures, manipulate consensus, or steal staked funds.
- ▪According to an analysis by Project Eleven, more than 65% of all ETH sits in addresses whose public keys are already exposed on-chain.
- ▪Ethereum's current staking system secures approximately 42.4 million staked ETH, worth roughly $104 billion, using BLS cryptographic signatures vulnerable to quantum attacks.
Post-quantum cryptography migration challenges
- ▪Ethereum developer Thomas Coratger noted that Bitcoin and Ethereum are leaning toward hash-based signatures, where stateless standardized versions require roughly 8KB of space.
- ▪The proposed EIP-8394 upgrade requires a coordinated fork across both the execution and consensus layers of Ethereum to take effect.
- ▪The EIP-8141 Frame Transactions proposal under consideration for the Hegotá upgrade would allow ordinary Ethereum accounts to change their transaction cryptography without changing addresses.
- ▪Post-quantum signature schemes like CRYSTALS-Dilithium or SPHINCS+ produce keys and signatures that are significantly larger than current BLS equivalents, requiring larger contract storage capacity.
Staking ecosystem exposure
- ▪A sudden cryptographic cutover would be operationally catastrophic for liquid staking protocols that manage large pools of staked ETH on behalf of users.
- ▪Restaking protocols built on top of Ethereum, such as EigenCloud which reports a total value locked of approximately $4.592 billion, face cascading exposure if base-layer cryptography is compromised.
Story comments
Loading comments…