Ethereum Foundation protocol researchers used a Sept. 16 Reddit AMA to outline the trade-offs shaping Ethereum’s next phase, covering scaling, privacy, post-quantum security, formal verification, ETH issuance, and client funding. In ETHTAO’s summary of the session, one theme cut across nearly every answer: post-quantum migration is starting to set technical priorities for the next several years, while zero-knowledge proofs are moving deeper into account design, consensus, and privacy.
The summary also stressed that many of the answers reflected personal views from researchers rather than settled protocol decisions. That distinction matters throughout the discussion, because the AMA mixed completed work, proposals that still need approval, and longer-range research ideas.
Post-quantum security is becoming a protocol-wide planning problem
The Protocol team said its target is a post-quantum Ethereum L1 by December 2029. That goal spans the full stack. User accounts would need new signature schemes, the consensus layer would need alternatives to BLS signatures and aggregation, and the data availability layer would need to reduce or change its dependence on KZG.
As summarized by ETHTAO, those pieces have to move in coordination and are unlikely to fit into a single isolated upgrade. Even if the core protocol completes its migration, wallets, rollups, bridges, and applications would not automatically become post-quantum secure. Each of those systems would still need to review its own cryptographic dependencies and migrate separately.
Frames is presented as a key account-layer direction
One of the main account-layer changes discussed in the AMA was Frames, described as a way to make transaction validation logic programmable. Combined with related migration proposals, it could let users move accounts away from the current secp256k1 key model and keep changing signature schemes over time.
That flexibility matters because post-quantum cryptography is still evolving. The protocol, in this view, needs room to adapt rather than locking itself into a single permanent choice too early.
But adding support for a new signature scheme is not the same as making it cheap enough for broad use. Vitalik compared the cost of ECDSA signatures, which he said require about 4,000 gas in computation and data, with SPHINCS- post-quantum signatures, which he said could require roughly 100,000 to 250,000 gas depending on parameters. That gap is why later work would also need signature aggregation before transactions enter blocks, along with proofs that replace large amounts of raw data and computation. In the summary’s framing, those mechanisms could serve both post-quantum accounts and lower-cost private transactions.
L1-zkEVM work is moving closer to production
The AMA also highlighted growing overlap between L1-zkEVM work and post-quantum migration. Both tracks are using RISC-V zkVMs, which means investments in proving systems and optimization tooling can be reused across efforts. Over the past year, the work has advanced through execution specs, testing, client integration, and open-source tooling, according to the summary.
Several zkVMs have made progress on performance and security, and execution clients and proven programs are already being tested through block verification and execution witness generation. One near-term checkpoint is whether EIP-8025, which would introduce optional execution proofs, can make it into Hegotá and provide deployment experience for later stages.
Justin Drake sounded optimistic about real-time proving. He said the main performance risks have dropped sharply and noted that some teams believe they can prove the vast majority of mainnet blocks in about two seconds by 2027. Other answers were more cautious and focused on engineering constraints. Gas limits, new precompiles, and block structure would all change the proving burden, and if performance is not there, mandatory proving should be delayed. The summary added another caveat: state growth could become a scaling bottleneck before proving latency does.
This architecture also creates a decentralization trade-off. Proof generation may require specialized hardware, while proof verification can stay cheap. Ethereum’s aim is to keep ordinary validators from having to upgrade hardware every time execution throughput rises. That shifts attention to builder and prover concentration risk. Research directions mentioned in the summary include lowering the hardware threshold for individual provers and exploring distributed proving.
Privacy work is advancing in layers, not as a single package
Privacy was another major topic, and the summary argued that two apparently conflicting timelines were actually about different things. Some participants said native private transactions could be possible by 2027. Justin, by contrast, said the probability of a protocol-embedded privacy pool by the end of 2028 was close to zero. The first claim is about privacy applications using Ethereum’s public transaction rails directly. The second is about whether Ethereum should hard-code a unified privacy pool into the protocol.
The nearer-term path is closer to the first model. Through Frames, related account mechanisms, and FOCIL, privacy applications may be able to use the public mempool and protocol-level censorship resistance instead of relying as heavily on specialized relays. That would let Ethereum support multiple privacy applications without first choosing a single official privacy pool. If post-quantum privacy proofs can later be aggregated efficiently, cost and scale could improve again. Even so, the dates discussed in the AMA were still conditional targets or personal forecasts, not fixed roadmap commitments.
On the longer-term question of a built-in privacy pool, researchers did not line up behind one answer. Justin mentioned ideas including default-private staked ETH and a path for unstaked ETH to connect to the same system. Another respondent argued that immutable privacy applications deployed after future upgrades might already have properties close to a protocol-level pool, leaving open whether it would still be worth embedding one directly in Ethereum.
The summary also made clear that stronger L1 privacy would not make privacy-focused L2s irrelevant. Basic transfers, private stablecoins, private DeFi, and full private smart contract environments could still be handled by different systems.
Formal verification is building out a broader toolchain
If zero-knowledge systems are expanding what the protocol can do, formal verification is being used to strengthen the safety case around those changes. The post listed work on security proofs for some signature schemes, verification of zkVM circuit constraints, and efforts around EVM execution programs. The process has already helped teams find and fix real bugs, but end-to-end verification from cryptographic constructions and proving systems down to concrete execution programs is still unfinished.
The tooling stack is also getting broader. Clean is being used to describe circuits directly in Lean. hax and Aeneas help connect Rust implementations to formal specifications. VCVio and ArkLib provide foundations for cryptographic proofs. evm-asm is pushing toward verifiable execution programs. The summary said automated research and performance optimization are also starting to connect with proof systems, making it possible to subject optimized programs to stricter checks. That raises the odds that formal verification becomes part of routine development rather than something reserved for the final review stage.
Ethereum is still chasing faster finality, but on a different path
Ethereum’s push for speed is continuing, though the route has changed. Ben Edgington said in the AMA that the original path toward single-slot finality is, in his view, over. The broader goal of getting close to that user experience remains.
A newer decoupled consensus approach would allow finality to improve step by step instead of waiting for validator scale, networking, and signature aggregation problems to all be solved at once. In his estimate, an early phase could cut finality from about 16 minutes to about 4 minutes, with a longer-term goal of finality in roughly one to two slots.
ETH issuance remains a social and economic dispute, not a settled policy
Technical design may be narrowing some protocol questions, but ETH issuance still appears to require much wider community agreement. Justin Drake and Anders Elowsson both said, in a personal capacity, that they support changes to the current issuance mechanism. Their concern is that ongoing staking incentives could place increasing relative pressure on holders who do not stake, pushing more users toward exchanges or liquid staking tokens and increasing contract, governance, and concentration risks.
The debate also reaches into ETH’s role in the broader economy. If more ETH is converted into staked claims carrying extra layers of risk, what happens to native ETH as money and collateral? Do businesses built around staking yield crowd out other DeFi experimentation? Would lower issuance make it harder for independent stakers to enter? The summary said those questions cannot be answered by comparing nominal annualized yields alone. They also require analysis of real participant costs and the composition of the staking set.
Backing reform does not mean a plan has been chosen. Anders said any issuance change would need a design with clear incentive effects, models that explain both total staking and participant composition, and open discussion of benefits and costs. Community members also raised objections about how urgent reform really is, who should convene the discussion, and whether current processes are sufficient. The AMA did not produce a policy conclusion that Ethereum had decided to cut issuance or cap the staking share.
EF’s organizational structure is expanding around coordination
The AMA also touched on organizational changes. According to the summary, Access Layer is beginning to take on application and developer support work above the protocol layer. Ethlabs members continue to participate in technical workshops and architecture discussions. Ethereum Institutional is working with researchers to explain the post-quantum roadmap and Strawmap to institutions.
The broader point was that the handoff between research, implementation, and applications will increasingly depend on sustained coordination across multiple teams. At the same time, the roadmap itself is still subject to revision, and researchers did not offer complete answers on L2 value capture, cross-chain liquidity, or privacy interoperability.

