Ethereum co-founder Vitalik Buterin outlined EIP-8288, a proposal for a recursive STARK mempool, and said he hopes it will be included in the I-star upgrade that follows Hegota. The proposal moves signatures and proofs out of Ethereum’s core execution path and recursively aggregates STARKs in the mempool, with the aim of reducing on-chain computation and data costs. According to Buterin, the design could enable low-cost quantum-safe signatures and privacy protocols. He said the cost of quantum-safe private transactions could fall from roughly 10 million gas to tens of thousands of gas. The proposal is also designed to work without changes to the Ethereum Virtual Machine, allowing compatibility with newer signature or proof systems such as Falcon and ML-DSA while also supporting private account abstraction. Under the proposed workflow, nodes would periodically aggregate transaction dependencies and generate recursive STARKs, while block builders would create proofs for transactions selected for inclusion. The added on-chain overhead per block would be about one 100 KB to 300 KB STARK plus 96 bytes of data for each claim being proven.
Ethereum co-founder Vitalik Buterin has presented EIP-8288, a proposal for a recursive STARK mempool, and said he wants it included in the I-star upgrade that comes after Hegota.
How EIP-8288 is designed
The proposal moves signatures and proofs outside Ethereum’s core execution path and recursively aggregates STARKs in the mempool. The goal is to lower on-chain computation and data costs.
Buterin said the approach could support low-cost quantum-safe signatures and privacy protocols. In his description, the cost of quantum-safe private transactions could drop from about 10 million gas to tens of thousands of gas.
Compatibility and execution flow
The design would work without modifying the Ethereum Virtual Machine, making it compatible with newer signature or proof systems including Falcon and ML-DSA. It would also support private account abstraction.
Under the proposal, nodes would periodically aggregate transaction dependencies and generate recursive STARKs. Block builders would then generate proofs for the transactions they plan to include in a block.
The additional on-chain overhead for each block would be about one STARK of 100 KB to 300 KB, plus 96 bytes of data for each claim that needs to be proven. Buterin also said the proposal could help push Ethereum toward adopting RISC-V as the standard instruction set for recursive STARKs.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.