Vitalik Buterin used the opening ceremony of the 2026 Hong Kong Web3 Carnival to lay out Ethereum’s roadmap, centering on zkEVM, preparation for a post-quantum future, and reducing transaction finality to 10 to 20 seconds. The speech came just two days after a major DeFi exploit drained $292 million from a bridge and triggered $6.6 billion in outflows from Aave.
On stage, Buterin described Ethereum as a “world computer” rather than a payments chain competing on transactions per second. His framing focused on verifiable data, shared digital assets, and a system where users retain control over their own security.
A three-layer plan for Ethereum
Buterin said Ethereum’s short-term agenda includes increasing the gas limit, rolling out zkEVM, and starting work for the post-quantum era. In his outline, zkEVM is not only a scaling tool. It is also a way to support more complex computation while keeping on-chain activity verifiable.
The mid-term target is to reduce finality. He said the process currently takes about 16 minutes, while the goal is to bring that down to 10 to 20 seconds. That would sharply change how quickly transactions reach a confirmed end state on Ethereum.
The long-range vision is broader: full quantum resistance, formal verification across the protocol, and stronger decentralization. Buterin said he wants Ethereum to become a chain that anyone can verify on any device, including phones and IoT hardware.
“Verify before you trust”
Explaining the technical direction, Buterin said zkVM makes it possible to verify the chain without depending on a large computer to run every operation directly. He added that people should verify the chain before trusting it, and that even phones and IoT devices should be able to do so.
That message fits Ethereum’s long-running stance. Rather than chasing raw throughput, Buterin presented the network as infrastructure built around verifiability and decentralization. The roadmap answered familiar criticism over Ethereum’s pace by returning to the same point: trust comes first.
The $292 million exploit sharpened the contrast
The rsETH attack on April 18 exposed the kind of cross-chain bridge complexity Ethereum has historically treated cautiously. According to the source material, the attacker exploited a single-verifier setup on a LayerZero bridge, minted 116,500 unbacked rsETH tokens, used them as collateral on Aave, and withdrew real ETH.
The damage spread quickly through DeFi. Markets were frozen, depositors were trapped, and the event reopened questions around composability risk. Buterin did not address the hack directly in the speech, yet the roadmap’s stress on security, verifiability, and decentralization closely matched the weaknesses exposed by the incident.

