Vitalik says EIP-8288 should be included in Ethereum’s I-star upgrade to cut quantum-safe transaction costs
Ethereum co-founder Vitalik Buterin outlined EIP-8288, a proposal for a recursive STARK mempool, and said he hopes it will be included in the I-star upgrade that follows Hegota. The proposal moves signatures and proofs out of Ethereum’s core execution path and recursively aggregates STARKs in the mempool, with the aim of reducing on-chain computation and data costs. According to Buterin, the design could enable low-cost quantum-safe signatures and privacy protocols. He said the cost of quantum-safe private transactions could fall from roughly 10 million gas to tens of thousands of gas. The proposal is also designed to work without changes to the Ethereum Virtual Machine, allowing compatibility with newer signature or proof systems such as Falcon and ML-DSA while also supporting private account abstraction. Under the proposed workflow, nodes would periodically aggregate transaction dependencies and generate recursive STARKs, while block builders would create proofs for transactions selected for inclusion. The added on-chain overhead per block would be about one 100 KB to 300 KB STARK plus 96 bytes of data for each claim being proven.








