InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good
A contributor's draft would make the validator deposit contract variable length and add a mode to end BLS signatures permanently. It is unfinished, unnumbered, and aimed at a 2029 target that may move.
The Investor · Invest desk
What happened
- Ethereum contributor Kevaundray Wedderburn opened a draft EIP that would replace the validator deposit contract with a variable-length version.
- The same draft carries a mode to retire BLS signatures irreversibly, as a step toward quantum-safe consensus keys.
- The draft is awaiting one more editor review, and an editor has asked for its placeholder number to be reassigned to 8394.
Why it matters
- constraint An irreversible retirement mode means the code that flips it has no rollback path, so its error budget is nothing like a routine parameter change.
- cost Bigger validator signatures are paid for in bandwidth and storage by whoever runs nodes, not by the Foundation writing the specification.
- decision Staking operators and custodians now have a validator key-format migration on a calendar set by protocol scheduling rather than their own upgrade cycles.
- exposure One year of clearance over NIST's ECDSA deprecation date is thin for a movable target, and slippage puts Ethereum's account-level cryptography past a regulator's own deadline.
The mechanical problem is a schema mismatch. Ethereum's deposit contract has fixed-size fields, post-quantum validator keys do not fit inside them, so the draft makes the fields variable length and puts the irreversible BLS off switch in the same document [6][2].
The sizes are where the cost lives. BLS signatures run 96 bytes; leanXMSS, the hash-based scheme the Ethereum Foundation has picked as the replacement, runs close to 3,000 [12]. That is about a 31-fold increase per signature [21], landing on a consensus layer whose current efficiency comes from folding hundreds of thousands of validator signatures into one, according to ethereum.org's quantum-resistance page [10]. Cryptopolitan's account of the draft does not say whether the hash-based scheme preserves that aggregation. Until someone publishes that, the 31x figure is a floor on per-signature growth and tells you nothing final about per-slot bandwidth.
Nothing here is near shipping. Wedderburn says the draft is unfinished and that large portions are boilerplate covering EIP-7685 mechanics [4], and it still has to be blended with validator EIPs 7251, 7002 and 8282 [5]. It was filed as pull request 12235 in the ethereum/EIPs repository, with Thomas Coratger and Tom Wambsgans listed as co-authors [3][7]. Merging four validator EIPs into one coherent deposit path is the gate on the schedule, not editor review.
And this is one quarter of the job. Vitalik Buterin's February 2026 roadmap set out four workstreams: validator BLS signatures, KZG commitments behind data availability, the ECDSA signatures guarding ordinary accounts, and the zero-knowledge proof systems rollups depend on [16]. Core layer-1 quantum upgrades are targeted for roughly 2029, which both ethereum.org and Cryptopolitan describe as a planning goal that could move [15]. NIST plans to deprecate ECDSA by 2030 and disallow it by 2035 [14], so the current target leaves one year of clearance on the first date and six on the second [22].
The Foundation is not treating this as speculative work. It named a dedicated post-quantum team in January 2026, with Coratger among its leaders [18], and attached a $1 million Poseidon Prize for hardening a hash function on top of an earlier $1 million Proximity Prize [19], or $2 million in bounties for cryptographic groundwork [23]. Justin Drake called the effort a "top strategic priority" [20].
The threat itself has not arrived. Machines capable of running Shor's algorithm against elliptic curve cryptography do not exist anywhere [11], but a March 2026 Google Quantum AI document cut the estimated cost of breaking the 256-bit curve Ethereum uses by around 20 times, per ethereum.org [13]. That is what turns a research topic into a deposit contract rewrite with a switch that only turns one way.
What to watch
- Whether EIP-8141 makes the Hegota upgrade, which would put ordinary-account protection in the queue ahead of validator keys.
- Client teams publishing measured bandwidth and storage figures for hash-based validator signatures on a test network.
- Any restatement of the roughly 2029 target once the deposit-contract draft is reconciled with the existing validator EIPs.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence54
- Adoption10
- Hype gap+18
- Incentives55
- Confidence52
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ethereum contributor Kevaundray Wedderburn opened a draft EIP for a variable-length validator deposit contract.
- [2]
The draft includes a mode to irreversibly retire BLS signatures, described as a step toward quantum-safe consensus keys.
- [3]
The draft was filed as pull request 12235 in the ethereum/EIPs repository.
- [4]
Wedderburn specified that the draft is unfinished and that large portions are boilerplate covering EIP-7685 mechanics.
- [5]
Wedderburn said the team still has to blend the draft with existing validator EIPs 7251, 7002 and 8282.
- [6]
Length-flexible contracts plus a switch that ends BLS for good resolve the problem of fitting the new larger keys into a deposit contract with fixed-size fields.
- [7]
The draft lists Thomas Coratger and Tom Wambsgans as co-authors.
- [8]
The draft plan to integrate quantum-safe keys into the validator deposit contract was presented on August 24 as part of the Ethereum Foundation's post-quantum readiness push for mainnet.
- [9]
The Ethereum Foundation's bot lists the draft as awaiting one more editor review, and an editor has asked that its placeholder number be reassigned to 8394 before it can advance.
- [10]
Ethereum validators currently sign with BLS, which relies on elliptic curve pairings and combines hundreds of thousands of signatures into one to keep consensus efficient, per ethereum.org's quantum-resistance page.
- [11]
A quantum computer running Shor's algorithm can solve the elliptic curve math BLS relies on, but such machines do not exist anywhere in the world right now.
- [12]
The Ethereum Foundation's fix is leanXMSS, a hash-based scheme that swaps BLS's 96-byte signatures for nearly 3,000 bytes.
- [13]
A March 2026 Google Quantum AI document slashed the cost of breaking the 256-bit elliptic curve cryptography Ethereum uses by about 20 times, per ethereum.org.
- [14]
NIST plans to deprecate ECDSA by 2030 and disallow it by 2035.
- [15]
Core layer-1 quantum upgrades are targeted for around 2029, a date both ethereum.org and Cryptopolitan describe as a planning goal that could still move.
- [16]
In a February 2026 roadmap, Vitalik Buterin set out four post-quantum workstreams: validator BLS signatures covering deposit contracts, KZG commitments behind data availability, ECDSA signatures guarding ordinary accounts, and zero-knowledge proof systems used by rollups.
- [17]
EIP-8141, a separate proposal to migrate users to quantum-safe signatures, is under consideration for the Hegota upgrade and is expected to handle account-level protection through native account abstraction.
- [18]
The Ethereum Foundation named a dedicated post-quantum team in January 2026, and Thomas Coratger is a leader on that team.
- [19]
The Foundation attached a $1 million Poseidon Prize to hardening a hash function, on top of an earlier $1 million Proximity Prize.
- [20]
Justin Drake described the Foundation's post-quantum efforts as a "top strategic priority".
- [21]
Moving from 96-byte BLS signatures to nearly 3,000-byte leanXMSS signatures is roughly a 31-fold increase in per-signature size.
- [22]
The roughly 2029 target for core L1 quantum upgrades sits one year before NIST's 2030 ECDSA deprecation date and six years before its 2035 disallow date.
- [23]
The Poseidon Prize and the earlier Proximity Prize together total $2 million.
Sources
1 independent publisher whose own reporting we read for this story.
- cryptopolitan.comEthereum developers advance post-quantum readiness with deposit contract proposal
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Ethereum protocol upgradesFollow
- Cryptographic key migrationFollow
- Post-Quantum CryptographyFollow
- Validator infrastructureFollow
Entities
- EthereumFollow
- Ethereum FoundationFollow
- Kevaundray WedderburnFollow
- Thomas CoratgerFollow
- Tom WambsgansFollow
- Vitalik ButerinFollow
- Justin DrakeFollow
- BLS signature schemesFollow
- leanXMSSFollow
- ECDSAFollow
- EIP-8141Follow
- EIP-7685Follow
- National Institute of Standards and TechnologyFollow
- Google Quantum AIFollow
- Hegotá upgradeFollow
- Shor's AlgorithmFollow