Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good

A contributor's draft would make the validator deposit contract variable length and add a mode to end BLS signatures permanently. It is unfinished, unnumbered, and aimed at a 2029 target that may move.

The Investor · Invest desk

How we use AISend a correction

What happened

  • Ethereum contributor Kevaundray Wedderburn opened a draft EIP that would replace the validator deposit contract with a variable-length version.
  • The same draft carries a mode to retire BLS signatures irreversibly, as a step toward quantum-safe consensus keys.
  • The draft is awaiting one more editor review, and an editor has asked for its placeholder number to be reassigned to 8394.

Why it matters

  • constraint An irreversible retirement mode means the code that flips it has no rollback path, so its error budget is nothing like a routine parameter change.
  • cost Bigger validator signatures are paid for in bandwidth and storage by whoever runs nodes, not by the Foundation writing the specification.
  • decision Staking operators and custodians now have a validator key-format migration on a calendar set by protocol scheduling rather than their own upgrade cycles.
  • exposure One year of clearance over NIST's ECDSA deprecation date is thin for a movable target, and slippage puts Ethereum's account-level cryptography past a regulator's own deadline.

The mechanical problem is a schema mismatch. Ethereum's deposit contract has fixed-size fields, post-quantum validator keys do not fit inside them, so the draft makes the fields variable length and puts the irreversible BLS off switch in the same document [6][2].

The sizes are where the cost lives. BLS signatures run 96 bytes; leanXMSS, the hash-based scheme the Ethereum Foundation has picked as the replacement, runs close to 3,000 [12]. That is about a 31-fold increase per signature [21], landing on a consensus layer whose current efficiency comes from folding hundreds of thousands of validator signatures into one, according to ethereum.org's quantum-resistance page [10]. Cryptopolitan's account of the draft does not say whether the hash-based scheme preserves that aggregation. Until someone publishes that, the 31x figure is a floor on per-signature growth and tells you nothing final about per-slot bandwidth.

Nothing here is near shipping. Wedderburn says the draft is unfinished and that large portions are boilerplate covering EIP-7685 mechanics [4], and it still has to be blended with validator EIPs 7251, 7002 and 8282 [5]. It was filed as pull request 12235 in the ethereum/EIPs repository, with Thomas Coratger and Tom Wambsgans listed as co-authors [3][7]. Merging four validator EIPs into one coherent deposit path is the gate on the schedule, not editor review.

And this is one quarter of the job. Vitalik Buterin's February 2026 roadmap set out four workstreams: validator BLS signatures, KZG commitments behind data availability, the ECDSA signatures guarding ordinary accounts, and the zero-knowledge proof systems rollups depend on [16]. Core layer-1 quantum upgrades are targeted for roughly 2029, which both ethereum.org and Cryptopolitan describe as a planning goal that could move [15]. NIST plans to deprecate ECDSA by 2030 and disallow it by 2035 [14], so the current target leaves one year of clearance on the first date and six on the second [22].

The Foundation is not treating this as speculative work. It named a dedicated post-quantum team in January 2026, with Coratger among its leaders [18], and attached a $1 million Poseidon Prize for hardening a hash function on top of an earlier $1 million Proximity Prize [19], or $2 million in bounties for cryptographic groundwork [23]. Justin Drake called the effort a "top strategic priority" [20].

The threat itself has not arrived. Machines capable of running Shor's algorithm against elliptic curve cryptography do not exist anywhere [11], but a March 2026 Google Quantum AI document cut the estimated cost of breaking the 256-bit curve Ethereum uses by around 20 times, per ethereum.org [13]. That is what turns a research topic into a deposit contract rewrite with a switch that only turns one way.

What to watch

  • Whether EIP-8141 makes the Hegota upgrade, which would put ordinary-account protection in the queue ahead of validator keys.
  • Client teams publishing measured bandwidth and storage figures for hash-based validator signatures on a test network.
  • Any restatement of the roughly 2029 target once the deposit-contract draft is reconciled with the existing validator EIPs.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence54
Adoption10
Hype gap+18
Incentives55
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Ethereum contributor Kevaundray Wedderburn opened a draft EIP for a variable-length validator deposit contract.

  2. [2]

    The draft includes a mode to irreversibly retire BLS signatures, described as a step toward quantum-safe consensus keys.

  3. [3]

    The draft was filed as pull request 12235 in the ethereum/EIPs repository.

Sources

1 independent publisher whose own reporting we read for this story.

  1. cryptopolitan.com

    1 article · August 25, 2026

    Ethereum developers advance post-quantum readiness with deposit contract proposal

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories