The Next Phase of Ethereum from the EF Protocol AMA
Author: SNZ Holding, ETHTAO
This article is compiled from the AMA held by EF researchers on Reddit with the community on September 16. The original AMA record can be found at: https://www.reddit.com/r/ethereum/comments/1wf48x3/comment/p9pw3pv/
Quantum Resistance Across All Aspects
On September 16, 2026, the Protocol team of the Ethereum Foundation held a new round of AMA on Reddit. The discussion covered scalability, privacy, quantum resistance, formal verification, ETH issuance, and client funding. By putting these answers together, a gradually clearer main line can be seen: Quantum migration is influencing Ethereum's technical priorities for the next few years, while ZK proofs are increasingly involved in the design of accounts, consensus, and privacy. Meanwhile, progress on the technical roadmap has not eliminated differences in economic policy and governance.
The value of this AMA lies in the researchers explaining both the ongoing work and the trade-offs and differing judgments. Many answers clearly belong to personal opinions, so understanding this discussion requires consistently distinguishing between achieved results, pending upgrade proposals, and longer-term research ideas.
Quantum security is the starting point for understanding these trade-offs. The goal proposed by the Protocol team is to achieve a quantum-resistant Ethereum L1 by December 2029. This goal involves the entire chain: user accounts need a new signature mechanism, the consensus layer needs to replace BLS signatures and aggregation methods, and the data availability layer also needs to adjust its reliance on KZG. Work at different levels must coordinate with each other, making it difficult to complete through a single isolated upgrade. The core protocol's migration will not automatically grant quantum resistance to wallets, Rollups, bridges, and applications; these systems still need to check their cryptographic dependencies and migrate individually.
Frame Transaction is All You Need - The Final Answer to Account Abstraction
The key change at the account layer is Frames, which makes transaction verification logic programmable. Combined with related migration proposals, users will have the opportunity to free their accounts from the control of the original secp256k1 keys and continue to change signature schemes in the future. This flexibility is important because quantum-resistant technology is still evolving, and the protocol needs to leave room for different schemes to evolve.
However, there is still a significant distance between supporting a new signature and making it cheap and usable. Vitalik compared in his response that the computational and data costs of ECDSA signatures are about 4,000 gas, while SPHINCS- quantum-resistant signatures require about 100,000 to 250,000 gas, depending on the parameters. Therefore, subsequent work also includes aggregating signatures before transactions enter blocks and replacing large amounts of raw data and computation with proofs. Such a mechanism serves both quantum-resistant accounts and may also reduce the cost of privacy transactions.
ZK-EVM Begins to Enter Practical Production
The intersection of L1-zkEVM and quantum migration has also led to more technical overlaps. Both routes are leveraging RISC-V zkVM, and investments in proof systems and optimization tools can be reused. Over the past year, related work has advanced to execution specifications, testing, client integration, and open-source tool development. Multiple zkVMs have made progress in performance and security, and executing clients and proven programs are also undergoing tests such as block validation and execution witness generation. A current important milestone is whether the optional execution proof EIP-8025 can be incorporated into Hegotá to accumulate experience for subsequent deployment.
Justin Drake is quite optimistic about real-time proofs. He believes that the main performance risks have significantly decreased and mentions that some teams are optimistic about achieving proof for the vast majority of mainnet blocks in about two seconds by 2027. However, other responses emphasize engineering conditions: gas limits, new precompiles, and block structure will all change the proof burden, and if performance is insufficient, mandatory proof should be postponed. State growth may also become a scaling bottleneck earlier than proof delays. Performance breakthroughs are expanding optional solutions, and the mainnet launch still requires complete security and integration work.
This architecture also brings a decentralized trade-off. Generating proofs may require specialized hardware, but verifying proofs can be very cheap. Ethereum hopes to allow ordinary validators not to have to continuously upgrade their devices as execution throughput increases through this division of labor. Correspondingly, the centralization risks of builders and provers need to be seriously addressed, with research directions including lowering the hardware threshold for individual provers and exploring distributed proofs.
Privacy Progressing in an Ordered Manner, Many Basic Works Still Need to Be Completed
Privacy is advancing based on these accounts and proof capabilities. The seemingly contradictory statements in this AMA actually point to different levels: some believe that native privacy transactions are expected to be supported by 2027, while Justin believes that the probability of achieving a protocol-built privacy pool before the end of 2028 is close to zero. The former discusses how privacy applications can directly use Ethereum's public transaction channels, while the latter discusses whether to write a unified privacy pool into the protocol.
The recent goals are closer to the former. Through Frames, related account mechanisms, and FOCIL, privacy application transactions are expected to utilize public mempool and the anti-censorship capabilities provided by the protocol, reducing reliance on dedicated relays. Ethereum can thus support various privacy applications without having to designate a single official privacy pool first. If efficient aggregation of quantum privacy proofs can be achieved in the future, it may further improve costs and scale. The relevant years remain conditional goals or personal predictions.
Whether a built-in privacy pool is needed in the long term is still a matter of different considerations among researchers. Justin has mentioned the idea of default privacy for staked ETH and allowing unstaked ETH to access this system; other respondents believe that immutable privacy applications after the upgrade may already possess attributes close to a protocol-built pool, so whether it is worth continuing to write it into the protocol still needs discussion. Enhancing L1 privacy capabilities does not mean that privacy L2 loses its effectiveness: basic transfers, privacy stablecoins, privacy DeFi, and a complete privacy contract environment may still be handled by different systems.
Promising Development of Formal Verification
If ZK is expanding what the protocol can do, formal verification is providing stronger security foundations for these changes. The post lists some security proofs of signature schemes, verification of zkVM circuit constraints, and related work on EVM execution programs. The verification process has already helped teams discover and fix real errors, but end-to-end verification covering cryptographic constructions, proof systems, and specific execution programs is still incomplete.
It is worth noting that this work is forming a more complete toolchain. Clean attempts to directly describe circuits in Lean; hax and Aeneas help connect Rust implementations to formal specifications; VCVio and ArkLib provide the basis for cryptographic proofs; and evm-asm advances verifiable execution programs. Automated research and performance optimization have also begun to combine with proofs, allowing optimized programs to undergo rigorous checks. This makes formal verification more likely to enter daily development rather than just appearing in the review phase after development ends.
A Faster Ethereum is on the Way
Ethereum's pursuit of speed is also adapting to these new constraints. Ben Edgington stated in his response that the initially envisioned single slot finality path has ended in his view, but the goal of approaching this experience is still retained. The new decoupled consensus approach allows for gradual improvement of finality without having to wait for the validator scale, network, and signature aggregation issues to be resolved simultaneously. He expects that the early stages may reduce the finality time from about sixteen minutes to about four minutes, with a long-term goal of achieving finality at one to two slot levels.
Monetary Policy Requires Broader Community Consensus
While technical design can continuously narrow the scope of issues, the ETH issuance policy still requires broader social consensus. Justin Drake and Anders Elowsson both explicitly support adjusting the current issuance mechanism in their personal capacities. They are concerned that ongoing staking incentives will put increasing relative pressure on non-staked holders, pushing more users toward exchanges or liquid staking tokens, and increasing contract, governance, and centralization risks.
This debate also involves the role of ETH in the economy. If more and more ETH is converted into staking certificates with additional risks, how will the status of native ETH as currency and collateral change? Will the business around staking yields crowd out other DeFi innovations? Will reducing issuance make it harder for independent stakers to enter? These questions cannot be answered solely by comparing nominal annualized yields; they also require analyzing the actual costs for participants and the composition of stakers.
Supporting reform does not mean that a plan has already been determined. Anders emphasized that adjusting issuance requires designs with clear incentive effects, models that can explain the total amount of staked ETH and the composition of participants, and open discussions on yields and costs. Community members have raised objections regarding the urgency of reform, who will convene discussions, and whether existing processes are sufficient. The AMA did not reach a policy conclusion to reduce issuance or limit staking ratios.
New Organizational Structure at EF, Dedicated Teams to Collaborate with the Community
Collaboration at the organizational level is also expanding. The Access Layer has begun to take on application and developer support work above the protocol, Ethlabs members continue to participate in technical discussions and architectural discussions, and Ethereum Institutional collaborates with researchers to explain the quantum-resistant roadmap and Strawmap to institutions. The future connection between research, implementation, and application will increasingly rely on continuous collaboration among multiple teams. Meanwhile, the roadmap itself will still be revised, and researchers have not provided complete answers to issues such as L2 value capture, cross-chain liquidity, and privacy interoperability.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like
![[Digital Bill of Rights③] Money Written by AI, "Make it Usable in Real Life"](/public-static/052_26710392f0.png?format=avif)
[Digital Bill of Rights③] Money Written by AI, "Make it Usable in Real Life"
![[Digital Bill of Rights②] The Success of Digital Dollar Comes from Competition](/public-static/078_4d1ce66fab.png?format=avif)
[Digital Bill of Rights②] The Success of Digital Dollar Comes from Competition

OKX Star Points Out THORChain TSS + Validator Model Lacks Decentralization

Costa Rica warns about crypto assets in political financing and strengthens its controls

Saylor: The era of intelligence and digital assets needs a bill of rights

Bitcoin at $84,000 Despite US-Iran Stalemate

Balancer fork’s 6 million BAL ask could cut holders’ redemption value

Fed stablecoin proposal would make circulation a capital cost for supervised issuers

OG.com Submits Application for US Stock Perpetual Contracts to CFTC Following Coinbase, Kalshi, and Kraken's Parent Company Payward

Solana’s Alpenglow upgrade reaches devnet with 150ms finality target

Bull Signal for Bitcoin: In 4 out of 5 Past Instances, Prices Increased

唐华斑竹: Quantum Computing Becomes a Core Risk Point in the Cryptocurrency Field

DeltaForesight Announces Completion of 324 Million Yen Financing to Develop Over-Collateralized Yen Stablecoin JPYdf

IBEX 35 Outlook 2026: Can Spain's Stock Market Reach 20,000 Again?

Goldman Sachs: AI Capital Expenditure to Reach $1.73 Trillion in 2026-2027

Federal Reserve Plans to Raise Regulatory Thresholds for Large Banks

Crypto in France: Binance, taxes, digital euro, what changes by 2027

LTC Airdrop 2026: How to Claim 50,000 USDT Rewards on WEEX

Dom Kwok Expects a Sudden Surge in Crypto Prices

Exclusive Interview with Frontier Technology Investor Zheng Di: SEC's 'Innovation Exemption' Opens the Door to a Compliant Bull Market, Which Assets Are Potential Stocks?

XRPL to Implement Major Upgrade on October 5: Adding Permission Delegation Feature

67% of the wealthy own digital assets, but the crypto adoption gap remains huge

How to Rewrite Internet Rules When Everyone Has an Indefatigable Agent

The End of the Blank Prompt: Why Trading AI Needs a Playbook

Cardano proposal slashes fees by 55%, but it comes with a cost for small pools

The Evolution of AI: The Boundaries and Truth of Recursive Self-Improvement (RSI)

The Quantum Issue: You Never Really Know The Future

Security and fees hold back deeper crypto use among wealthy investors: Nexo report

Bitcoin Developers Concerned About Mining Subsidy









