Key TakeawaysEthereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together blockKey TakeawaysEthereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together block

Vitalik Says Ethereum Is Becoming a Cryptographic World Computer: What Changes After Hegota

 
 
 
Key Takeaways
Ethereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together blockchains and modern cryptography" and writing on X that "it's really not just a blockchain anymore." Buterin frames the blockchain label as one Ethereum carries largely for historical reasons, and he positions Hegota, the hard fork planned for 2027, as the network's last conventional upgrade before recursive STARKs, automated formal verification, optimized consensus and quantum-safe cryptography take over the roadmap. His stated formulation is that starting after Hegota, this transformation becomes Ethereum's primary story. The 2030 targets he sets out are 4-to-8-second slots and 8-to-32-second finality, measured against roughly 17-second blocks and around 200 seconds for twelve confirmations in the original design. FOCIL, catalogued as EIP-7805, is the one headline feature currently scheduled for inclusion in Hegota, and it puts censorship resistance in the hands of sixteen pseudorandomly drawn validators per slot. EIP-8288, authored by Buterin and Thomas Coratger and created in June 2026, addresses the cost problem that quantum-safe signatures and STARK proofs create by aggregating them into a single recursive proof in the block header. The quantum work targets December 2029 across execution, consensus and data layers.
 
 

Overview

Ethereum has spent a decade being described with a word that its own creator now treats as a historical accident. In an essay published, Vitalik Buterin argued that the network is becoming a cryptographic world computer, a system in which mathematical proofs, off-chain computation and privacy machinery carry work that the base chain once had to perform itself. He posted the piece as an attempt to express in concise terms the meaning of everything planned for Ethereum starting from the fork after Hegota. The essay is a framing document, and its practical content sits in three places: what the network stops doing, what replaces it, and when. Ethereum stops asking every participant to re-execute every transaction, because SNARK and STARK verification lets a node check a proof that computation was performed correctly.
 

1. What the Essay Argues

Buterin's central claim is that Ethereum's architecture has already stopped matching the category it is filed under. His words on X were direct: "It's really not just a blockchain anymore. It's a hybrid architecture that combines together blockchains and modern cryptography." In the essay he goes further, describing the blockchain designation as something Ethereum retains to a large extent for historical reasons.
 
 
The argument rests on what a blockchain was originally for. Satoshi Nakamoto's design solved a coordination problem by making every participant repeat every calculation, then agree on the result. Redundancy was the security model. Anything a node could not independently verify by redoing the work was, by construction, untrusted. That requirement set the ceiling on throughput, dictated hardware requirements, and made privacy structurally impossible, since verification required visibility.
What Buterin describes as the hybrid architecture keeps the Satoshian core and attaches to it a set of tools that did not exist, or had not matured, when Bitcoin launched in 2009. Succinct proofs let one party prove a computation was performed correctly and let everyone else verify the proof at a fraction of the cost of redoing the work. Data availability sampling lets a node confirm that data was published without downloading it. Encrypted computation lets participants operate on inputs they cannot read. Each of these breaks a different piece of the original trade-off, and taken together they change what the base layer needs to do at all.
His framing of the consequence is that decentralization stops being purely defensive. In the original design, distributing the network was the price paid for censorship resistance, and every performance characteristic suffered for it. In the architecture he outlines, distributing data storage, computation and privacy work across many parties improves performance, because the parties are no longer duplicating each other. Structuring computation, in his phrasing, lets the blockchain more effectively focus on its job.
 

2. Why Proofs Change the Constraint

The technical pivot underneath all of this is verification cost. A SNARK or a STARK is a proof that a computation was executed correctly, and checking one is orders of magnitude cheaper than performing the computation. Once that gap is wide enough and the proving side is fast enough, the question of what a blockchain must do narrows sharply.
Under proof-based verification, the chain's remaining jobs are ordering transactions, guaranteeing that the data behind them was published, and confirming proofs. Execution itself can happen anywhere, including on hardware the network has never seen, provided the result arrives with a valid proof attached. This is the same logic that ZK rollups already run on, applied to the base layer itself.
PeerDAS handles the second job. It shipped in Fusaka in December 2025, and it lets validators sample small portions of blob data to gain high statistical confidence that the full dataset was published, without any individual validator carrying the whole thing. The user draft placed PeerDAS among future upgrades; it has been live on mainnet for most of a year, and it is the piece of the hybrid architecture that already works in production.
Recursive STARKs are where the essay points for the rest. Recursion means a proof can attest to the validity of other proofs, which lets many separate claims collapse into one object of fixed size. That property is what makes aggregation viable at protocol level, and it is the mechanism behind both the quantum-safety plan and the signature-cost work described further below. Buterin pairs it with automated formal verification, which addresses a second-order problem: a proof system that is itself buggy verifies incorrect computation with full confidence, so the cryptographic stack needs machine-checked correctness guarantees of its own.
 

3. Hegota, and the Forks Around It

Glamsterdam is expected in Q4 2026, having already slipped from earlier targets. Hegota follows it, planned for 2027, and it cannot begin testnet work until Glamsterdam ships, which means any further delay in Glamsterdam cascades forward. Buterin's line is that Hegota is likely to be Ethereum's last normal fork, the last upgrade that would look structurally familiar to a developer who has been building on the chain since 2015.
Hegota's scope is narrower. FOCIL, catalogued as EIP-7805, is the single headline feature currently marked as scheduled for inclusion. FOCIL pseudorandomly selects sixteen validators per slot to assemble inclusion lists of pending transactions. Proposers and builders must include the transactions on those lists, and a block that omits them does not gather the votes it needs to be canonical. The censorship calculus changes accordingly: an adversary attempting to keep a transaction out would have to neutralise a freshly drawn group of sixteen validators every slot, indefinitely.
The problem it addresses is a practical one; Block construction on Ethereum is concentrated among a small number of sophisticated builders, and the ability of that layer to exclude transactions has been a live concern since proposer-builder separation became standard practice. FOCIL puts the guarantee back in the protocol instead of relying on builder goodwill. EIP-8141, which introduces frame transactions, sits at "considered for inclusion" and has not been confirmed. It is the native account abstraction proposal, and it is what would give Ethereum accounts flexible signing rules covering social recovery, spending limits, sponsored gas and quantum-resistant signature schemes. The user draft placed these capabilities in 2030; they are candidate features for a 2027 fork, and their inclusion is not settled. The Hegota meta-document, EIP-8081, remains in draft status, so the final scope is still open.
 

4. EIP-8288 and the Cost of Being Quantum-Safe

The most concrete engineering document behind the essay is EIP-8288, authored by Buterin and Thomas Coratger, created on June 3, 2026 and currently in draft status as a core standards-track proposal. It exists because the cryptography Ethereum needs for quantum safety and privacy is expensive in ways that would break the network if deployed naively.
The numbers in the proposal state the problem plainly. Hash-based post-quantum signatures run to roughly 2 to 3 kilobytes each and cost somewhere between 150,000 and 200,000 gas to verify. STARK proofs all exceed 128 kilobytes. At those sizes, a block full of quantum-safe transactions consumes bandwidth and gas at rates that would make the network unusable, and privacy protocols that depend on STARKs would price themselves out entirely. FOCIL compounds the issue, since inclusion lists have to be propagated alongside everything else.
Gas accounting under the proposal is fixed and charged regardless of execution outcome: 3,000 gas per leanSPHINCS signature and 30,000 gas per leanSTARK. Set against the 150,000 to 200,000 gas that verifying a hash-based signature costs today, the reduction is the difference between quantum-safe transactions being a specialist option and being the default. The proof system uses Lean Ethereum tooling, keeping it consistent with the consensus layer work happening in parallel.
 

5. The 2030 Targets

Buterin's essay carries a comparison between Ethereum as it was designed in 2015 and what the roadmap targets for 2030.
The original network produced blocks roughly every 17 seconds, and an application waiting for twelve confirmations before treating a transaction as settled waited around 200 seconds. The 2030 target is 4-to-8-second slots with full finality in 8 to 32 seconds. That range comes from the lean consensus work, which moves Ethereum through single-slot finality toward Minimmit, a single-round consensus design that removes a communication round from the finality path. Buterin has described the scope of the Lean Ethereum effort as comparable to the Merge.
Compressing settlement from three minutes to under half a minute changes which applications can use the base layer directly. Tokenized securities settlement, institutional payment rails and any system that has to reconcile against traditional market infrastructure all operate on timing assumptions that 200 seconds violates and 30 seconds does not. The figure sits within the same range that conventional clearing systems target for intraday finality, which is the comparison institutional buyers actually make.
Hardware requirements move in the same direction. The 2015 architecture gave users two options, running a substantial full node or trusting a third party for everything. The 2030 target is that a participant can obtain optimal cryptographic guarantees on much lighter hardware, because proof verification replaces re-execution and data availability sampling replaces full data download. A wallet that checks a proof gets the same assurance as a machine that redid the work, which collapses the gap between light clients and full nodes that has shaped Ethereum's user model since launch. Censorship resistance moves from a property the network hopes to retain into one the protocol enforces in real time through FOCIL. Privacy moves from none, with the chain public by default.
 

6. Privacy, the Mempool and the Obfuscation Endgame

Privacy in the essay is a layered programme. The near-term work sits at the mempool and networking level. Onion routing and mixnets obscure which node originated a transaction, which closes the metadata leak that persists even when transaction contents are shielded. Encrypted mempools keep transaction contents hidden until inclusion is fixed, which removes the information that front-running and sandwich attacks depend on. These are engineering problems with known approaches, and their main obstacle has been cost, which is precisely what the aggregation scheme in EIP-8288 is designed to reduce.
Above that sit transaction and account privacy tools built on zero-knowledge proofs, where a user proves a transaction is valid without revealing the parties, amounts or balances involved. This is the category that has existed in production for years in systems like Zcash and in application-layer tools on Ethereum, and the roadmap's contribution is making it cheap enough to be ordinary instead of a specialist choice.
The endpoint is indistinguishability obfuscation, which Buterin has described as cryptography's final boss and which he presents as speculative. Obfuscation, if it can be made practical, allows a program to be published in a form that reveals nothing about its internal logic while still running correctly, and it would enable encrypted multiparty computation, in which several parties jointly compute over inputs none of them can see. Working constructions exist in the academic literature and are far too slow to deploy. Buterin includes it as a direction the architecture is capable of absorbing when the cryptography matures
 

7. The Quantum Deadline

The quantum work carries the roadmap's only hard date. Ethereum's planning targets December 2029 for quantum resistance across the execution layer, the consensus layer and the data layer, and the assumption behind that date is that cryptographically relevant quantum machines could appear as early as 2030.
Four things have to be replaced. BLS signatures secure validator attestations and aggregation in consensus. ECDSA secures ordinary user accounts, meaning every externally owned address on the network. KZG commitments underpin the blob data scheme that rollups and PeerDAS both rely on. The zero-knowledge proof systems in production use elliptic curve assumptions that a sufficiently capable quantum computer breaks. All four fall to Shor's algorithm, and none of them can be swapped out without protocol changes.
The replacement is hash-based. Hash functions resist quantum attack in a way elliptic curves do not, and both leanSPHINCS signatures and STARK proofs are built on hash assumptions alone. That is why recursive STARK aggregation carries so much weight in the roadmap: it is simultaneously the scaling mechanism, the privacy enabler and the quantum defence, and the cost work in EIP-8288 is what makes deploying it at network scale arithmetically possible.
The deadline also explains the sequencing pressure. Account-level signature flexibility has to exist before users can move to post-quantum schemes, which is why EIP-8141 matters beyond its account abstraction benefits, and it is a candidate for a fork planned for 2027. Anything that slips pushes the migration window closer to the threat window.
 

Frequently Asked Questions

What is a cryptographic world computer?
It is the term Vitalik Buterin uses for the architecture Ethereum is moving toward, published in an essay on September 27, 2026. Instead of every participant re-executing every transaction to verify it, the network combines base-layer blockchain security with zero-knowledge proofs, data availability sampling, off-chain computation and privacy protocols. Buterin describes it as a hybrid architecture that combines blockchains and modern cryptography, and says the blockchain label now applies to Ethereum largely for historical reasons.
What is the Hegota fork and when is it happening?
Hegota is Ethereum's hard fork planned for 2027, following Glamsterdam, which is expected in Q4 2026. Buterin describes it as likely to be Ethereum's last normal fork, meaning the last upgrade that would look structurally familiar to a developer who has built on the chain since 2015.
What is FOCIL?
FOCIL, catalogued as EIP-7805, is the one headline feature currently scheduled for inclusion in Hegota. It pseudorandomly selects sixteen validators per slot to build inclusion lists of pending transactions, and proposers and builders must include those transactions or their blocks fail to gather enough votes. Censoring a transaction would require neutralising a freshly drawn group of sixteen validators every slot.
What does EIP-8288 do?
EIP-8288, authored by Vitalik Buterin and Thomas Coratger and created on June 3, 2026, aggregates cryptographic signatures and zero-knowledge proofs at protocol level. Transactions declare dependencies without executing them, and a single recursive STARK in the block header proves all of them valid together.
How fast will Ethereum be in 2030?
The roadmap targets 4-to-8-second slots with full finality in 8 to 32 seconds, against roughly 17-second blocks and around 200 seconds for twelve confirmations in the original design. The finality improvement comes from lean consensus work moving toward Minimmit, a single-round consensus design.
When does Ethereum become quantum-resistant?
Planning targets December 2029 across the execution, consensus and data layers, on the assumption that cryptographically relevant quantum computers could appear as early as 2030. BLS validator signatures, ECDSA account signatures, KZG commitments and existing zero-knowledge proof systems all need replacing with hash-based alternatives, which resist quantum attack in a way elliptic curve cryptography does not.
 
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or trading advice. Digital assets are volatile and you may lose capital. Conduct your own research before making any decision.
市场机遇
4 图标
4实时价格 (4)
$0.020806
$0.020806$0.020806
USD

本页面分享的文章均源自公开平台,仅供参考。该内容不代表 MEXC 的立场或观点。所有版权归 Emmanuel Olamiye 所有。如果您认为任何内容侵犯了第三方的权益,请联系 service@support.mexc.com 以便及时删除。 MEXC 不保证任何内容的准确性、完整性或及时性,且不对基于所提供信息而采取的任何行动负责。本内容不构成财务、法律或其他专业建议,亦不应被解释为 MEXC 的推荐或认可。如需专家见解和深入分析,请造访 MEXC 学院。

4 最新动态

查看更多
特斯拉2026年第二季度财报日期:发布时间、网络直播及关键指标

特斯拉2026年第二季度财报日期:发布时间、网络直播及关键指标

特斯拉2026年第二季度财报定于2026年7月22日(星期三)美国股市收盘后发布,管理层计划于美国中部时间下午4:30 / 东部时间下午5:30主持实时Q&A网络直播。第二季度的更新和网络直播将通过特斯拉的投资者关系网站提供,并在电话会议后提供存档重播。 这不仅仅是另一个普通的特斯拉财报日。特斯拉已经报告了超预期的交付季度:在2026年第二季度,公司生产了451,758辆汽车,交付了480,126辆汽车,并部署了13.5 GWh的储能产品。 对于交易员来说,关键问题不再是特斯拉是否交付了更多汽车,这部分已经是已知事实。真正的问题是,这些交付是否足够盈利,储能业务的增长是否能支撑特斯拉更宏大的愿景,以及管理层能否证明其在人工智能、自动驾驶和Robotaxi(无人驾驶出租车)领域的投资正从“叙事”走向可衡量的业务进展。
2026/07/06
特斯拉2026年第一季度财报回顾:交付量反弹,但利润率质量仍是真正的考验

特斯拉2026年第一季度财报回顾:交付量反弹,但利润率质量仍是真正的考验

特斯拉于2026年4月22日美国股市收盘后公布了其2026年第一季度的财务业绩。该公司本季度交付了358,023辆汽车,创造了224亿美元的总营收,并报告归属于普通股股东的GAAP净利润为4.77亿美元。总GAAP毛利率提升至21.1%,而营业利润率达到4.2%。 核心信号不仅在于特斯拉的交付量从去年同期的疲软基数中恢复。更重要的问题是:更高的交付量、FSD相关营收、更低的单车成本以及改善的汽车毛利率,能否重建市场对特斯拉盈利能力的信心。对于寻找下一次TSLA财报日期或关注特斯拉财报的投资者来说,第一季度的表现为第二季度设立了一个关键考验:即销量的增长能否可持续地转化为更高质量的收益。
2026/07/09
苹果 2026 财年第二季度财报回顾:iPhone 营收与服务业务增长维持 EPS 预期

苹果 2026 财年第二季度财报回顾:iPhone 营收与服务业务增长维持 EPS 预期

苹果于 2026 年 4 月 30 日发布了 2026 财年第二季度财报,涵盖截至 2026 年 3 月 28 日的季度。总营收达到 1112 亿美元,同比增长 17%,摊薄后每股收益(EPS)增长 22% 至 2.01 美元。苹果表示,该季度创下了公司 3 月份季度的总营收、iPhone 营收和 EPS 纪录,同时服务业务营收也创下历史新高。 这不仅仅是一份常规的硬件周期财报。苹果第二季度的业绩证明,iPhone 需求、服务业务增长以及积极的资本回报计划仍在共同支撑着该公司强大的 EPS 增长故事。对于寻找下一个苹果财报或 AAPL 财报更新的投资者而言,未来的关键问题是,在市场等待更强劲的 AI 和产品周期催化剂之际,苹果能否维持其溢价估值。
2026/07/09
查看更多