Key TakeawaysEthereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together blockKey TakeawaysEthereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together block
Vitalik Says Ethereum Is Becoming a Cryptographic World Computer: What Changes After Hegota
Key Takeaways
Ethereum co-founder Vitalik Buterin published an essay titled "The cryptographic world computer," describing the network as "a hybrid architecture that combines together blockchains and modern cryptography" and writing on X that "it's really not just a blockchain anymore." Buterin frames the blockchain label as one Ethereum carries largely for historical reasons, and he positions Hegota, the hard fork planned for 2027, as the network's last conventional upgrade before recursive STARKs, automated formal verification, optimized consensus and quantum-safe cryptography take over the roadmap. His stated formulation is that starting after Hegota, this transformation becomes Ethereum's primary story. The 2030 targets he sets out are 4-to-8-second slots and 8-to-32-second finality, measured against roughly 17-second blocks and around 200 seconds for twelve confirmations in the original design. FOCIL, catalogued as EIP-7805, is the one headline feature currently scheduled for inclusion in Hegota, and it puts censorship resistance in the hands of sixteen pseudorandomly drawn validators per slot. EIP-8288, authored by Buterin and Thomas Coratger and created in June 2026, addresses the cost problem that quantum-safe signatures and STARK proofs create by aggregating them into a single recursive proof in the block header. The quantum work targets December 2029 across execution, consensus and data layers.
Overview
Ethereum has spent a decade being described with a word that its own creator now treats as a historical accident. In an essay published, Vitalik Buterin argued that the network is becoming a cryptographic world computer, a system in which mathematical proofs, off-chain computation and privacy machinery carry work that the base chain once had to perform itself. He posted the piece as an attempt to express in concise terms the meaning of everything planned for Ethereum starting from the fork after Hegota. The essay is a framing document, and its practical content sits in three places: what the network stops doing, what replaces it, and when. Ethereum stops asking every participant to re-execute every transaction, because SNARK and STARK verification lets a node check a proof that computation was performed correctly.
1. What the Essay Argues
Buterin's central claim is that Ethereum's architecture has already stopped matching the category it is filed under. His words on X were direct: "It's really not just a blockchain anymore. It's a hybrid architecture that combines together blockchains and modern cryptography." In the essay he goes further, describing the blockchain designation as something Ethereum retains to a large extent for historical reasons.
The argument rests on what a blockchain was originally for. Satoshi Nakamoto's design solved a coordination problem by making every participant repeat every calculation, then agree on the result. Redundancy was the security model. Anything a node could not independently verify by redoing the work was, by construction, untrusted. That requirement set the ceiling on throughput, dictated hardware requirements, and made privacy structurally impossible, since verification required visibility.
What Buterin describes as the hybrid architecture keeps the Satoshian core and attaches to it a set of tools that did not exist, or had not matured, when Bitcoin launched in 2009. Succinct proofs let one party prove a computation was performed correctly and let everyone else verify the proof at a fraction of the cost of redoing the work. Data availability sampling lets a node confirm that data was published without downloading it. Encrypted computation lets participants operate on inputs they cannot read. Each of these breaks a different piece of the original trade-off, and taken together they change what the base layer needs to do at all.
His framing of the consequence is that decentralization stops being purely defensive. In the original design, distributing the network was the price paid for censorship resistance, and every performance characteristic suffered for it. In the architecture he outlines, distributing data storage, computation and privacy work across many parties improves performance, because the parties are no longer duplicating each other. Structuring computation, in his phrasing, lets the blockchain more effectively focus on its job.
2. Why Proofs Change the Constraint
The technical pivot underneath all of this is verification cost. A SNARK or a STARK is a proof that a computation was executed correctly, and checking one is orders of magnitude cheaper than performing the computation. Once that gap is wide enough and the proving side is fast enough, the question of what a blockchain must do narrows sharply.
Under proof-based verification, the chain's remaining jobs are ordering transactions, guaranteeing that the data behind them was published, and confirming proofs. Execution itself can happen anywhere, including on hardware the network has never seen, provided the result arrives with a valid proof attached. This is the same logic that ZK rollups already run on, applied to the base layer itself.
PeerDAS handles the second job. It shipped in Fusaka in December 2025, and it lets validators sample small portions of blob data to gain high statistical confidence that the full dataset was published, without any individual validator carrying the whole thing. The user draft placed PeerDAS among future upgrades; it has been live on mainnet for most of a year, and it is the piece of the hybrid architecture that already works in production.
Recursive STARKs are where the essay points for the rest. Recursion means a proof can attest to the validity of other proofs, which lets many separate claims collapse into one object of fixed size. That property is what makes aggregation viable at protocol level, and it is the mechanism behind both the quantum-safety plan and the signature-cost work described further below. Buterin pairs it with automated formal verification, which addresses a second-order problem: a proof system that is itself buggy verifies incorrect computation with full confidence, so the cryptographic stack needs machine-checked correctness guarantees of its own.
3. Hegota, and the Forks Around It
Glamsterdam is expected in Q4 2026, having already slipped from earlier targets. Hegota follows it, planned for 2027, and it cannot begin testnet work until Glamsterdam ships, which means any further delay in Glamsterdam cascades forward. Buterin's line is that Hegota is likely to be Ethereum's last normal fork, the last upgrade that would look structurally familiar to a developer who has been building on the chain since 2015.
Hegota's scope is narrower. FOCIL, catalogued as EIP-7805, is the single headline feature currently marked as scheduled for inclusion. FOCIL pseudorandomly selects sixteen validators per slot to assemble inclusion lists of pending transactions. Proposers and builders must include the transactions on those lists, and a block that omits them does not gather the votes it needs to be canonical. The censorship calculus changes accordingly: an adversary attempting to keep a transaction out would have to neutralise a freshly drawn group of sixteen validators every slot, indefinitely.
The problem it addresses is a practical one; Block construction on Ethereum is concentrated among a small number of sophisticated builders, and the ability of that layer to exclude transactions has been a live concern since proposer-builder separation became standard practice. FOCIL puts the guarantee back in the protocol instead of relying on builder goodwill. EIP-8141, which introduces frame transactions, sits at "considered for inclusion" and has not been confirmed. It is the native account abstraction proposal, and it is what would give Ethereum accounts flexible signing rules covering social recovery, spending limits, sponsored gas and quantum-resistant signature schemes. The user draft placed these capabilities in 2030; they are candidate features for a 2027 fork, and their inclusion is not settled. The Hegota meta-document, EIP-8081, remains in draft status, so the final scope is still open.
4. EIP-8288 and the Cost of Being Quantum-Safe
The most concrete engineering document behind the essay is EIP-8288, authored by Buterin and Thomas Coratger, created on June 3, 2026 and currently in draft status as a core standards-track proposal. It exists because the cryptography Ethereum needs for quantum safety and privacy is expensive in ways that would break the network if deployed naively.
The numbers in the proposal state the problem plainly. Hash-based post-quantum signatures run to roughly 2 to 3 kilobytes each and cost somewhere between 150,000 and 200,000 gas to verify. STARK proofs all exceed 128 kilobytes. At those sizes, a block full of quantum-safe transactions consumes bandwidth and gas at rates that would make the network unusable, and privacy protocols that depend on STARKs would price themselves out entirely. FOCIL compounds the issue, since inclusion lists have to be propagated alongside everything else.
Gas accounting under the proposal is fixed and charged regardless of execution outcome: 3,000 gas per leanSPHINCS signature and 30,000 gas per leanSTARK. Set against the 150,000 to 200,000 gas that verifying a hash-based signature costs today, the reduction is the difference between quantum-safe transactions being a specialist option and being the default. The proof system uses Lean Ethereum tooling, keeping it consistent with the consensus layer work happening in parallel.
5. The 2030 Targets
Buterin's essay carries a comparison between Ethereum as it was designed in 2015 and what the roadmap targets for 2030.
The original network produced blocks roughly every 17 seconds, and an application waiting for twelve confirmations before treating a transaction as settled waited around 200 seconds. The 2030 target is 4-to-8-second slots with full finality in 8 to 32 seconds. That range comes from the lean consensus work, which moves Ethereum through single-slot finality toward Minimmit, a single-round consensus design that removes a communication round from the finality path. Buterin has described the scope of the Lean Ethereum effort as comparable to the Merge.
Compressing settlement from three minutes to under half a minute changes which applications can use the base layer directly. Tokenized securities settlement, institutional payment rails and any system that has to reconcile against traditional market infrastructure all operate on timing assumptions that 200 seconds violates and 30 seconds does not. The figure sits within the same range that conventional clearing systems target for intraday finality, which is the comparison institutional buyers actually make.
Hardware requirements move in the same direction. The 2015 architecture gave users two options, running a substantial full node or trusting a third party for everything. The 2030 target is that a participant can obtain optimal cryptographic guarantees on much lighter hardware, because proof verification replaces re-execution and data availability sampling replaces full data download. A wallet that checks a proof gets the same assurance as a machine that redid the work, which collapses the gap between light clients and full nodes that has shaped Ethereum's user model since launch. Censorship resistance moves from a property the network hopes to retain into one the protocol enforces in real time through FOCIL. Privacy moves from none, with the chain public by default.
6. Privacy, the Mempool and the Obfuscation Endgame
Privacy in the essay is a layered programme. The near-term work sits at the mempool and networking level. Onion routing and mixnets obscure which node originated a transaction, which closes the metadata leak that persists even when transaction contents are shielded. Encrypted mempools keep transaction contents hidden until inclusion is fixed, which removes the information that front-running and sandwich attacks depend on. These are engineering problems with known approaches, and their main obstacle has been cost, which is precisely what the aggregation scheme in EIP-8288 is designed to reduce.
Above that sit transaction and account privacy tools built on zero-knowledge proofs, where a user proves a transaction is valid without revealing the parties, amounts or balances involved. This is the category that has existed in production for years in systems like Zcash and in application-layer tools on Ethereum, and the roadmap's contribution is making it cheap enough to be ordinary instead of a specialist choice.
The endpoint is indistinguishability obfuscation, which Buterin has described as cryptography's final boss and which he presents as speculative. Obfuscation, if it can be made practical, allows a program to be published in a form that reveals nothing about its internal logic while still running correctly, and it would enable encrypted multiparty computation, in which several parties jointly compute over inputs none of them can see. Working constructions exist in the academic literature and are far too slow to deploy. Buterin includes it as a direction the architecture is capable of absorbing when the cryptography matures
7. The Quantum Deadline
The quantum work carries the roadmap's only hard date. Ethereum's planning targets December 2029 for quantum resistance across the execution layer, the consensus layer and the data layer, and the assumption behind that date is that cryptographically relevant quantum machines could appear as early as 2030.
Four things have to be replaced. BLS signatures secure validator attestations and aggregation in consensus. ECDSA secures ordinary user accounts, meaning every externally owned address on the network. KZG commitments underpin the blob data scheme that rollups and PeerDAS both rely on. The zero-knowledge proof systems in production use elliptic curve assumptions that a sufficiently capable quantum computer breaks. All four fall to Shor's algorithm, and none of them can be swapped out without protocol changes.
The replacement is hash-based. Hash functions resist quantum attack in a way elliptic curves do not, and both leanSPHINCS signatures and STARK proofs are built on hash assumptions alone. That is why recursive STARK aggregation carries so much weight in the roadmap: it is simultaneously the scaling mechanism, the privacy enabler and the quantum defence, and the cost work in EIP-8288 is what makes deploying it at network scale arithmetically possible.
The deadline also explains the sequencing pressure. Account-level signature flexibility has to exist before users can move to post-quantum schemes, which is why EIP-8141 matters beyond its account abstraction benefits, and it is a candidate for a fork planned for 2027. Anything that slips pushes the migration window closer to the threat window.
Frequently Asked Questions
What is a cryptographic world computer?
It is the term Vitalik Buterin uses for the architecture Ethereum is moving toward, published in an essay on September 27, 2026. Instead of every participant re-executing every transaction to verify it, the network combines base-layer blockchain security with zero-knowledge proofs, data availability sampling, off-chain computation and privacy protocols. Buterin describes it as a hybrid architecture that combines blockchains and modern cryptography, and says the blockchain label now applies to Ethereum largely for historical reasons.
What is the Hegota fork and when is it happening?
Hegota is Ethereum's hard fork planned for 2027, following Glamsterdam, which is expected in Q4 2026. Buterin describes it as likely to be Ethereum's last normal fork, meaning the last upgrade that would look structurally familiar to a developer who has built on the chain since 2015.
What is FOCIL?
FOCIL, catalogued as EIP-7805, is the one headline feature currently scheduled for inclusion in Hegota. It pseudorandomly selects sixteen validators per slot to build inclusion lists of pending transactions, and proposers and builders must include those transactions or their blocks fail to gather enough votes. Censoring a transaction would require neutralising a freshly drawn group of sixteen validators every slot.
What does EIP-8288 do?
EIP-8288, authored by Vitalik Buterin and Thomas Coratger and created on June 3, 2026, aggregates cryptographic signatures and zero-knowledge proofs at protocol level. Transactions declare dependencies without executing them, and a single recursive STARK in the block header proves all of them valid together.
How fast will Ethereum be in 2030?
The roadmap targets 4-to-8-second slots with full finality in 8 to 32 seconds, against roughly 17-second blocks and around 200 seconds for twelve confirmations in the original design. The finality improvement comes from lean consensus work moving toward Minimmit, a single-round consensus design.
When does Ethereum become quantum-resistant?
Planning targets December 2029 across the execution, consensus and data layers, on the assumption that cryptographically relevant quantum computers could appear as early as 2030. BLS validator signatures, ECDSA account signatures, KZG commitments and existing zero-knowledge proof systems all need replacing with hash-based alternatives, which resist quantum attack in a way elliptic curve cryptography does not.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or trading advice. Digital assets are volatile and you may lose capital. Conduct your own research before making any decision.
市場機遇
4實時價格 (4)
$0.020708
$0.020708$0.020708
USD
4 (4) 實時價格圖表
本頁面分享的文章均源自公開平台,僅供參考。該內容不代表 MEXC 的立場或觀點。所有版權歸 Emmanuel Olamiye 所有。如果您認為任何內容侵犯了第三方的權益,請聯絡 service@support.mexc.com 以便及時刪除。 MEXC 不保證任何內容的準確性、完整性或及時性,且不對基於所提供信息而採取的任何行動負責。本內容不構成財務、法律或其他專業建議,亦不應被解釋為 MEXC 的推薦或認可。如需專家見解和深入分析,請造訪 MEXC 學院。
4 最新動態
查看更多
從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心
據報導,OpenAI 傾向將其 IPO 推遲至 2027 年,但更強烈的市場訊號來自 SpaceX。SpaceX 於 6 月 22 日收盤下跌了 16.4%,收於 154.60 美元,較盤中高點 225.64 美元降低了 31.5%,但仍較其 135 美元的 IPO 價格高出 14.5%。這一走勢使 SpaceX 從一個由稀缺性驅動的 IPO 成功案例,轉變為 AI 相關超大型上市週期中首個重大公開市場壓力測試。
OpenAI 的問題不在於需求,而在於估值。路透社引用《紐約時報》的報導指出,OpenAI 正考慮等待至 2027 年,以維持高達 1 兆美元的估值目標,而顧問將此選擇定調為:要麼等待達到該估值,要麼以較低目標提前上市。
預測市場已開始反映這種謹慎態度。Polymarket 的 OpenAI IPO 市場近期顯示,OpenAI 在 2026 年 12 月 31 日前完成 IPO 的機率約為四分之一,這表明交易者不再將近期上市視為明確的基本情境。對於加密貨幣交易者而言,這使得 AI 上市前的曝險從單向的稀缺性交易,轉變為與公開市場基準掛鉤的估值紀律交易。
2026/06/29

Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認
比特幣硬體錢包製造商 Coinkite 已警告用戶,Coldcard 裝置存在種子生成問題,影響範圍涵蓋所有 4.0.1 及更高版本的 Mk3 韌體。此警告是在安全研究人員調查一宗涉及 594.48 BTC(價值約 3,800 萬美元)的協調性盜取事件時出現的。然而,目前尚無公開的技術證據證實 Coldcard 的問題導致了這些轉帳。
2026/07/31

Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心
Mastercard 於三月宣布該交易後,已於 2026 年 8 月 3 日(UTC +8)完成對穩定幣基礎設施供應商 BVNK 的收購。
2026/08/04
您可能也會喜歡
熱門
目前熱門備受市場關注的加密貨幣
加密貨幣價格
按交易量計算交易量最大的加密貨幣


