EIP-8288 would be one of the most groundbreaking updates to Ethereum if shipped, but it may not be obvious from the technical language. Let me try to explain in plain words.
Today, Ethereum scales in three dimensions:
- Execution aka "gas limit"
- Blobs aka "data availability"
- State aka on-chain data
EIP-8288 enables Ethereum to scale in a fourth dimension -- proof verification.
Ethereum will need to verify a lot of proofs, because in a post-quantum world, signatures will be too expensive to verify directly, so we must aggregate them through STARKs (a type of ZK proofs) and verify the STARK proofs instead. At the same time, privacy transactions (such as those sent through Railgun / Tornado Cash) will also need to use STARKs to be quantum-safe.
The problem with quantum-safe STARKs however is that they are very large (~512kb) and will therefore take millions of gas to verify. Therefore, for Ethereum to support private, post-quantum transactions at scale, it's important to lower the cost of verifying STARKs.
One natural solution to this problem is to ask the block builder to create a single STARK that aggregates all the PQ signatures and STARKs in the block. That way, the cost of verifying each individual signature/proof becomes amortized over the cost of verifying a single block-level proof.
This simple solution has a few issues, however:
- It places a huge amount of compute burden on the block builder, who now becomes the bottleneck for how many signatures/proofs can be verified in a block.
- Since many transactions are gossiped through the public mempool, if every transaction carries large PQ signatures/proofs, it can quickly overwhelm the bandwidth of mempool nodes. If the public mempool stops functioning, Ethereum loses its censorship resistance.
The core insight of EIP-8288 is that we can solve these problems by aggregating signatures/proofs with a distributed network -- the mempool itself. Each mempool node would locally aggregate proofs of the signatures/proofs it has seen, and instead of gossiping the raw signatures/proofs, it would gossip the aggregated proofs instead. This new architecture solves both problems:
- By the time the block builder is building a block, most of the signatures/proofs will have already been aggregated into a small number of aggregated proofs, so now the builder just has to aggregate *those* proofs.
- Since mempool nodes gossip aggregated proofs rather than raw sigs/proofs, the bandwidth requirements on the mempool are vastly reduced.
In short, EIP-8288 turns what's traditionally a scaling bottleneck -- the distributed mempool -- into a scaling *resource* instead. The more nodes we have in the mempool, the more PQ signatures/proofs can be aggregated, which means the more PQ/private transactions Ethereum can handle. For once, decentralization makes scaling easier, not harder. That's revolutionary!
By leveraging its decentralized mempool as a compute resource, Ethereum will become the only network to support uncensorable, private, and quantum-safe transactions AT SCALE. Couldn't be more excited about this future!
Show more