Vitalik's bigger point here isn't just that SNARKs could become dramatically cheaper.
Across several posts this week, he's describing a future where signatures, ZK proofs and other expensive checks can increasingly be compressed into proofs, and where "cryptographizing" computation eventually becomes as routine as using HTTPS.
If that happens, it changes what we should want from a blockchain VM.
If more of the base layer's job becomes verifying proofs of computation happening elsewhere, its cryptographic capabilities shouldn't be frozen around the primitives that happened to matter when the chain launched.
Interestingly, that was one of CKB's earliest architectural bets.
CKB is designed as a universal verification layer. CKB-VM runs RISC-V and hardcodes no cryptographic precompiles, so new signature schemes, SNARK/STARK verifiers and other cryptographic constructions can be implemented as software at the smart contract or script layer rather than added one by one to the base protocol.
We've already seen this flexibility in practice.
Groth16 and other ZK proof verifiers have been implemented directly on CKB-VM without modifying the underlying chain, and NIST-standardized SPHINCS+ is already live on mainnet as an opt-in Lock Script.
The point is, nobody knows which cryptographic primitives will dominate ten years from now.
So if Vitalik is right that cryptography is about to evolve much faster than most expect, the advantage isn't predicting the winners today.
It's crypto agility: being able to adopt whatever wins tomorrow.
One optimistic and still very-non-consensus belief I have about the far future of cryptography:
I think that there is a 33% chance that, for average real-world computation, there exist ways to implement all three of what I call the Egyptian God Protocols (SNARK, FHE, iO) with 1+ε factor overhead (meaning, for large enough instances, the added overhead of cryptographizing a computation becomes arbitrarily small compared to the base cost of doing the computation itself)
And a 60% chance that all three can be done with single-digit overhead (ie. <10x, measured in total cost of energy plus amortized compute)
I think there's a good chance we'll get one of these (probably SNARKs with single-digit overhead) by the end of this decade. After all, we're already there for specialized hash functions and for some LLM inference.