devlongs retweeted
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
141
347
1,957
421,908
devlongs retweeted
As a founder just pray to experience that venture capital funding, or angel check invested in you. It gives you a certain reassurance that there are people out there who believe in you and your idea enough to fund it with a certain possibility of losing it all attached to the equation. It’s an insane feeling you will never get from bootstrapping. There is a certain level of reassurance that it gives you when building. Coupled with the fact that you will be operating from a different base unlike when you bootstrap.
8
1
30
1,355
Bosstrapping a company/startup is something I wouldn’t recommend to anyone building from Africa. Yes it’s great to experiment but the time it will take you to scale on bootstrapped funds will be really long. Nothing beats having venture funds to scale with.
21
11
77
9,563
Make PQ Ethereum faster!!!
Quantum computers put hundreds of billions of dollars at risk on Ethereum. In order to scale post-quantum Ethereum, the cryptography needs to be faster. Today, we’re teaming up with @succinctlabs & @ethereumfndn to launch SNARK.fast, an open autoresearch challenge where anyone can improve Flock, a leading post-quantum proof system, and make post-quantum Ethereum a reality. Bring your agent. Make it go fast.
12
409
Can't wait to share the gean story.
Some of the world’s most important blockchain infrastructure is being built by Africans. It’s time we talked about it. We’re thrilled to welcome @devlongs_ Ethereum Protocol Engineer at Gean Labs, to the #W3LC5 stage. This isn’t just another Ethereum talk. It’s a conversation about building the technology that powers the ecosystem, from Africa, for the world. 📍August 28th–29th Glover Memorial Hall, CMS Lagos 🎟️ event.web3bridge.com #W3LC5 #Ethereum #Web3Lagos #Conversations
5
2
20
419
devlongs retweeted
Replying to @VitalikButerin
@VitalikButerin's new proposal, The Extremely Lean Chain, shows how shifting state tracking to validators via zkSTARKs can reduce per-validator state to just couple of bytes. We are heading towards a future where STARKs are everywhere!🧵👇
3
8
55
3,686
devlongs retweeted
If we want to make the Lean Ethereum consensus chain aggressively more "lean", and add strong validator privacy (ZK-unlink deposit from staking activity from withdrawal, and re-anonymize stakers every day), here is a path: ethresear.ch/t/the-extremely…
367
394
2,428
464,211
Another milestone for @geanclient. We have completed Devnet 5 and are participating in interoperability testing with other Lean Ethereum clients. Consensus is progressing normally, blocks are being produced, justified, and finalized across the network. Devnet 5 introduces full-block aggregation, significantly reducing block sizes while preserving security. Steady progress toward a post-quantum Ethereum. Onward to Devnet 6.
5
24
447
devlongs retweeted
Today a crazy quantum story just got wilder. On March 31, the Google Quantum AI team published a landmark result on Shor's algorithm for elliptic curve cryptography. Technically, the paper was a bombshell: a dramatic 10x improvement over the state-of-the-art. As a stunt and wakeup call to the blockchain space, those optimisations were illustrated on secp256k1, the elliptic curve underlying Bitcoin and Ethereum signatures. But perhaps the most striking part of the paper was sociological, not technical. Instead of following standard academic process, the optimisations were kept secret, hidden behind a zero-knowledge (ZK) proof. Google's accompanying blog post mentions they "engaged with the U.S. government". The ZK proof demonstrates the existence of algorithmic improvements without leaking details. Academic censorship with ZK, a historic first! As a co-author of the Google paper I witnessed some of the context surrounding this censorship. To be honest, multiple aspects of that context don't sit well with me. As much as I believe the general public ought to know more, I am limited in my ability to whistleblow. Though let me be clear about one thing: the Google team's professionalism has been absolutely exemplary, and they deserve nothing but praise. Censorship has a way of backfiring. The Streisand effect, where an attempt to bury something only draws more attention to it, is exactly what's unfolding today. First, Google's key optimisation has been rediscovered by the French. And in a thrilling turn of events, a collaborative Shor-at-home challenge just launched. The initiative, available at ecdsa[.]fail, breached a new Shor world record in a matter of hours. Let's start with the rediscovery. Just two months after Google's paper, French quantum expert André Schrottenloher cracks the main secret optimisation. His paper, titled "Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms", landed on the arXiv today. Big congrats to André, who beat several other nerdsnipped experts to it. In a blog post also published today, Craig Gidney, the world expert on Shor optimisations, revealed that he'd been sitting on this very optimisation for a whole year under censorship pressure. Interestingly, André missed a handful of minor optimisations, both from Google's original publication and from improvements found since. It's plausible there's still plenty of juice left to squeeze out of Shor, and this is exactly what the ecdsa[.]fail challenge is about. The verifier program developed for the ZK proof does double duty, automatically filtering for valid submissions. Dozens of compounding small and micro improvements are rolling in. As of the time of writing there's an 8.4% improvement to Google's circuit, as measured by the product of logical qubit count and Toffoli gate count. Nice! The nerdsnipping ran deeper than anyone expected. Over the last few weeks it became clear it extended well beyond André and other quantum experts. Behind the scenes, a small army of amateurs quietly got to work. Inspired by Karpathy-style autoresearch, they turned AI on Shor. Ironically, the verifier program for the ZK proof makes an ideal reward function for AIs. The barrier to entry for this modern style of research is refreshingly low, with several non-experts, even a teenager, finding nice optimisations. Get in touch if you'd like to join a Telegram group with fellow autoresearchers :) Part 2: neutral atoms and qday The story doesn't end with Google. On the same day Google went public, a stealthy startup called Oratomic published its own Shor paper in a coordinated release. It made a splash, ultimately becoming the most upvoted paper on scirate[.]com, a website ranking arXiv papers. Oratomic's claim was wild. By building on Google's logical optimisations and applying custom physical optimisations for neutral atoms, they claimed just 10K physical qubits were sufficient to run Shor's algorithm on secp256k1. That number is mind-bogglingly low. Knowing essentially nothing about neutral atoms when Oratomic's paper landed, I was intrigued and decided to learn more about the tech. I fell straight down the rabbit hole and spent a couple hundred hours on the topic. I got a little obsessed and watched every YouTube video I could find and spoke to a bunch of experts. My conclusion? The tech is real, very real. Even Google recently decided to start a neutral atom lab, a notable pivot from their sole focus on superconducting qubits. If you care about qday, i.e. the day a quantum computer will break the first piece of cryptography in production, neutral atoms demand your attention. I shared some of my learnings on Shor and neutral atoms in a 30min talk at the ZKProof cryptography conference. You can find it on YouTube by searching "zkproof neutral atom". Here's an interesting observation about this duo of breakthrough papers: neither Google nor Oratomic say a word about what their results mean for qday. No timelines. Zero. Nada. That is especially baffling given that the whole point of whitehat quantum cryptanalysis is to inform qday estimations and help the general public make good decisions. So let me attempt to partially fill the silence, similarly to what Scott Aaronson did in his April 29 post. Given everything I know, including scary non-public information, I now put the odds of qday by 2032 at 50%. 10% by 2030. Anecdotally, the US government has its own date: 2035. Originating at the NSA and later adopted by NIST, it's when branches of the US government will be disallowed from using quantum-vulnerable cryptography. In plain language: with hindsight, that date is a joke and should be discounted entirely. I don't see how NIST avoids being forced to pull it forward by years. Part 3: post-quantum cryptography There are good reasons to sound the alarm today, but please do not panic. Rushing carelessly towards immature post-quantum cryptography is a recipe for disaster. IMO a good target date for migration is 2029, roughly 3.5 years out. 2029 happens to be the date selected by Google, Cloudflare, and the Ethereum Foundation. These days most of my time goes to safely migrating Ethereum towards post-quantum cryptography as part of the broader lean Ethereum effort. There's a lot to do. We need to rip out and replace BLS signatures at the consensus layer, KZG commitments at the data layer, and ECDSA signatures at the execution layer. The plan to get there is compelling, and is based on hash-based cryptography. Within the Ethereum Foundation we've developed a Swiss army knife called leanVM (github[.]com/leanEthereum/leanVM) powered by the magic of hash-based SNARKs. Thanks to truly exceptional work by Emile, Thomas, and others, its performance is derisked. Regarding security, leanVM is a jewel, a minimal zkVM crafted for end-to-end formal verification and maximum security. Want to help? There are two $1M initiatives. First, the Proximity Prize (proximityprize[.]org). Solve a long-standing mathematical conjecture in coding theory, improve hash-based SNARKs, and go home a millionaire. Second, the Poseidon Initiative (poseidon-initiative[.]info), offers $1M for breaking Poseidon, the SNARK-friendly hash function.
434
1,126
6,270
3,794,987
Geanie 🔥
So cool to see there's a Nigerian Blockchain Lab building an ethereum consensus client @geanclient It's our time 💪🏾
1
13
508
devlongs retweeted
more people should know @kevaundray and for that matter the others doing the zkevm work (including those outside EF) (Justin is of course great, but I've mentioned justin being great many times already😄)
43
14
335
52,469
Gean is now passing all Lean Ethereum Hive test suites (200/200), the official conformance tests that run Lean Consensus clients against the spec. This includes interop, rpc-compat, reqresp, gossip, validation, fork-choice, state-transition and signature verification suites.
1
6
18
432
A major milestone for Gean and another step toward production-grade Lean Ethereum consensus infrastructure in Go. Live dashboard: hive.leanroadmap.org
5
10
263
devlongs retweeted
The timeline for Q-Day is accelerating. The probability of a Cryptographically Relevant Quantum Computer (CRQC) breaking blockchain cryptography by 2032 has shot up. Here is a technical breakdown of @drakefjustin's recent presentation on the quantum threat at @zkproof. 🧵👇
3
13
62
3,920
devlongs retweeted
THE MORE I STUDY SCIENCE, THE MORE I BELIEVE IN JESUS. 100%
410
634
8,643
132,827
👏 👏 👏
We have completed devnet-4 development and currently participating in the devnet-4 multi-client interop run. Here are some of the notable implementations done for devnet-4
14
236
I mapped out projects from Cohort 5 & 6 what’s been explored and where there’s still room to contribute. Read here: hackmd.io/@dicethedev/Hk6uCt…
EPF7 applications are open. Deadline is May 13. If you want to work on core Ethereum protocol — client development, testing, specs, research — this is the program for you.
1
5
18
722