fort mode 🤝 beast mode

world computer
The drums of quantum computing are getting louder. An ambitious roadmap backed by concrete designs and 30+ years of cryptographic research is already underway. Learn more at leanroadmap[.]org."
38
66
358
151,965
lean Ethereum retweeted
The Protocol Cluster has published two new posts: Hegotá EIP Opinion Post and Tier List evaluates and grades all 62 EIPs proposed for Hegotá, providing the cluster’s first unified tier list for a network upgrade Current and Emerging Priorities covers commitments and research arcs, anchored on a quantum-resistant Ethereum L1 by Dec. 2029 Offered as one input to Hegotá scoping, roughly 60 researchers, engineers, and individual domain experts across all 9 teams in the Protocol Cluster contributed to the Hegotá tier list, providing 397 tier grades before discussing contested items live. The plan, commitments, and shared set of cluster-wide priorities covered in the companion post provide the context behind the final tier grades. The Protocol cluster will host a Reddit AMA on r/ethereum on September 16 at 2pm UTC to talk through these priorities, the Hegotá tier list, and anything else on your mind. → Submit questions ahead of time here: pad.ethereum.org/form/#/2/fo… Read the articles here: → EF Protocol - Current and Emerging Priorities: blog.ethereum.org/2026/09/07… → EF Protocol - The Hegotá EIP Opinion Post and Tier List: blog.ethereum.org/2026/09/07…
20
53
257
66,379
lean Ethereum retweeted
Ethereum Foundation Protocol’s tier list cheat sheet S-tier (must ship) • FOCIL (7805) • Frames (8141) A-tier (high priority) • Privacy: 8250, 8272 • Security: 7906 • PQ: 8365, 8298, 8151 • zkEVM: 8025 • CR: 8369 • Repricings: 8131, 8279 • Networking: 8334 • History and logs: 8383 • EVM: 5920 • Clean-ups: 3298, 8015, 4758 B-tier (on the fence) • Quick slots: 8198 • Networking: 8146, 8237, 8077 • Repricings: 8374, 7709 • PQ: 8321 • Clean-ups: 8253 C-tier (below the line) • Blobs: 8371 • PQ: 8355 • Repricings: 8358 • EVM: 8200, 7666 • Clean-ups: 7668, 8116 DFI (declined for inclusion) • Staking: 7716, 8148, 8205 • Fees and issuance: 8363, 8375, 8115 • Consensus: 8243, 8333, 8359, 8341 • Networking: 8379, 8094 • Blobs: 8142 • PQ: 8367 • AA: 7851, 7819, 7645 • Privacy: 8182 • zkEVM: 7862 • Repricings: 7923, 7973 • EVM: 8163, 7979, 8219 • State: 8188 • Data formats: 7807 • History and logs: 8304 • Clean-ups: 2488 TBD (waiting on mainnet data) • State repricings: 8368, 8372
We've published the EF Protocol cluster's priorities and our first shared Hegotá EIP tier list, with input from ~60 researchers and engineers across all 9 Protocol teams. We're aggressively targeting a quantum-resistant Ethereum L1 no later than December 2029. That has implications for what we propose including in Hegotá, and how much capacity we leave for the forks after it. Keeping mainnet safe remains our first priority. We'll be on r/ethereum for an AMA on September 16 at 2pm UTC. Please come ask us about the priorities, the tier list, or anything else you're curious about. Tier and priorities posts and question form can be found below in this thread:
4
24
110
9,346
lean Ethereum retweeted
TLDR: EIP-7906 lets transactions include assertions defining permitted outcomes. If one fails, the execution effects are reverted. One example scenario could be that you interact with a contract you believe claims an airdrop. With 7906 you should be able to assert that the transaction produce only the expected effects of receiving the airdrop, and if it instead were to grant a malicious third party permission to spend your ERC-20 tokens, the assertion would fail and the execution effects would instead be reverted.
An EIP I think will be a game-changer: EIP-7906 eip7906.forshtat.com/
1
17
56
3,814
PQ w/minimal assumptions — lean
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
2
2
40
2,456
lean Ethereum retweeted
did yall think we weren’t gonna cook an EthCC storm? dropping soon… ft. beast + fort mode event
2
3
58
3,614
We must take this seriously. It’s non-negotiable.
Today is a monumentous day for quantum computing and cryptography. Two breakthrough papers just landed (links in next tweet). Both papers improve Shor's algorithm, infamous for cracking RSA and elliptic curve cryptography. The two results compound, optimising separate layers of the quantum stack. The results are shocking. I expect a narrative shift and a further R&D boost toward post-quantum cryptography. The first paper is by Google Quantum AI. They tackle the (logical) Shor algorithm, tailoring it to crack Bitcoin and Ethereum signatures. The algorithm runs on ~1K logical qubits for the 256-bit elliptic curve secp256k1. Due to the low circuit depth, a fast superconducting computer would recover private keys in minutes. I'm grateful to have joined as a late paper co-author, in large part for the chance to interact with experts and the alpha gleaned from internal discussions. The second paper is by a stealthy startup called Oratomic, with ex-Google and prominent Caltech faculty. Their starting point is Google's improvements to the logical quantum circuit. They then apply improvements at the physical layer, with tricks specific to neutral atom quantum computers. The result estimates that 26,000 atomic qubits are sufficient to break 256-bit elliptic curve signatures. This would be roughly a 40x improvement in physical qubit count over previous state-of-the-art. On the flip side, a single Shor run would take ~10 days due to the relatively slow speed of neutral atoms. Below are my key takeaways. As a disclaimer, I am not a quantum expert. Time is needed for the results to be properly vetted. Based on my interactions with the team, I have faith the Google Quantum AI results are conservative. The Oratomic paper is much harder for me to assess, especially because of the use of more exotic qLDPC codes. I will take it with a grain of salt until the dust settles. → q-day: My confidence in q-day by 2032 has shot up significantly. IMO there's at least a 10% chance that by 2032 a quantum computer recovers a secp256k1 ECDSA private key from an exposed public key. While a cryptographically-relevant quantum computer (CRQC) before 2030 still feels unlikely, now is undoubtedly the time to start preparing. → censorship: The Google paper uses a zero-knowledge (ZK) proof to demonstrate the algorithm's existence without leaking actual optimisations. From now on, assume state-of-the-art algorithms will be censored. There may be self-censorship for moral or commercial reasons, or because of government pressure. A blackout in academic publications would be a tell-tale sign. → cracking time: A superconducting quantum computer, the type Google is building, could crack keys in minutes. This is because the optimised quantum circuit is just 100M Toffoli gates, which is surprisingly shallow. (Toffoli gates are hard because they require production of so-called "magic states".) Toffoli gates would consume ~10 microseconds on a superconducting platform, totalling ~1,000 sec of Shor runtime. → latency optimisations: Two latency optimisations bring key cracking time to single-digit minutes. The first parallelises computation across quantum devices. The second involves feeding the pubkey to the quantum computer mid-flight, after a generic setup phase. → fast- and slow-clock: At first approximation there are two families of quantum computers. The fast-clock flavour, which includes superconducting and photonic architectures, runs at roughly 100 kHz. The slow-clock flavour, which includes trapped ion and neutral atom architectures, runs roughly 1,000x slower (~100 Hz, or ~1 week to crack a single key). → qubit count: The size-optimised variant of the algorithm runs on 1,200 logical qubits. On a superconducting computer with surface code error correction that's roughly 500K physical qubits, a 400:1 physical-to-logical ratio. The surface code is conservative, assuming only four-way nearest-neighbour grid connectivity. It was demonstrated last year by Google on a real quantum computer. → future gains: Low-hanging fruit is still being picked, with at least one of the Google optimisations resulting from a surprisingly simple observation. Interestingly, AI was not (yet!) tasked to find optimisations. This was also the first time authors such as Craig Gidney attacked elliptic curves (as opposed to RSA). Shor logical qubit count could plausibly go under 1K soonish. → error correction: The physical-to-logical ratio for superconducting computers could go under 100:1. For superconducting computers that would be mean ~100K physical qubits for a CRQC, two orders of magnitude away from state of the art. Neutral atoms quantum computers are amenable to error correcting codes other than the surface code. While much slower to run, they can bring down the physical to logical qubit ratio closer to 10:1. → Bitcoin PoW: Commercially-viable Bitcoin PoW via Grover's algorithm is not happening any time soon. We're talking decades, possibly centuries away. This observation should help focus the discussion on ECDSA and Schnorr. (Side note: as unofficial Bitcoin security researcher, I still believe Bitcoin PoW is cooked due to the dwindling security budget.) → team quality: The folks at Google Quantum AI are the real deal. Craig Gidney (@CraigGidney) is arguably the world's top quantum circuit optimisooor. Just last year he squeezed 10x out of Shor for RSA, bringing the physical qubit count down from 10M to 1M. Special thanks to the Google team for patiently answering all my newb questions with detailed, fact-based answers. I was expecting some hype, but found none.
5
5
98
4,601
The drums of quantum computing are getting louder. An ambitious roadmap backed by concrete designs and 30+ years of cryptographic research is already underway. Learn more at leanroadmap[.]org."
3
1,255
FORT MODE was a blast! Thanks to all of the speakers! We hope to post links to presentations and a YouTube playlist next week-ish.
Final session of the day: Make Ethereum Post Quantum secure
1
2
35
2,266
lean Ethereum retweeted
Big day in Cannes tomorrow if you care about crypto surviving. @corcoranwill and the @leanEthereum team are hosting a full day dedicated to post quantum cryptography. @lou3ee & I will be there to get some alpha to share and we will try to explain things here.
12
18
98
10,462
🏰 FORT MODE (sunday, sunday, sunday)
excited to share the schedule for BEAST MODE + FORT MODE in cannes! hope to see you there — links to register in 🧵
2
29
1,983
> ETH people have already figured this out. Everyone else seems to be petrified in fear. not petrified. in my lane. moisturized. leaning in.
Elliptic curve cryptography is on the brink of obsolescence. Whether it’s 3 or 10 years; it’s over and we need to accept that The only thing that matters is how quickly blockchain developers recognize that they need to bake in cryptographic mutability into their networks This of course requires an entire reimagining of how these systems work. Today the crypto is hardcoded in. That will have to change ETH people have already figured this out. Everyone else seems to be petrified in fear. Unless something changes quickly ETHBTC will start to reflect the divergence in prioritisation
6
9
123
6,048
thanks again to @nico_mnbl @AnnaRRose and the @zeroknowledgefm for featuring lean Ethereum over the last 6 episodes. we made a playlist—you can see them all here! piped.video/playlist?list=PL…
Wrapping up @nico_mnbl's series on the @zeroknowledgefm pod all about @leanEthereum ! Check out the full series over on our Youtube channel piped.video/@zeroknowledgefm
1
1
18
2,181
the 6th and final installment of the @zeroknowledgefm mini-series focused on lean Ethereum. this one is a deep dive into formal verification with protocol snarkification team lead @alexanderlhicks .
How do you actually formally verify the code underpinning Ethereum's future? In this episode (the finale of the @leanEthereum miniseries), @nico_mnbl sits down with Alex Hicks (@alexanderlhicks), lead of Protocol Snarkification at the @ethereumfndn, to break down formal verification from first principles. They cover: – What formal verification actually is and the trust boundaries between proof assistants, SMT solvers, and kernels – The full verification stack for RISC-V ZKVMs: from SAIL specs to constraint extraction to soundness proofs – Why writing constraints directly in Lean makes proofs 10–100x more ergonomic – How AI is now proving hard theorems in hours for $200 — and what that unlocks for the whole pipeline They also explore the boundaries problem, why specs can have bugs too, and the end goal of a full Lean stack that bypasses Rust and LLVM entirely. Listen to the full episode ------------------------------------------------------------ TIMECODES: 09:16 – What is formal verification? Proof assistants vs SMT solvers 18:33 – Formal verification of code: specs, semantics, and trust boundaries 29:30 – Formally verifying the Lean Ethereum stack: RISC-V ZKVMs in focus 33:02 – Extracting ZKVM constraints into Lean and proving soundness 36:35 – Writing constraints directly in Lean: 10–100x better proof ergonomics 44:02 – Proving Polishchuk–Spielman in 8 hours for $200 with AI 51:01 – The end goal: a full Lean stack bypassing Rust and LLVM
1
3
36
1,957
lean Ethereum retweeted
Quantum computing (Q-day) is shifting from a theoretical hurdle to an imminent threat for blockchains potentially by ~2032 following @drakefjustin hot take for @Bankless podcast. How do Bitcoin and Ethereum plan to survive the transition to post-quantum cryptography? 🧵👇
2
9
38
2,552
Ansgar knows a thing or two
Ethereum is leading the way in quantum preparedness. To learn more, check out pq.ethereum.org - it's a beautiful website!
1
1
43
3,043
lean Ethereum retweeted
Today, several teams at the EF are launching pq.ethereum.org, a dedicated resource for Ethereum's post-quantum security effort. What started with early STARK-based signature aggregation research in 2018 has grown into a coordinated, multi-team effort, all open source. The Post-Quantum team and Cryptography teams, with help from the Protocol Architecture and Protocol Coordination teams, have been working on this body of work for 8+ years. At pq.ethereum.org you'll find: - How PQ impacts each protocol layer - The full PQ roadmap (strawmap.org) - Open resources: repos, specs, papers, EIPs - FAQ: 14 questions across 5 categories, written by the PQ team - A 6-part lean Ethereum interview series (@zeroknowledgefm) - Interest form for the 2nd Annual PQ Research Retreat (Cambridge, UK, Oct 2026) - 10+ client teams are already building and shipping devnets weekly through PQ Interop. All the work is public and all of it is open. pq.ethereum.org
91
245
956
96,204
lean Ethereum retweeted
Fair warning. This post is bullish on Ethereum. Yesterday, the Ethereum Foundation Enterprise team ran the Institutional Ethereum Forum in New York City. Broad Adoption Activated. Invitation only. 100's of Banks, asset managers, and infrastructure providers representing around $250 trillion in assets under management. feedback so far "Absolute banger tbh." "People won't stop talking and networking and the content has all been great." "Your institutional team did an amazing job. I was there. Kudos." BlackRock. Western Union. Robinhood. Moody's. Baillie Gifford. Securitize. All on panels. Not as guests. As participants building on Ethereum. This is what adoption actually looks like. EF also presents its post-quantum security strategy and launches pq.ethereum.org. EF also presented its post-quantum security strategy and launched pq.ethereum.org. This is not just leading blockchain. No major technology platform has a published, open-source post-quantum migration roadmap at this level of detail. Ethereum is doing it before it is required, not after. Proud of the Enterprise team for putting this together. Choose Ethereum.
31
87
489
61,192
Today I had the opportunity to present Ethereum's post-quantum security strategy at the Institutional Ethereum Forum in NYC. 15 minutes to explain why every proof-of-stake blockchain faces the same signature aggregation problem — and what the EF is doing about it. We also launched pq.ethereum.org — a dedicated resource that brings together everything the PQ/Crypto teams have been working on: → How PQ impacts each protocol layer → The full PQ roadmap → Open resources — repos, specs, papers → FAQ — 14 questions we keep getting from institutions, now open-sourced → Interest form for the 2nd Annual PQ Research Retreat (Cambridge, Oct 2026) Huge thanks to @drakefjustin @tcoratger @asanso and the entire PQ team, the @leanEthereum client teams shipping devnets every week. Next week: Fort Mode in Cannes. pq.ethereum.org
2
7
60
3,820
Ethproofs call #8 covered the (proposed) Poseidon2 → Poseidon1 switch for lean consensus. 10 yrs of Lindyness, ~2x plain-text slowdown, ~30% end-to-end in leanVM. $1.15M in bounties targeting Poseidon1 security, soonTM Full call here: piped.video/7Jxq3YU8GUY?si=139W…
1
5
33
5,280
lean Ethereum retweeted
Justin Drake thinks post-quantum is an opportunity for Ethereum — not a hurdle. “It’s an opportunity for Ethereum to stand out as the very first global financial system that is post-quantum secure.” “Not just relative to its competitors... but also relative to fiat and tradfi.” “It would send a very strong message... a very natural security starting point for the world to migrate over to Ethereum.” 📆 Out on Monday, March 23 w/ @drakefjustin
29
64
420
35,667