In May, the Protocol cluster welcomed a trio of latest cluster coordinators and promised updates to observe.
After months of settling in and aligning with contributors cluster-wide, throughout the EF and throughout the Ethereum ecosystem, we at the moment are glad to share Protocol’s priorities: what Protocol is for, the commitments that govern its work by way of 2029, and what these commitments require of the forks now getting into scope.
With Glamsterdam approaching mainnet, Protocol has entered the Hegotá scoping season. We used the method described in an August 28 post: 62 EIPs proposed for inclusion, a number of Glamsterdam retrospectives, 16 contribution templates, and several other cluster-wide working classes. That course of helped roughly 60 researchers and engineers to find out a shared set of priorities. These priorities cowl the longer-term roadmap and are centered by way of a vital path. That path begins with how we scope Hegotá.
This put up communicates that shared set of cluster-wide priorities. For our grade on each Hegotá candidate, learn the companion: EF Protocol: The Hegotá EIP Opinion Post and Tier List.
I. The north star
The EF Protocol cluster is aiming for Ethereum L1 to be quantum-resistant throughout all three layers (execution, consensus, and information) by December 2029. That date strains up with the 2029 migration targets independently set by Google, Cloudflare, and Microsoft. Estimates for Q-day will sharpen as time progresses. Its timing is exterior anybody’s management, which is strictly why we’ve got mounted a goal moderately than ready for certainty. For now, Ethereum L1 ought to plan for Q-day taking place as early as 2030. Planning for Q-day in 2030 is a intentionally aggressive assumption. Most credible estimates place Q-day later, some a lot later, and we might by no means see it in any respect.
Delivery post-quantum readiness early is the safe factor to do. It’s the strategically accountable factor to do. It’s the clearest sign we are able to ship that Ethereum intends to exist 50, 100, and 1,000 years from now. Ethereum’s intuition, rightly, is to mistrust all-in bets, and so can we. Right here, although, we’re making that wager intentionally. Q-day can’t be scheduled, so we’ve got assigned ourselves a self-imposed deadline.
The EF Protocol cluster will deal with this self-imposed deadline as non-negotiable not less than till January 2027, when quantum progress might be reassessed with the steerage of out of doors specialists.
II. The plan
Two cadences to December 2029
Shopper groups can realistically start Hegotá implementation in late This fall 2026. Underneath the July Strawmap, full post-quantum readiness sits in L*, 5 hardforks after Glamsterdam. Delivery Glamsterdam in December 2026 and L* in December 2029 requires a median cadence of seven.2 months per fork. That schedule is kind of aggressive, and leaves little room for error ought to a fork take longer to ship than anticipated 12 months upfront.
The August 19 Strawmap update added a minimal viable post-quantum (MV-PQ) L1 milestone at J*. The post-quantum public-key registry sits in I*. The post-quantum heartbeat on the consensus layer, leanDA sampling on the information layer, and leanSPHINCS transactions on the execution layer sit in J*. A 12-month cadence from Glamsterdam can attain that contingency milestone by December 2029.
MV-PQ is a short lived safeguard
MV-PQ is designed to maintain Ethereum working by way of Q-day with decreased ensures. Researchers are nonetheless defining precisely what that discount in ensures would seem like. Full resistance throughout execution, consensus, and information stays the December 2029 goal. The remaining work consists of post-quantum attestations, required for full financial finality to finish consensus design.
Versatile fork order after J*
The Strawmap might swap Ok* and L*, transferring lean consensus ahead by one fork and necessary execution proofs again by a fork. Reaching full post-quantum readiness in Ok* by December 2029 implies a 9-month cadence. We’re planning Hegotá, I*, and J* as one supply sequence whereas that ordering will solely be finalized as soon as analysis matures and shopper capability is healthier understood.
Parallel supply throughout the ecosystem
The cadence these milestones demand would require an unbelievable quantity of teamwork, inside Protocol and past. Forks will overlap, delivery Hegotá concurrently whereas I* specs mature and J* by way of L* analysis produces testable elements. Merely delivery the forks in a linear sequence can not meet the December 2029 schedule. Doing so would require tighter communication contained in the cluster, and fascinating shopper groups, grant recipients, academia, and the broader neighborhood so the pipeline from analysis to mainnet accelerates with each fork.
Delivering PQ-readiness will even take extra fingers than any prior fork sequence, together with cryptographers, shopper devs, researchers, safety reviewers, and testing capability, contained in the EF and effectively past it. This might be an ecosystem-wide effort.
III. The 5 multi-fork analysis arcs
Concurrently engaged on a number of forks is how the Protocol cluster carries all of its interconnected work, near-horizon and long-horizon alike, past the quick push to succeed in minimal viable post-quantum. These efforts are organized round 5 multi-fork analysis arcs: quick finality, post-quantum, privateness, state, and zkEVM.
Quick finality
Quick finality reduces Ethereum’s time to finality from minutes to seconds. The present design path decouples finality from block manufacturing and rebuilds the consensus layer round an out there chain and a finality gadget. Specs and prototypes are underway, aimed toward I*, the place decoupled consensus is the main headliner candidate.
Publish-quantum
The post-quantum arc (as described in “II. The Plan” above) delivers the December 2029 dedication and it spans all three layers: consensus, information, and execution. Cryptographic agility is vital to the execution layer, the place native account abstraction lets signature schemes be swapped with out a arduous fork per scheme. Frames supplies that property with its strategy to native account abstraction. The consensus layer, nonetheless, can not depend on cryptographic agility; its cryptography and aggregation schemes can solely change by way of a tough fork. Consensus cryptography will get the other remedy in consequence. It will get battle-tested and hardened earlier than rollout, and consensus elements watch for the entire PQ design as an alternative of delivery one by one.
Privateness
The privateness arc is working towards privateness as a protocol assure, in order that customers can transact, maintain balances, and work together with purposes with out exposing their monetary historical past or trusting third events. We consider this work ought to begin in Hegota to ship native, trustless, censorship resistant non-public transactions on Ethereum L1. Later work focuses on post-quantum privateness at scale, and encrypted mempools that conceal transaction contents till inclusion.
State
The state arc retains state progress and entry from turning into Ethereum’s binding constraint. Its work consists of migrating to a brand new trie, sustainable state progress, and decentralized entry to present and historic state. The most important design and migration work is anticipated to start in I* and continues past it.
zkEVM
The zkEVM arc strikes execution proofs from out there and elective, to anticipated, to necessary. Validators finally confirm a succinct proof and cease re-executing each block. Underneath the present Strawmap ordering, necessary proofs arrive in Ok*. One reordering is in evaluate: swap the PQ attestation and necessary proofs milestones. PQ attestations would transfer ahead from L* to Ok*, and necessary proofs would transfer again from Ok* to L*, whereas the remainder of every fork stays the place it’s. If that occurs, necessary proofs arrive one fork later so the most important remaining piece of consensus PQ arrives one fork sooner. Both manner, the push to ship an L1 zkEVM additionally drives ahead formal verification tooling, workflows, and verified cryptographic elements that different arcs profit from, post-quantum particularly.
IV. How we set priorities & ship them
Our crucial, first revealed within the July all-Protocol update, stays:
“Focus Protocol on what solely Protocol can do and can do, and full the Strawmap gadgets that permit Ethereum to uphold the Mandate.”
Glamsterdam’s completion and the December 2029 dedication transfer post-quantum work from a long-horizon analysis concern into near-fork supply. The post-Glamsterdam precedence ladder data that change and locations formal verification throughout the remaining analysis arcs as shared tooling.
| As of Q2 2026 | Publish-Glamsterdam | |
|---|---|---|
| P0 | Hold mainnet protected | Hold mainnet protected (unchanged) |
| P1 | Ship Glamsterdam and Hegotá with out safety or stability points and in a well timed method | Ship the vital elements of Hegotá, I*, and J*: the trail to MV-PQ |
| P2 | Maintain analysis and engineering capability for the fork after subsequent (I*) | Maintain analysis and engineering capability for Ok* and L*, centered on accelerating the remaining PQ gadgets |
| P3 | Maintain analysis functionality for the 5 multi-year arcs (quick finality, post-quantum, privateness, state, and zkEVM) | Maintain analysis functionality for the 4 remaining arcs (quick finality, privateness, state, and zkEVM), with formal verification as cross-cutting tooling that advances all of them |
The ladder units precedence; the maturity pipeline units how work earns inclusion:
Analysis → EIP → Prototype → Devnet → PFI → CFI → SFI → Mainnet
Every step ought to add proof, cut back uncertainty, and make possession seen earlier than the subsequent dedication is made. A devnet can ship work again to analysis. PFI, CFI, and SFI sign rising confidence amongst AllCoreDevs; they don’t substitute for implementation proof. A lot of what Protocol is uniquely positioned to do is transferring concepts throughout this entire pipeline.
V. The following fork, as the primary check
This part is about Hegotá particularly. Protocol’s view of the fork now being scoped. The companion put up, EF Protocol: The Hegotá EIP Opinion Post and Tier List, particulars how the Protocol cluster grades each EIP, with a particular clarification for every EIP. On this part, we cowl the priorities, commitments, and scope boundaries that produced these views.
Hegotá is just not the PQ fork; it’s the fork that decides whether or not the PQ forks occur on time. Its SFI’d headliners are EIP-7805 Fork-choice enforced Inclusion Lists (FOCIL) on the consensus layer and EIP-8141 Frame Transaction on the execution layer. They need to ship collectively safely, with the interplay between inclusion and the brand new transaction mannequin examined as a part of the fork’s foremost engineering carry.
There may be little urge for food for extra consensus-layer scope. FOCIL is Hegotá’s consensus-layer centerpiece. Our urge for food past it’s near zero except an addition immediately helps post-quantum readiness. Every extra consensus-layer merchandise attracts from the identical researchers and shopper devs wanted to specify and prototype decoupled consensus and put together I* and J* when their Hegotá implementations are accomplished.
Preserving CROPS as an entire
The Mandate defines Protocol’s job by way of CROPS: Censorship Resistance (CR), Open Supply and Free, as in Freedom (O), Privateness (P), and Safety (S). These properties are one set of protocol ensures. Open-source growth and open participation are the baseline for each fork. Hegotá makes particular commitments throughout the opposite 3.
Censorship resistance (CR)
FOCIL’s purpose is to enhance Ethereum’s transaction inclusion ensures by enabling a number of validators to impose constraints on builders’ blocks. They accomplish that by specifying a set of transactions that should be included by way of ILs for the block to be thought-about legitimate by attesters. EIP-8369 VOPS Profiles for FOCIL Eligibility defines which transactions are eligible and what validators should confirm, so FOCIL’s ensures can prolong to future transaction sorts. Collectively, they’re Hegota’s direct dedication to censorship and seize resistance.
Privateness (P)
Ethereum continues to be lacking some fundamental protocol assist that privateness purposes want. EIP-8250 Keyed Nonces lets many customers share the identical sender for higher anonymity, whereas giving their transactions separate nonces so they don’t block each other. EIP-8272 Recent Roots lets non-public transactions use current onchain state in a type FOCIL can verify, to allow them to profit from its inclusion ensures. Collectively, they take away two main obstacles to trustless, censorship resistant non-public exercise on L1 and may ship with Frames.
Safety (S)
Body transactions makes transaction validation, execution, and gasoline fee programmable on the protocol stage. It provides accounts a local route away from susceptible secp256k1 keys, helps signature aggregation, and lets new signature schemes be launched with out a arduous fork for every scheme. It additionally retains account validation and price fee permissionless. Keyed nonces and up to date roots full the Frames core wanted for Hegotá.
EIP-8365 BLS Withdrawal Credential Retirement begins the retirement course of for withdrawal credentials that stay tied to susceptible cryptography. The work can start now with out ready for the complete post-quantum consensus design.
The Frames-extension bundle hardens accounts immediately. EIP-7906 Transaction Assertions via State Diff Opcode lets transactions confirm specified results earlier than committing, defending in opposition to assaults reminiscent of drainers, EIP-8298 SETCODEFROM Code Reuse Instruction lets delegated accounts turn out to be full smart-contract accounts, and EIP-8151 Account Code Restricted ecRecover blocks legacy key authentication as soon as an account has actual code. The final 2 type the account path for retiring secp256k1 as a grasp key.
The bounding pair treats worst-case block development as safety work: EIP-8279 Block Access List Byte Floor and EIP-8131 Unified Transaction Content Floor put a predictable gasoline ground beneath adversarial block content material. Any later use of ensuing headroom is a separate scope resolution.
Delivering FOCIL and Frames safely, and testing the interplay between them, is Hegotá’s core engineering dedication. Each addition competes with that testing floor and should clear the need bar.
VI. What to anticipate
The companion post publishes the Protocol cluster’s Hegotá tier listing and clarification of each grade. In case you learn one factor past this put up, learn the companion.
Lastly, we wish your questions. We’re internet hosting a Reddit AMA on r/ethereum on September 16 at 2pm UTC to speak by way of these priorities, the Hegotá tier listing, and the rest in your thoughts. Submit questions forward of time using the form here. The sharper the query, the higher the thread.
