BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

八年投入急转弯,以太坊为何突然放弃Poseidon?

Foresight News
特邀专栏作者
2026-08-14 08:20
This article is about 3178 words, reading the full article takes about 5 minutes
After eight years and tens of millions of dollars invested, Ethereum has chosen a more conservative but also more certain post-quantum path.
AI Summary
Expand
  • Core Thesis: The Ethereum Foundation has decided to abandon the SNARK-friendly hash function Poseidon in favor of traditional hash functions such as SHA2 or BLAKE2, in order to address post-quantum security threats and accelerate technical deployment.
  • Key Elements:
    1. Poseidon, introduced in 2019, became mainstream due to its high efficiency in SNARK circuits, but its relatively short cryptanalytic history has exposed limitations under post-quantum security requirements.
    2. Through "binary field" computation methods, traditional hash functions have achieved performance in SNARKs comparable to Poseidon, with laptops verifying approximately 1 million traditional hash invocations per second.
    3. The Ethereum roadmap plans to launch a production-grade leanVM in 2027, with deployment across consensus, execution, and data availability layers by 2028 to achieve post-quantum signature aggregation.
    4. Quantum computer threats are accelerating, with Q-Day potentially arriving between 2030 and 2033, placing trillions of dollars in on-chain assets at risk and driving the urgency of PQC migration.
    5. The Solana Foundation has selected the Falcon post-quantum signature scheme, and Starknet plans to replace the Pedersen hash with BLAKE2, as the industry advances post-quantum transformation in parallel.

Original author: ChandlerZ, Foresight News

On August 13, Ethereum researcher Justin Drake announced on X that the Ethereum Foundation has decided to abandon the SNARK-friendly hash algorithm Poseidon on the L1 layer, opting instead for traditional hash functions such as SHA2 or BLAKE2.

Behind this decision lies eight years of research, tens of millions of dollars in investment, and a major correction to the post-quantum cryptography roadmap.

Since its launch in 2019, Poseidon has been regarded as the ideal hash scheme for applications such as zkRollups and zkVMs. Its structure makes it cheaper and more efficient in SNARK circuits than traditional binary-operation-based hash functions. However, when post-quantum security became a hard requirement for Ethereum, Poseidon's limitations began to surface.

Justin Drake stated that this shift is driven by breakthrough progress in SNARK design—specifically, through "binary field" arithmetic, which enables traditional hash functions to achieve performance in SNARK circuits comparable to Poseidon, which was previously purpose-built for SNARK optimization. A single laptop can now verify approximately 1 million traditional hash invocations per second.

The article notes that since its launch in 2019, Poseidon has been the mainstream SNARK-friendly hash scheme, providing security for applications such as zkRollups and zkVMs. Justin Drake said that according to the roadmap, a production-grade leanVM is expected to launch in 2027, with consensus-layer, data-layer, and execution-layer deployments expected to be completed by 2028. The Ethereum Foundation's post-quantum team is also accelerating research into binary fields.

Why Now?

Traditional hashes have long struggled to integrate with SNARKs, with the primary obstacle stemming from differences in computational paradigms. SHA2, BLAKE2s, and Keccak rely heavily on bitwise operations such as XOR and shifts, whereas traditional SNARKs typically operate on arithmetic over large prime fields. Simulating each bitwise operation incurs prohibitively high constraint costs. Poseidon was designed directly around prime-field arithmetic, trading fewer constraints for faster proving—at the cost of a shorter algorithmic track record requiring ongoing cryptanalysis.

Binary fields switch the underlying mathematics to the smallest prime field containing only 0 and 1, using binary extension fields to carry larger data. Bitwise operations can therefore enter the proving system directly, and SNARKs begin to accommodate traditional hashes. The technical focus shifts from designing SNARK-friendly hashes to designing hash-friendly SNARKs.

Binius, proposed by Jim Posen and Benjamin Diamond in 2023, demonstrated a binary tower field SNARK path. The Flock paper by Benedikt Bünz, Ron Rothblum, and William Wang was uploaded to arXiv on July 29, 2026, with M4 Max benchmarks showing 82,000 BLAKE3 compressions, 42,000 SHA-256 compressions, and 30,000 Keccak permutations proven per second on a single core—while 10-core BLAKE3 throughput exceeds 660,000.

Drake noted that a laptop can prove approximately 1 million traditional hash invocations per second, with overhead of roughly 100x native CPU boolean computation. SNARK.fast recently achieved 1.8 million BLAKE3 proofs per second on an M3 Max.

leanVM in 2027, Three-Layer Deployment in 2028

Another key reason for abandoning Poseidon is the accelerated timeline for post-quantum security. The Project Eleven report, "The Quantum Threat to Blockchains – 2026 Report," points out that the rapid advancement of quantum computers poses a serious threat to blockchain security. Once a "cryptographically relevant quantum computer" (CRQC) emerges, Shor's algorithm could quickly break asymmetric encryption such as ECDSA (used by Bitcoin and most public chains) and RSA. Q-Day (quantum break day) is projected to arrive between 2030 and 2033, at which point trillions of dollars in on-chain assets would be at risk.

Because blockchain public keys remain static for long periods and cannot be rolled back, migration is extremely difficult. The report recommends immediately initiating post-quantum cryptography (PQC) migration, including lattice-based and hash-based quantum-resistant signature schemes, with a gradual transition through hybrid approaches to avoid a full-blown quantum threat.

Justin Drake warned that AI's enhanced capabilities in cryptanalysis have already dealt successive blows to the lattice-based scheme HAWK and the isogeny-based scheme SQIsign. This has forced the Ethereum Foundation to bet on hash-based schemes, which are considered to have stronger resistance to quantum attacks.

Previously, Ethereum had already published its post-quantum roadmap, including the deployment of a production-grade leanVM in 2027, with consensus-layer, execution-layer, and data-availability-layer deployments completed in 2028. leanVM is a minimal zero-knowledge virtual machine purpose-built for post-quantum signature aggregation, viewed as a core component of the overall strategy.

In March 2026, the Ethereum Foundation launched pq.ethereum.org as a post-quantum security resource center, with over 10 client teams now running weekly post-quantum interoperability devnets. The Foundation has also established a $1 million Poseidon Prize and an equal-value Proximity Prize to advance post-quantum cryptography research. Vitalik Buterin himself has repeatedly emphasized that post-quantum security is a necessary condition for Ethereum's "walkaway test"—Ethereum cannot be "frozen" until it achieves quantum security.

The hash function switch does not change the overall structure of Ethereum's post-quantum roadmap. Validators currently use BLS signatures that rely on elliptic curves; future schemes remain based on hash-based signatures such as leanXMSS, with leanVM compressing large numbers of signatures into a single small proof per block. Ethereum's official page previously provided the comparison: leanXMSS signatures are approximately 3,000 bytes, while BLS signatures are only 96 bytes. leanVM's data compression target is approximately 250x.

SHA2 and BLAKE2s have longer public analysis histories, allowing the EF to reduce the time spent waiting for Poseidon parameters to withstand years of cryptanalysis. Drake's strawmap points to a production-grade leanVM in 2027 and consensus-layer, data-layer, and execution-layer deployments in 2028.

Racing Peers: Solana Chooses Falcon

Ethereum is not the only major public chain preparing for the post-quantum era. The Solana Foundation released its post-quantum security roadmap in April 2026, with its core developer teams Anza and Jump Crypto's Firedancer independently converging on the same post-quantum signature scheme: Falcon.

Falcon is one of the NIST-standardized post-quantum signature schemes, with compact signatures well suited to high-throughput blockchain environments like Solana.

The two validator client development teams, Anza and Firedancer, independently reached the same conclusion in selecting the post-quantum digital signature scheme Falcon, and have both published initial implementation code on GitHub. The current roadmap follows three steps: continuous evaluation of Falcon and alternatives; adopting post-quantum schemes for new wallets when the quantum threat materializes; and ultimately migrating all existing wallets. Additionally, Blueshift's Solana Winternitz Vault has been running in the ecosystem for over two years, and was cited earlier this year in a Google Quantum AI whitepaper as a cutting-edge industry case.

The Solana Foundation stated that quantum computing posing a material threat is still years away, and there is no need for immediate migration. However, research, infrastructure, and ecosystem coordination are all in place to enable rapid activation once the time is right, with no significant expected impact on network performance.

Starknet is currently the closest point of comparison to the EF's new direction. StarkWare published its roadmap on June 30, which will proceed in three phases. The first phase will replace the Pedersen hash algorithm with BLAKE2 for state commitments, contract addresses, and network configuration, while also introducing post-quantum consensus signatures such as Falcon-512. The second phase focuses on migration tooling for legacy contracts, while the final phase addresses external dependencies that still relate to Ethereum, including bridge system calls and blob data availability. The third phase depends on Ethereum's own migration path.

Compared to other public chains, Ethereum has chosen a path of "establishing standards first, then moving code." Abandoning Poseidon in favor of SHA2/BLAKE2 is essentially a choice for more mature, more widely validated cryptographic primitives in the post-quantum era.

ETH
public chain
Welcome to Join Odaily Official Community