The Ethereum Foundation has committed over $22 million in direct funding — a $20 million formal verification initiative and $2 million in cryptographic research prizes — to replace the network's transaction re-execution model with zero-knowledge proof verification at the base layer. The effort, c...
"Resilience is still the soul of Ethereum." — Hsiao-Wei Wang, Co-Executive Director, Ethereum Foundation
The Ethereum Foundation has committed over $22 million in direct funding — a $20 million formal verification initiative and $2 million in cryptographic research prizes — to replace the network's transaction re-execution model with zero-knowledge proof verification at the base layer. The effort, codified in the L1-zkEVM 2026 roadmap and EIP-8025, would allow validators to confirm blocks via compact mathematical proofs rather than maintaining full execution-layer state, potentially reducing hardware requirements for node operators currently facing $1,000–$2,000 in equipment costs plus 4–8 TB of NVMe storage.
Three competing zkVM vendors — Succinct (SP1 Hypercube), ZKsync (Airbender), and RISC Zero (R0VM 2.0) — are racing to deliver real-time proving capability, defined as sub-12-second proof generation to match Ethereum's block time. The stakes are material: Ethereum secures over $55.6 billion in DeFi TVL and more than $105 billion in staked ETH across 1 million+ validators spanning 80 countries. A successful transition to proof-based validation would represent the largest deployment of zero-knowledge cryptography in production, potentially reshaping the economics of network participation.
The transition depends on the Glamsterdam hardfork delivering Enshrined Proposer-Builder Separation (ePBS), which extends the proving window to 6–9 seconds. Without it, single-slot proving remains infeasible for production use. The Foundation has set a 100-bit provable security threshold by May 2026, with full 128-bit security targeted by year-end — acknowledging that recent research has disproven mathematical conjectures underpinning some existing STARK-based systems.
EIP-8025, published as part of the L1-zkEVM 2026 roadmap on the Fellowship of Ethereum Magicians forum, introduces a new validator role: the zkAttester. Unlike conventional attesters that re-execute every transaction in a proposed block, zkAttesters verify cryptographic proofs confirming that execution was performed correctly.
The specification establishes a 3-of-5 threshold model. Attesters must verify three out of five independent proofs — generated from different execution client implementations — before accepting a block's execution as valid. Proofs circulate through a dedicated peer-to-peer gossip network separate from existing block propagation channels.
The 2026 roadmap divides implementation across six sub-themes:
The first L1-zkEVM workshop convened on February 11, 2026. The design assumes a 1-of-N liveness model, meaning one honest prover is sufficient to maintain chain operation. According to the roadmap documentation, "proving should remain viable outside of data centre infrastructure" — a stated goal to prevent centralization of the prover role.
Phase One, expected in 2026, targets up to 10% of validators switching to proof-based verification. Phase Two would make proofs mandatory for block producers.
The ZK proving industry has attracted over $3 billion in cumulative funding since 2020. Three vendors currently demonstrate the ability to prove Ethereum blocks, each with distinct architectural trade-offs.
Succinct Labs, which raised $55 million in a Paradigm-led Series A, has built SP1 Hypercube from the ground up using multilinear polynomials. The system proves 99.7% of Ethereum L1 blocks in under 12 seconds using 16 NVIDIA RTX 5090 GPUs, according to the company's published benchmarks. A live demonstration proved block 22309250 in 10.8 seconds, generating a 1MB proof.
Hardware cost for a cluster capable of real-time proving: $300,000–$400,000 using 160 RTX 4090 GPUs, with potential reduction to $100,000 using more cost-efficient configurations. The company's 2026 roadmap includes FPGA acceleration in Q2 2026, which it claims could boost proof generation speeds by 20x.
ZKsync's Airbender achieves 21.8 million cycles per second on a single NVIDIA H100 GPU — more than 6x faster than competing systems on a per-GPU basis, according to ZKsync's published benchmarks. It proves Ethereum blocks in approximately 35 seconds on a single GPU (17 seconds without recursion).
The cost advantage is significant: approximately $0.0001 per transfer, described as more than 10x cheaper than ZKsync's previous Boojum prover. Airbender is live on mainnet, powering all new ZKsync Chains. The system is open-source and positions itself as a potential universal standard for zero-knowledge proving.
RISC Zero, backed by a $40 million Series A, reduced Ethereum block proving from 35 minutes to 44 seconds with R0VM 2.0. While slower than the competition in raw proving speed, the company operates Boundless, a decentralized proof marketplace live on mainnet since September 2025 with 542.7 trillion cycles processed across 399,000 orders.
RISC Zero's Zeth project — an open-source "Type 0" zkEVM — runs revm (a Rust EVM implementation) inside the zkVM, maximizing code reuse with existing Ethereum execution clients.
| Vendor | Hardware | Proving Time | Cost per Transfer | Status | |--------|----------|-------------|-------------------|--------| | Succinct SP1 Hypercube | 16x RTX 5090 | <12s (99.7% of blocks) | Not disclosed | Testnet | | ZKsync Airbender | 1x H100 | ~35s (17s w/o recursion) | ~$0.0001 | Mainnet | | RISC Zero R0VM 2.0 | Not specified | ~44s | Not disclosed | Mainnet (Boundless) |
The comparison is imperfect. SP1 Hypercube achieves lower latency but requires substantially more GPUs. Airbender optimizes for single-GPU efficiency. RISC Zero prioritizes a decentralized marketplace model. The Ethereum Foundation's multi-prover design explicitly accommodates this diversity: any conforming zkVM can generate proofs that the consensus layer accepts.
The Ethereum Foundation's December 2025 blog post, "Shipping an L1 zkEVM #2: The Security Foundations," disclosed a structural concern: many STARK-based zkEVMs rely on unproven mathematical conjectures to meet security targets. Recent cryptanalytic research disproved some of these conjectures, reducing the effective security of deployed systems below claimed levels.
The Foundation's response has three components:
$20M Formal Verification Project. Led by Alex Hicks, who joined the Foundation in June 2024 and became Team Lead for Protocol Snarkification in June 2025, this initiative formally verifies SNARK primitives, zkVM circuits, and the EVM guest program. Progress across three tracks — RISC-V circuits (verified against the Sail specification), the EVM guest program, and cryptographic primitives — is described as showing "high confidence" in circuit correctness.
$1M Poseidon Prize. The Foundation established this prize to strengthen the Poseidon hash function, a component in ZK proof systems and privacy tools. The contest invites cryptographers worldwide to propose improvements that harden the function against potential quantum exploits.
$1M Proximity Prize. A separate prize targeting broader post-quantum cryptographic research.
The security timeline is rigid. By Glamsterdam (targeted May 2026), all participating prover systems must demonstrate 100-bit provable security as measured by soundcalc, a standardized security evaluation tool. Full 128-bit provable security is required by end of 2026. The Foundation has stated explicitly: "If an attacker can forge a proof, they can mint tokens from nothing, rewrite state, and steal funds."
Running an Ethereum full node in 2026 requires a modern 8-core CPU, 32–64 GB RAM, 4–8 TB NVMe SSD, and 300–500 Mbps bandwidth, according to multiple infrastructure guides. Archive nodes demand 18–20 TB for Geth. Hardware costs range from $1,000–$2,000, excluding ongoing bandwidth expenses of at least 2 TB per month.
A zkAttester, by contrast, does not need to hold execution-layer state. It does not need to sync the full execution-layer chain. Verification of a compact proof replaces the computational burden of re-executing every transaction.
The economic shift, if realized, would redistribute costs within the validator ecosystem. Proof generation becomes the computationally expensive step — requiring GPU clusters costing $100,000–$400,000 for real-time performance — while proof verification becomes cheap. This mirrors the economic structure of existing rollups, where provers bear capital costs and validators consume minimal resources.
With over 1 million validators currently operating across 80 countries, reducing the hardware barrier could expand the validator set, particularly in regions where storage and bandwidth costs are prohibitive. Alternatively, it could concentrate proving in the hands of well-capitalized GPU operators — a centralization risk the Foundation acknowledges by insisting proving remain feasible outside data centers.
In January 2026, the Ethereum Foundation elevated post-quantum security to a top strategic priority, forming a dedicated team led by cryptographic engineer Thomas Coratger. Researcher Justin Drake stated that Ethereum is shifting from background research to active engineering, including biweekly developer sessions on post-quantum transactions and multi-client post-quantum consensus test networks.
According to Coratger, Ethereum already has test networks running with post-quantum signatures. The timeline acceleration is driven by advances in quantum computing hardware — a development the Foundation characterizes as narrowing the window for proactive preparation.
The intersection with the L1-zkEVM roadmap is direct: ZK proof systems themselves must be quantum-resistant. The Poseidon Prize and Proximity Prize both target this requirement. If the cryptographic primitives underlying the proof systems are vulnerable to quantum attacks, the entire L1-zkEVM architecture inherits that vulnerability.
ePBS dependency. The L1-zkEVM system requires Enshrined Proposer-Builder Separation, targeted for the Glamsterdam hardfork. ePBS extends the proving window to 6–9 seconds through block pipelining. Without this extension, real-time proving within the current 12-second block time is not feasible for most implementations. Any Glamsterdam delay cascades directly into the zkEVM timeline.
Prover centralization. Real-time proving currently requires $100,000–$400,000 in GPU hardware. The 1-of-N liveness model means one honest prover maintains chain operation, but economic incentives could concentrate proving among a small number of operators. The Foundation's stated goal of data-center-independent proving has not been demonstrated at production scale.
Security conjecture risk. The Foundation's own disclosure that "recent research has disproven some foundational conjectures" in existing STARK systems indicates the security landscape remains unsettled. New cryptanalytic results could invalidate assumptions in currently deployed prover systems, requiring costly re-engineering.
Coordination complexity. Six development sub-themes, multiple zkVM vendors, a multi-client proof verification model, and a phased rollout create substantial coordination overhead. The multi-prover 3-of-5 threshold model has no precedent in production blockchain systems.
The L1-zkEVM initiative represents Ethereum's most structurally significant upgrade since the Merge. The economics are straightforward: shift computational burden from every validator to specialized provers, reduce participation costs for attesters, and secure $55.6 billion in DeFi TVL with mathematical guarantees rather than redundant execution.
The engineering challenges are equally straightforward. No production blockchain has implemented multi-vendor zero-knowledge proof verification at the consensus layer. The security foundations are under active revision following the invalidation of previously relied-upon conjectures. The GPU cost structure for real-time proving currently favors institutional operators, regardless of stated decentralization goals.
The ZK proving industry's $3 billion in cumulative funding has produced measurable capability — sub-12-second Ethereum block proofs exist — but the gap between vendor demos and production consensus integration remains substantial. The 2026 timeline is ambitious. Whether it holds depends on Glamsterdam shipping on schedule, the security milestones being met without further conjecture invalidation, and the multi-prover coordination model functioning at scale.
The data suggests capability is ahead of schedule. The institutional and coordination risks are the binding constraints.