The Ethereum Foundation on August 13 abandoned Poseidon, the specialized hash function it had pursued since 2018 for zero-knowledge proof integration into the base layer, in favor of conventional SHA-2 or BLAKE alternatives. Core researcher Justin Drake confirmed the pivot after a July 29 academi...
The Ethereum Foundation on August 13 abandoned Poseidon, the specialized hash function it had pursued since 2018 for zero-knowledge proof integration into the base layer, in favor of conventional SHA-2 or BLAKE alternatives. Core researcher Justin Drake confirmed the pivot after a July 29 academic paper demonstrated that binary-field proof systems can now handle standard hashes at speeds that eliminate Poseidon's former advantage.
The decision affects Ethereum's forward-looking L1 architecture — specifically a planned "leanVM" targeted for 2027 and cross-layer deployments in 2028 — but issues no migration order to the zk-rollup ecosystem, where Poseidon secures an estimated $13 billion or more in total value locked across zkSync Era ($4.1B), Linea ($3.4B), Scroll ($2.1B), World Chain ($1.8B), and Starknet ($1.5B), according to DeFiLlama data from Q2 2026.
The shift aligns with Ethereum's broader post-quantum roadmap, which targets full quantum resistance by approximately 2029 through seven planned hard forks. A dedicated Post-Quantum Security team, led by Thomas Coratger, has been operational since January 2026.
Poseidon was designed in 2019 to solve a specific engineering constraint: standard hash functions like SHA-256 and Keccak operate on Boolean logic (bitwise XOR, AND, rotation), which is expensive to represent inside SNARKs that use large prime-field arithmetic. Poseidon used arithmetic operations native to these prime fields, yielding 10-100x proving speed advantages over standard hashes inside zk-circuits.
That advantage no longer holds.
Binary-field proof systems — notably Binius, published by Ethereum Foundation researchers, and its successor Flock, posted July 29, 2026, by Benedikt Bünz, Ron Rothblum, and William Wang — work over F₂ (the binary field) and its extensions. This eliminates the embedding overhead that made Boolean operations costly in traditional SNARKs. The result: standard hashes can now be proven at speeds within 250x of native CPU execution, a threshold the Ethereum Foundation considers sufficient for production use.
Drake summarized the shift: researchers built "hash-friendly SNARKs, reducing the need for SNARK-friendly hashes." Poseidon, he emphasized, "is not broken." The technology simply rendered its core value proposition redundant for Ethereum's L1 plans.
The Ethereum Foundation's engagement with specialized hash functions spans from 2018 to the present:
Drake described the total investment as an "8-figure" sum. The Poseidon Cryptanalysis Initiative Phase 2, focused on Poseidon over the KoalaBear prime field, remains active through December 2026 — the Foundation continuing security vetting even as it redirects L1 engineering elsewhere.
The Flock paper provides the concrete performance data that underpins the Foundation's decision. Key benchmarks on a single M4 Max core:
| Hash Function | Compressions/sec (1 core) | Compressions/sec (10 cores) | |---|---|---| | BLAKE3 | ~82,000 | >660,000 | | SHA-256 | ~42,000 | — | | Keccak | ~30,000 | — |
Additional performance context:
At these speeds, the Foundation calculates approximately 1 million traditional hash calls can be proven per second on commodity hardware. This crosses the practical threshold for L1 consensus, data availability, and execution layer applications.
The announcement explicitly scopes the change to Ethereum's own future L1 architecture. No migration order has been issued to rollups, zkVMs, or other projects currently using Poseidon.
This distinction matters. Poseidon is embedded in the proving circuits of major infrastructure:
| Protocol | TVL (Q2 2026) | Hash Usage | |---|---|---| | zkSync Era | $4.1B | Poseidon in state tree | | Linea | $3.4B | Poseidon variants | | Scroll | $2.1B | Poseidon for Merkle proofs | | World Chain | $1.8B | ZK proving infrastructure | | Starknet | $1.5B | Pedersen/Poseidon hybrid |
Collective ZK-rollup TVL secured by Poseidon-based or Poseidon-adjacent cryptography exceeds $13 billion. Replacing Poseidon in deployed circuits would require re-auditing proving systems, migrating state trees, and coordinating upgrades across independent protocol governance structures. No timeline for such migrations exists, and the Foundation has not requested one.
However, the signal is clear: new projects designing proving systems from scratch now face a changed recommendation landscape. SHA-2 and BLAKE carry decades of cryptanalysis, NIST standardization, and hardware acceleration (Intel SHA Extensions, ARM Cryptography Extensions). Poseidon, by contrast, has approximately seven years of public cryptanalysis, and the Foundation's own bounty program remains in progress.
The Poseidon pivot is one element of a broader post-quantum defensive strategy. In March 2026, Google Quantum AI published research estimating that breaking 256-bit elliptic curve cryptography — the signature scheme Ethereum uses for account authentication — would require approximately 1,200 logical qubits. This figure, roughly 20x lower than previous estimates, compressed the perceived threat timeline.
The Ethereum Foundation responded with the "Strawmap": a structured sequence of seven hard forks targeting full quantum resistance by approximately 2029.
Key milestones:
The pivot to SHA/BLAKE aligns with this timeline. Standard hashes have known, well-characterized quantum resistance profiles. SHA-256 requires Grover's algorithm to attack, reducing effective security from 256 bits to 128 bits — still considered adequate. BLAKE2s and BLAKE3 carry similar properties. Poseidon's algebraic structure, while not known to be quantum-vulnerable, has not undergone equivalent quantum cryptanalysis.
The Foundation is adopting ERC-4337 account abstraction to enable "cryptographic agility" — users can voluntarily migrate from ECDSA to quantum-secure authentication without network-wide forced upgrades.
The preference for standard hashes reflects a risk-adjusted engineering calculus:
Audit history: SHA-2 has been publicly analyzed since 2001 (25 years). BLAKE was a SHA-3 finalist in 2012. Poseidon's preprint dates to 2019 (7 years). For infrastructure securing hundreds of billions in value, audit depth functions as a form of security capital.
Hardware acceleration: SHA-256 benefits from dedicated CPU instructions on Intel (SHA-NI, available since 2016) and ARM (Cryptography Extensions). BLAKE3 is designed for SIMD parallelism. Poseidon has no hardware acceleration path and is unlikely to receive one given its niche use case.
Standardization: SHA-2 is NIST-approved (FIPS 180-4). BLAKE2 is described in RFC 7693. Poseidon has no standards-body endorsement. For institutional and regulatory contexts — increasingly relevant as TradFi enters on-chain infrastructure — this gap carries compliance weight.
Quantum resistance profile: Standard hashes have well-understood quantum attack vectors (Grover's algorithm halves effective bit security). Poseidon's algebraic structure over prime fields presents a different, less-studied attack surface under quantum threat models.
The tradeoff Poseidon offered — faster ZK proving at the cost of shorter audit history and no hardware support — made sense when binary-field proofs were theoretical. With Flock demonstrating production-viable speeds, the tradeoff no longer justifies the risk premium.
The Poseidon pivot represents a rare case of an infrastructure project voluntarily abandoning years of specialized research because the general-purpose alternative caught up. The Ethereum Foundation spent eight years and eight figures building toward a future where ZK proofs required exotic hash functions. Advances in binary-field proof theory — primarily through Binius and Flock — made that future unnecessary.
For the $13 billion-plus ZK-rollup ecosystem, the immediate operational impact is nil: no migration is required, and Poseidon remains functional. The long-term signal, however, is significant. New protocol designs will increasingly default to standard hashes, backed by deeper cryptanalysis, hardware acceleration, and clearer quantum resistance profiles. The Poseidon Cryptanalysis Initiative continues through December 2026, but its findings will inform rollup-level decisions rather than L1 architecture.
The decision also illustrates a pattern relevant to blockchain infrastructure broadly: the economic value of cryptographic choices compounds over time. Ethereum's willingness to write off an 8-figure research program rather than deploy a less-audited primitive reflects a maturation in how the network weighs security capital against performance gains.