Ethereum Proposes Restructuring Staking Entry for Quantum Migration
Ethereum developers submitted draft EIP to replace the existing validator deposit entry with a "post-quantum ready" deposit contract, reserving an interface for future changes to the validator password system; the proposal has not yet been reviewed or included in any network upgrades.
The new design removes the fixed-length BLS public key and signature fields in the existing contract, instead supporting variable-length public keys, signatures, and credential metadata; each item has a limit of 8192 bytes to accommodate potentially larger post-quantum signatures or credential structures in the future.
Each validator deposit must declare a "credential scheme" number. Scheme 0 is reserved for the existing BLS system, ensuring compatibility of the current validator deposit path during the transition period; future scheme numbers may correspond to an undecided post-quantum signature system. The draft does not formally determine specific post-quantum algorithms.
The proposal designs three states: disabled, BLS enabled, and BLS permanently retired. The system may first allow new BLS deposits, which can later enter a "permanently retired" state through protocol upgrades; once triggered, new deposits under scheme 0 will be permanently prohibited and cannot be re-enabled. Existing BLS validators will not automatically exit due to the switch, and how to handle old validators, exits, withdrawal credentials, and migrations still needs to be resolved by subsequent rules.
Deposit data processing will also shift from the old contract's Merkle tree mechanism to a log-derived path based on EIP-7685 execution layer requests, transmitting validator deposit information from the execution layer to the consensus layer. This move aims to reduce the deposit mechanism's binding to specific password formats and historical contract structures.
The draft authors include Kevaundray Wedderburn, Tom Wambsgans, and Thomas Coratger. The proposal was submitted on GitHub as PR #12235, still marked as Draft, with no confirmed contract address, deployment code, activation time, or assigned formal EIP number.
Current post-quantum research focuses on hash-based signatures, such as leanXMSS; such schemes avoid reliance on elliptic curve structures vulnerable to Shor's algorithm, but the signature size is significantly larger than current BLS signatures. The 8192-byte limit reserves space for larger schemes and does not imply that leanXMSS has been formally selected by Ethereum.
In market mechanisms, the draft will not immediately change ETH staking yields, the number of validators, or on-chain transaction costs; its role is to reduce architectural friction for future password migrations. Long-term beneficiaries include staking service providers with key rotation, hardware security module, multi-signature custody, node upgrades, and password auditing capabilities; validator operators relying on fixed BLS key processes, lacking migration tools and institutional-level operational capabilities, will face higher upgrade costs.
Source: Public Information
ABAB AI Insight
The core of this draft is not that "Ethereum is already quantum-resistant," but rather to decouple the validator entry from the hard-coded BLS format. The current validator deposit contract has fixed-length BLS public keys, signatures, and Merkle tree processing logic written in; if a post-quantum password system is determined in the future, direct replacement would involve the consensus layer, execution layer, staking service providers, custodians, and hundreds of thousands of validators. The new contract establishes a "pluggable password scheme" container first, aiming to separate future algorithm choices from the underlying deposit structure.
Capital paths will first flow to the intermediate layer of password migration, rather than the new signature algorithm itself. Validator operators need to support larger key materials, update remote signers, replace hardware security modules, rebuild key backup and rotation processes, and prove that no double signing, loss of withdrawal credentials, or validator downtime occurs during migration. For centralized or semi-centralized staking services like Lido, Coinbase, and Kraken, upgrades are operational and compliance engineering; for individual stakers, the upgrade threshold may directly impact the cost of continuing to participate in network security.
A historical comparison is the internet's phasing out of SHA-1, TLS migration, and Ethereum's shift from proof of work to proof of stake: the most challenging part of security upgrades is not releasing new standards, but enabling old systems, third-party tools, hardware, and user keys to transition simultaneously. Post-quantum migration is more complex because blockchains cannot easily modify historical public keys and signatures already left on-chain; protocols can change future validator entries but still need to separately handle old accounts, long-dormant assets, and existing validators' password exposure.
This belongs to industry chain reconstruction. The security boundary of the staking system will expand from "who holds the BLS private key" to "who can continuously manage upgradable password identities." The mechanism is that quantum risks primarily threaten the long-term security of elliptic curves and pairing passwords; once validator keys cannot be flexibly migrated, any new algorithm will struggle to enter the network. Variable credentials, scheme numbers, and irreversible BLS retirement switches effectively embed future password choices, migration sequences, and network security responsibilities into protocol governance.
ABAB News · Cognitive Law
Quantum resistance is not about changing algorithms, but first rebuilding migration channels
The harder keys are to rotate, the closer security debt approaches systemic risk
In future password competition, the first battle will be for upgrade entry points within the protocol