
Three developers have submitted a proposal (EIP-8394) to prepare Ethereum's deposit contract for post-quantum cryptography.
Three developers submitted EIP-8394 to adapt the Ethereum deposit contract to future post-quantum cryptography standards, anticipating the vulnerability of current BLS signatures to future quantum computers.
AI-generated summary
Ethereum's current deposit contract uses the BLS12-381 scheme, vulnerable to future quantum computers using Shor's algorithm.
A lock that is changed before the burglary, not after. Three developers submitted this week a draft EIP (Ethereum Improvement Proposal, the standard format for submitting a modification to the protocol) which touches on one of the most sensitive cogs of Ethereum, the deposit contract. It is through him that each validator enters into staking (staking, the mechanism which secures the network against a stake in ETH). The objective is simple to state, much more difficult to execute. Make room for keys that the quantum computer cannot break, before the threat becomes real.
The deposit contract, this lock that we had not thought of expanding
Kevaundray Wedderburn, Tom Wambsgans and Thomas Coratger submitted their text on August 24 to the EIP GitHub repository, in the form of a draft awaiting review. An editor has already suggested numbering it EIP-8394, but nothing has been done.
The problem they solve is almost stupid once stated. The current deposit contract hardcodes the dimensions of BLS12-381, the signature scheme used by all validators since the move to proof of stake in 2022.
Concretely, 48 bytes for a public key, 96 for a signature, not one more. Post-quantum schemes require significantly more space. The new contract would increase this cap to 8,192 bytes, with a schema identifier attached to each repository. The zero scheme remains BLS, the following remain vacant, waiting for a future proposal to decide which post-quantum cryptography will fill them.
Why BLS, precisely, is the fragile link
BLS owes its success to practical sleight of hand. It aggregates hundreds of thousands of validator signatures into one, which keeps the cost of consensus bearable. But this elegance relies on elliptic curves, and elliptic curves are precisely what Shor's algorithm knows how to dismantle, provided you have a quantum computer powerful enough to run it.
For the moment, this machine does not exist. 42.4 million ETH, or approximately $104 billion, remain staked and therefore protected by this same theoretically vulnerable BLS, according to figures relayed by CoinDesk. A Google Quantum AI study published in March mapped five quantum attack scenarios targeting Ethereum, placing more than $100 billion in assets at risk in total. The Project Eleven firm estimates that the probability that a machine capable of breaking elliptic curves will exist by 2033 is more than one in two, with a possible deadline as early as 2030. More than 65% of the ETH in circulation is already sleeping in addresses whose public key has been exposed on-chain. A ready-made boulevard for those who know how to use it.
The text provides three states for the contract, deactivated, BLS active, then BLS retired. Once switched to this last mode, no new BLS deposit would ever be accepted, with no possible return. However, the validators already in office would not disappear. Only new entrants should present a key conforming to the future scheme, which remains, at this stage, an empty box.
The proposal builds on EIP-7685, the channel already used to escalate deposits, withdrawals and validator mergers to the consensus layer. At the same time, a cousin project is running, EIP-8141, examined for the next Hegotá upgrade, which would allow an ordinary account to change its signature cryptography without changing address. Thomas Coratger, one of the three authors, summarized the work of cryptographer Dan Boneh on the subject on August 24. Bitcoin and Ethereum both lean towards signatures based on hash functions rather than curves, a variant whose format retained by NIST weighs precisely 8 kilobytes. “Post-quantum cryptography isn’t a simple upgrade,” he summarized on
AI outlook — possibilities, not facts
Integration of the proposal in a future upgrade of the Ethereum protocol.
Possible · Within years

Andrew Bailey, président du FSB et gouverneur de la Banque d'Angleterre, avertit les ministres des Finances et gouverneurs des banques centrales du G20 que les modèles d'IA les plus avancés pourraient accroître la vitesse, l'ampleur et le coût des cyberattaques, tout en amplifiant les risques financiers liés à l'endettement et à la valorisation des actifs numériques, dans un contexte de tensions économiques mondiales.

Six blockchains de l'écosystème Cosmos ont été touchées par des attaques exploitant une faille critique dans Cosmos EVM, permettant le vol d'environ 5,7 millions de dollars d'actifs après un signalement ignoré en avril.

Entre juillet et août 2026, une faille de sécurité vieille de cinq ans dans les portefeuilles matériels Coldcard a permis le vol d'environ 1 824 BTC, soit près de 140 millions de dollars, touchant des milliers d'adresses.

La communauté GnosisDAO a approuvé la transition de Gnosis Chain d'une blockchain layer 1 autonome vers un rollup au sein de l'Ethereum Economic Zone (EEZ), avec 123 158 GNO favorables contre 115 défavorables et 151 abstentions. Le changement, prévu pour fin 2026 ou début 2027, vise à améliorer la sécurité et l'interopérabilité en s'appuyant sur Ethereum plutôt que sur ses propres validateurs.

Manchester Airports Group a subi une intrusion informatique compromettant les données de 8,7 millions de clients. Les informations dérobées incluent des adresses e-mail, numéros de téléphone et plaques d'immatriculation, exposant les usagers à des risques de phishing.

Le 28 août, la juge fédérale Rita F. Lin a annulé la décision du Pentagone de mettre Anthropic sur liste noire, jugée comme une représaille illégale au titre du Premier Amendement. Le ministère avait sanctionné l'entreprise pour avoir refusé que son modèle Claude serve à la surveillance de masse et aux armes autonomes. Malgré un contrat de 200 millions de dollars avec le Pentagone, Anthropic a subi des pressions politiques après des déclarations de Trump et Hegseth. La juge a rejeté l'utilisation du 10 U.S.C. § 3252, destiné à écarter les fournisseurs étrangers, comme un détournement dans un différend contractuel. Une seconde désignation sous la loi FASCSA reste pendante. Cette décision crée un précédent pour les fournisseurs technologiques de l'État américain face aux pressions politiques.