Author: ChandlerZ, Foresight News
After eight years of investment, why did Ethereum suddenly abandon Poseidon?
On August 13, Ethereum researcher Justin Drake posted on X that the Ethereum Foundation has decided to abandon the SNARK-friendly hash function Poseidon at the L1 layer in favor of traditional hash functions such as SHA2 or BLAKE2.
This decision is the result of eight years of research, tens of millions of dollars in investment, and a major revision to the post-quantum cryptography roadmap.
Since its launch in 2019, Poseidon has been regarded as an ideal hashing scheme for applications such as zkRollups and zkVMs, as its structure makes it cheaper and more efficient in SNARK circuits compared to traditional binary-based hash functions. However, as post-quantum security became a mandatory requirement for Ethereum, Poseidon's limitations began to surface.
Justin Drake stated that this advancement is made possible by breakthroughs in SNARK design, specifically through the use of "binary field" operations, enabling traditional hash functions to achieve performance in SNARK circuits comparable to Poseidon, which was previously optimized specifically for SNARKs—allowing approximately one million traditional hash verifications per second on a single laptop.
The article states that Poseidon has been a mainstream SNARK-friendly hashing scheme since its launch in 2019, providing security for applications such as zkRollups and zkVMs. Justin Drake noted that projections indicate a production-grade leanVM is expected to be released in 2027, with related deployments on the consensus, data, and execution layers anticipated to be completed by 2028. The Ethereum Foundation’s post-quantum team is also accelerating research related to binary fields.
Why now?
Traditional hash functions have long struggled to enter SNARKs, primarily due to differences in computational languages. SHA2, BLAKE2s, and Keccak rely heavily on Boolean operations such as XOR and bit shifting, while traditional SNARKs operate over large prime fields and simulating each bit operation incurs high constraint costs. Poseidon is designed directly around prime field arithmetic, achieving faster proof generation with fewer constraints, at the cost of a shorter algorithmic history requiring ongoing cryptographic analysis.
Binary fields switch the underlying mathematics to the smallest prime field containing only 0 and 1, and use binary extension fields to accommodate larger data. Bit operations can thus directly enter the proof system, enabling SNARKs to align with traditional hashing, shifting the technical focus from designing SNARK-friendly hashes to designing hash-friendly SNARKs.
Jim Posen and Benjamin Diamond's Binius, proposed in 2023, demonstrates a binary tower field SNARK pathway. The Flock paper by Benedikt Bünz, Ron Rothblum, and William Wang was uploaded to arXiv on July 29, 2026, achieving a benchmark on M4 Max of 82,000 BLAKE3 compressions, 42,000 SHA-256 compressions, and 30,000 Keccak permutations per second per core, with a 10-core BLAKE3 throughput exceeding 660,000.
Drake stated that a laptop can prove approximately 1 million traditional hash calls per second, with an overhead of about 100 times that of native CPU boolean operations; SNARK.fast recently achieved 1.8 million BLAKE3 operations per second on an M3 Max.
leanVM in 2027, three-tier deployment in 2028
Another key reason Poseidon was abandoned is that the timeline for post-quantum security is accelerating. Project Eleven’s report, “The Quantum Threat to Blockchains – 2026,” highlights that the rapid advancement of quantum computers poses a serious threat to blockchain security. Once a cryptographically relevant quantum computer (CRQC) emerges, Shor’s algorithm can swiftly break asymmetric encryption methods such as ECDSA—used by Bitcoin and most public blockchains—and RSA. The so-called Q-Day (Quantum Decryption Day) is projected to occur between 2030 and 2033, putting trillions of dollars in on-chain assets at risk.
Due to the long-term static nature and irreversibility of blockchain public keys, migration is extremely challenging. The report recommends immediately initiating a post-quantum cryptography (PQC) migration, including lattice-based, hash-based, and other quantum-resistant signature schemes, and transitioning gradually through hybrid solutions to avoid a full-scale quantum threat.

Justin Drake warned that AI's enhanced capabilities in cryptanalysis have recently compromised the lattice-based scheme HAWK and the isogeny-based scheme SQIsign, forcing the Ethereum Foundation to bet on hash-based schemes, which are considered more resistant to quantum attacks.
Previously, Ethereum announced its post-quantum roadmap, including the deployment of a production-grade leanVM in 2027 and full deployment across the consensus, execution, and data availability layers by 2028. The leanVM is a minimal zero-knowledge virtual machine specifically designed for post-quantum signature aggregation and is considered a core component of the entire strategy.
In March 2026, the Ethereum Foundation launched pq.ethereum.org as a post-quantum security resource center, with over ten client teams beginning weekly operations of a post-quantum interoperability testnet. The Foundation also established a $1 million Poseidon Prize and an equal Proximity Prize to advance post-quantum cryptography research. Vitalik Buterin himself has repeatedly emphasized that post-quantum security is a necessary condition for Ethereum’s “walkaway test”—Ethereum cannot be “frozen” until it achieves quantum security.
Switching hash functions will not alter the overall structure of Ethereum’s post-quantum roadmap. Validators currently use BLS signatures based on elliptic curves, while future solutions will still be built on hash-based signatures such as leanXMSS, with leanVM compressing large numbers of signatures into a single small proof per block. Ethereum’s official page previously noted that a leanXMSS signature is approximately 3,000 bytes, while a BLS signature is only 96 bytes, with leanVM targeting a compression ratio of about 250x.
SHA2 or BLAKE2s have a longer history of public analysis, allowing EF to reduce the wait time for Poseidon parameters to undergo years of cryptographic analysis. Drake's strawmap points to a production-grade leanVM by 2027, and deployment of the consensus, data, and execution layers by 2028.
Competing with peers, Solana has chosen Falcon
Ethereum is not the only major public chain preparing for the post-quantum era; in April 2026, the Solana Foundation released its post-quantum security roadmap, and its core development teams, Anza and Jump Crypto’s Firedancer, independently selected the same post-quantum signature scheme: Falcon.
Falcon is one of the post-quantum signature schemes standardized by NIST, featuring compact signatures that are well-suited for high-throughput blockchain environments like Solana.
The two validator client development teams, Anza and Firedancer, independently concluded that the post-quantum digital signature scheme Falcon is the optimal choice and have each published preliminary implementation code on GitHub. The current roadmap consists of three phases: ongoing evaluation of Falcon and alternative solutions; adopting post-quantum schemes for new wallets when quantum threats become real; and ultimately migrating all existing wallets. Additionally, Blueshift’s Solana Winternitz Vault has been operational within the ecosystem for over two years and was cited earlier this year by Google Quantum AI as a leading industry case study.
The Solana Foundation states that quantum computing poses a substantial threat still several years away; immediate migration is not required, but research, infrastructure, and ecosystem coordination are already in place and ready to activate swiftly when the time comes, with no significant impact expected on network performance.
Starknet is currently the closest counterpart to the EF’s new direction. StarkWare announced its roadmap on June 30, which will be implemented in three phases: the first phase will replace Pedersen hashing with BLAKE2 for state commitments, contract addresses, and network configuration, while also introducing post-quantum consensus signatures such as Falcon-512; the second phase will focus on migration tools for traditional contracts, and the final phase will address remaining external dependencies tied to Ethereum, including bridge system calls and blob data availability; the third phase depends on Ethereum’s own migration path.
Compared to other public blockchains, Ethereum chose a path of “establish standards first, then implement code.” Switching from Poseidon to SHA2/BLAKE2 reflects a decision in the post-quantum era to adopt more mature and widely validated cryptographic primitives.
Twitter: https://twitter.com/BitpushNewsCN
BitPush Telegram community: https://t.me/BitPushCommunity
BitPush TG subscription: https://t.me/bitpush

