On December 18, 2025, the Ethereum Foundation officially closed the proof latency phase: generation time collapsed from 16 minutes to 16 seconds, costs fell 45x, and 99% of mainnet blocks can now be proven in under 10 seconds. But a more structural problem surfaced as several cryptographic conjectures underpinning STARK-based zkEVMs were broken, forcing a new 128-bit security bar by December 1, 2026.
🔑 Key takeaways
- Proof generation: from 16 minutes to 16 seconds, costs down 45x
- 99% of mainnet blocks provable in under 10 seconds
- Several proximity assumptions in STARK/SNARK low-degree tests have been mathematically invalidated
- Three hard milestones: soundcalc (Feb 2026), 100 bits (May 2026), 128 bits (Dec 2026)
- JPMorgan launches its first tokenized money market fund ($100M) on Ethereum
Speed won, security still in progress
In one year, proof generation times for an Ethereum block dropped from 16 minutes to 16 seconds, costs fell by a factor of 45, and 99% of mainnet blocks can now be proven in under 10 seconds on target hardware. These figures, released by the Ethereum Foundation on December 18, 2025, were measured on the public EthProofs dashboard. The performance seemed to mark the official end of the real-time proof latency phase.
But the foundation immediately added a caveat: speed without soundness is a liability, not an achievement. Over recent months, several mathematical conjectures on which many STARK-based zkEVMs rely have begun to be falsified. In particular, the proximity assumptions used in low-degree tests of SNARKs and STARKs built on hash functions have been mathematically broken, lowering the effective security level in bits of the parameter sets that depend on them.
« If someone can forge a zkEVM proof, they can forge anything: mine tokens out of thin air, rewrite chain state, steal funds. »
Ethereum Foundation, blog post dated December 18, 2025

Three hard milestones and a canonical tool
To address this threat, the foundation structured its response around three calendar milestones announced on December 18, 2025 and detailed in February by Dmitry Khovratovich, Arantxa Zapico, and George Kadianakis from the foundation’s cryptography research team. The central tool is soundcalc, a public calculator that estimates the security of a proof system from current cryptanalytic bounds and scheme parameters: each team must integrate its circuits, and any new attack can be immediately reflected in the estimates.
M1, M2, M3: timeline and requirements
| Milestone | Deadline | Main requirement | Proof size |
|---|---|---|---|
| M1 | End of February 2026 | Circuit integration into soundcalc | — |
| M2 (Glamsterdam) | End of May 2026 | ≥ 100 bits of provable security via soundcalc + architecture sketch | ≤ 600 KiB |
| M3 | December 1, 2026 | 128 bits provable + formal security argument | ≤ 300 KiB |
M3 quietly slips from the initial roadmap that already targeted 128 bits and 300 KiB for December 2025. The move to December 2026 leaves time for reviews before the holiday season, according to the research team. M2 acts as an intermediate tier at 100 bits, deemed sufficient for early deployment but incompatible with sensitive production use.
A three-step architecture whitepaper
In parallel, teams must publish a zkVM architecture whitepaper in three milestones: W1 on May 1 with an overview (segmentation, recursive structure); W2 on September 1 with detailed sections on buses, memory, instruction fetch, and recursion; W3 on December 1 with a formal security argument proving that the zkVM constitutes a knowledge argument.
WHIR, JaggedPCS, and the better.codes challenge
The foundation leans on recent cryptographic advances to make these targets achievable. WHIR, a new Reed-Solomon proximity test that also serves as a multilinear polynomial commitment scheme, offers transparent post-quantum security and produces smaller proofs with faster verification than traditional FRI schemes at the same security level. The post also cites JaggedPCS, a set of techniques that avoids over-padding when encoding execution traces as polynomials: provers skip wasted work while still producing compact commitments.
A public research challenge, better.codes, measures in real time the security gap on specific parameters. On August 21 at 15:44 UTC, the live dashboard showed for the koalaIRS12 profile (fixed parameters for an interleaved Reed-Solomon reduction) a lower certificate of 63.99 bits and an upper certificate of 116.13 bits, leaving 52.14 bits unresolved after nine promoted submissions from seven solvers. The production target requires 128 bits at the system level, out of reach until the interval closes.
« Once teams hit these targets and zkVM architectures stabilize, the formal verification work we have invested can reach its full potential. »
George Kadianakis, cryptography team, Ethereum Foundation
Ethereum doubles down on institutional adoption
Alongside the cryptographic workstream, the foundation launched in October a dedicated portal for financial institutions: « Ethereum for Institutions ». The platform highlights the network’s decade-long track record, with more than 1.1 million validators and continuous uptime. It stresses the role of zero-knowledge proofs, fully homomorphic encryption, and trusted execution environments for compliant applications.
JPMorgan opens the door to tokenized money market funds
| Metric | Value |
|---|---|
| Share of tokenized real-world assets hosted on Ethereum | 66% (source: RWA.xyz) |
| Initial allocation to the MONY fund (JPMorgan) | $100M |
| Minimum investment | $1M (qualified investors) |
| Distribution platform | Kinexys Digital Assets |
John Donohue, head of asset management at JPMorgan, told the Wall Street Journal that there is « massive interest » from clients in tokenization and that the bank intends to lead the segment with offerings designed to replicate traditional money market funds on the blockchain.
Conclusion: security as prerequisite, not guarantee
The Ethereum Foundation’s reset puts the cryptographic bar back at the center of the roadmap. Reaching 128 provable bits on soundcalc and publishing a formal argument for the recursion topology does not close the debate: it opens an audit and review cycle in which every broken conjecture must be integrated. The W1 to W3 whitepapers and the better.codes challenge turn security into a living process rather than a marketing figure.
If M1 and M2 are met, a 100-bit zkEVM deployment becomes credible by mid-2026. If M3 is missed, the network stays stuck in a trade-off between proof cost and cryptographic trust. In either scenario, institutional capital — JPMorgan at the front — arrives only after the mathematical guarantee, not before.
Sources
- CryptoSlate – Ethereum researchers are racing to close a zkEVM security gap before December
- Ethereum Foundation – Cryptography research update
- InvestingLive – Ethereum puts security ahead of speed
- TradingView – Ethereum shifts focus from speed to security
- CryptoRank – Ethereum Foundation refocuses on security
- Galaxy Research – zkEVMs: the future of Ethereum scalability
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

