Ethereum's Privacy Upgrade Has a 90,000-Gas Gap Nobody's Filling
A Sept. 5 tweak to EIP-8141 lets some nodes accept heavier privacy transactions. Problem is the benchmark says one Groth16 proof needs 190,628 gas. The cap is 100,000. That's not a rounding error. That's a chasm.
Ethereum's privacy push just hit a wall. Not a philosophical wall. A math wall.
The numbers don't work. And anon, let me save you some gas fees on the debate: this isn't close.
The Timeline
Let's rewind to Sept. 2. Researcher mmjahanara drops a benchmark on ethresear.ch. The target is EIP-8141, Ethereum's proposed Frames transaction design. The finding: an optimized Groth16 proof verifier needs 190,628 gas just to run.
That's nearly double the 100,000-gas cap the current draft allows for initial validation. The cryptographic pairing check alone eats 181,000 gas. Already over budget before anything else executes.
Three days later, on Sept. 5, contributor AnkushinDaniil opens a pull request. The idea: turn that 100,000-gas validation maximum into a floor. Nodes would have to propagate transactions within the limit. But capable nodes could accept more expensive ones locally. Optional flexibility. No network-wide commitment.
Sounds reasonable on paper. But here's the thing: it doesn't solve the problem.
Allowing some nodes to accept heavier transactions doesn't mean those transactions will travel across the public network. You need propagation. You need the whole chain to play ball, not just the nice nodes.
And the benchmark isn't even the worst-case scenario. The full model reports minimums of 211,828 gas for a single-note spend. An eight-note spend? That's 351,828 gas. The author recommends at least 250,000 gas for typical optimized transactions. Even that wouldn't cover the eight-note total.
The proposal's author suggests a 100,000-gas guarantee. The benchmark says one specific proof component needs 190,628. Who's right?
Honestly? Doesn't matter. The gap is too wide for either side to wave away.
The Numbers Problem
Let's get concrete about what's at stake here.
Tornado Cash and RAILGUN designs depend on proofs that nodes will accept and propagate. If those proofs cost more than the validation budget, they don't get through. Simple as that.
This isn't about node operators being cheap. It's about DoS exposure. Lower gas caps mean lower attack surface. Raise the cap too much and you invite spam. Keep it too low and privacy apps can't function.
The benchmark assumes some application-level changes. Moving non-verification work into later frames. Optimizing verifiers. Compressing proof inputs. All that helps. But the SHA-256 compression option increases the work required to generate proofs on users' devices. You're just moving the bottleneck around.
There's also an accounting discrepancy worth noting. The benchmark charges nullifier costs to execution gas. EIP-8250, the companion draft, charges fresh nonce keys to state gas instead. Different budgets. The totals don't directly compare.
But that accounting difference doesn't erase the core problem. The verifier's execution cost still blows past the proposed allowance. You can shuffle the books all you want. The math doesn't cooperate.
Even if you accepted a 250,000-gas allowance, the eight-note spend at 351,828 gas still gets rejected. So what's the actual number? Nobody's saying. And that's the issue.
This is the alpha nobody's sharing: privacy on Ethereum keeps getting framed as a policy problem. It's not. It's an engineering constraint. Gas is computational work. Privacy proofs are computationally expensive. You can't negotiate with arithmetic.
I aped in so you don't have to. I've read the EIPs. I've stared at the benchmark tables. The conclusion is uncomfortable for anyone hoping Frames solves privacy overnight.
What Comes Next
So where does this leave us?
The practical decision is how to accommodate privacy-proof validation while bounding node work. The September proposal offers optional flexibility at individual nodes. Guaranteed public access for these privacy designs would require accommodating their proof costs across the entire network.
That's a harder sell. Node operators don't want to eat the cost of verifying 350,000-gas privacy transactions. Not when they're already worried about block validation time and MEV extraction.
There's also EIP-8250's constraint: one pending public-mempool transaction per sender. That's another obstacle for privacy designs sharing an address. Even with a bigger gas allowance, you can't have multiple transactions queued from the same identity.
And public propagation is distinct from block validity. EIP-8141 allows transactions outside its public rules into local or private mempools. The informational EIP-8369 proposal describes future rules for inclusion enforcement. But it requires a binding protocol extension. That's not coming tomorrow.
The trenches don't sleep, and neither does the math.
My take? The 100,000-gas cap is dead on arrival. It was designed for simple signature checks and basic execution. Privacy proofs in their current form don't fit. The question is whether Ethereum's core devs will accept that before or after another year of debate.
Realistically, we're looking at EIP-8141 getting revised upward. The alternative is watching privacy apps continue to rely on off-chain relayers, which is exactly what this proposal was trying to eliminate.
Relayers introduce trust assumptions. They create censorship vectors. They're the reason privacy protocols keep getting compromised. If Frames can't handle the proof costs, we're stuck with the status quo.
And the status quo isn't great. Privacy users keep getting exposed. Bots keep front-running. The money keeps flowing to the fastest predators.
The crypto market doesn't care about the gas math until a privacy protocol fails. Then it cares a lot. Ask anyone holding bags from the last Tornado Cash enforcement action.
I'm not saying the sky is falling. Ethereum has solved harder problems. But this one needs attention now, not after another upgrade slips.
Remember, the next major upgrade already slipped to late 2026. That forced a two-week scramble to save the 2027 roadmap. Core devs are stretched thin. Adding a privacy-proof gas negotiation to the pile isn't going to speed things up.
So here's my honest read: someone needs to bite the bullet and propose a realistic gas number. Not 100,000. Not 250,000. Something that actually covers the proofs privacy apps need to ship.
That number might be ugly. It might make node operators uncomfortable. But pretending the problem doesn't exist won't make the verifier cheaper.
Not financial advice, but I'm watching this EIP like a hawk. The resolution tells you whether Ethereum actually wants privacy or just wants to talk about it.
Talk is cheap. Proofs aren't.