Vitalik Buterin against a yellow-orange and blue cryptography network background

Vitalik Buterin Sees a 60% Chance Cryptography’s Biggest Tools Get Far Cheaper

September 7, 2026 7:40 am Comments

Vitalik Buterin is putting unusually specific odds on a future that could make some of cryptography’s most powerful tools dramatically cheaper to use.

The Ethereum co-founder says he sees a 60% chance that SNARKs, fully homomorphic encryption and indistinguishability obfuscation can eventually run with less than 10 times the cost of ordinary computation.

The post sets no product launch or Ethereum roadmap date. Buterin called the forecast optimistic and “very-non-consensus.”

It is still a striking benchmark from someone who has spent years pushing zero-knowledge proofs and programmable cryptography toward practical use.

According to CryptoSlate, Buterin measures overhead through total energy consumption and amortized computing expense. That definition accounts for the hardware and power needed to perform the protected computation over time.

The report says cheaper SNARKs could make it easier for Ethereum to raise gas limits without demanding a proportional increase in validator hardware. FHE could open more financial calculations to encrypted inputs, allowing institutions to process sensitive data while the underlying information stays private.

Indistinguishability obfuscation is further from practical use. It aims to conceal a program’s internal logic while leaving its behavior intact, and the computational burden remains enormous.

Buterin also assigned a 33% chance that all three techniques eventually approach what he described as 1+epsilon overhead. In plain English, applying the cryptography could become only marginally more expensive than running the underlying computation without it, once the workload is large enough.

His full probability estimate appears in this post:

The three technologies solve different problems.

SNARKs let one party prove that a computation was completed correctly without forcing every verifier to repeat all the work or exposing the underlying private data. They already sit behind important blockchain privacy and scaling systems.

Fully homomorphic encryption, usually shortened to FHE, is designed to let programs work directly on encrypted information. The operator can perform the computation without first seeing the raw data.

Indistinguishability obfuscation, or iO, aims at an even harder target: protecting the internal logic of a program while preserving what it does.

Buterin has called this trio the “Egyptian God Protocols” because each primitive is unusually powerful and general-purpose. In his earlier technical overview of Ethereum’s possible future, he argued that programmable cryptography can replace large amounts of application-specific security work with tools that operate across many kinds of programs.

The catch has always been cost.

A cryptographic technique can be mathematically impressive and still remain commercially marginal if it requires enormous hardware, energy or processing time. Moving the overhead below 10 times ordinary compute could put far more real applications within reach.

Buterin thinks SNARKs are the likeliest of the three to cross that line first, potentially by the end of this decade. He pointed to specialized hash functions and some large-language-model inference workloads as areas where single-digit overhead has already been reached.

His separate post on the Poseidon family of hashes shows why that progress matters now:

Poseidon was built to work efficiently inside zero-knowledge systems. That kind of specialized optimization is one reason users can already generate proofs on their own devices for modern privacy applications.

The larger prize is to bring similar economics to general-purpose computation.

For Ethereum, cheaper proofs could support more verification and privacy without requiring hardware costs to climb at the same pace. For finance, practical FHE could allow institutions to calculate over sensitive positions or customer data while keeping the inputs encrypted.

Efficient obfuscation would push the frontier further by making software logic itself harder to expose.

None of those outcomes is guaranteed. Buterin’s percentages are a personal forecast, and the hardest techniques remain far from ordinary production use.

Still, the direction is clear. Cryptography is moving from asking whether these capabilities are possible to asking how much they will cost.

If Buterin’s 60% bet proves right, the biggest change may not be a new coin or a single Ethereum upgrade. It may be that privacy and verifiable computation stop feeling like expensive special features and start becoming normal parts of software.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.