Ethereum Boosts Security with BLS12-381 Precompiles
Ethereum has upgraded its security by introducing seven precompiles for BLS12-381 curve operations to the execution layer. The new addition replaces BN254 with a more secure pairing-friendly curve, providing 120 bits of security compared to the existing 80-bit security.
This upgrade addresses the limitations of BN254, which many zkRollup projects have identified as insufficient for advanced scalability solutions like data availability and multi-signature aggregation.
The BLS12-381 precompiles enable specific operations such as point addition, multi-scalar-multiplication (MSM), pairing checks, and field-to-curve mappings. Each operation uses specific encoding formats for field elements and curve points.
The gas schedule for these precompiles does not always align with real-world computation time. On a Ryzen 7840U, mapping an element to a G2 point achieves 702.17 MGas/s, but on an older Intel i5-5257U, that same operation only achieves 230 MGas/s.
The introduction of EIP-2537 provides the necessary cryptographic security for ZK-based scaling, but the current gas pricing for G2 operations remains inefficiently high.