The Ethereum Foundation is walking back one of its more ambitious cryptographic bets. After spending over a year evaluating the Poseidon hash function as a potential upgrade for base-layer hashing, the foundation is now favoring SHA and BLAKE3, two well-established alternatives with decades of security research behind them.
The reason is almost counterintuitive: the very zero-knowledge proof systems that made Poseidon attractive in the first place have gotten so much better that the exotic hash no longer offers a meaningful edge.
From darling to doubt
Poseidon first entered the conversation as a serious candidate in February 2025, when Vitalik Buterin floated the idea of migrating Ethereum’s base-layer hashing to Poseidon, pointing to its dramatically lower constraint counts inside ZK circuits. In plain terms, Poseidon was designed from the ground up to play nicely with zero-knowledge proofs, making it cheaper and faster to verify computations on-chain.
The hash function itself dates back to 2021, co-designed by cryptographer Dmitry Khovratovich. Its core selling point was reducing the computational overhead compared to Pedersen hashes, the incumbent in many ZK systems.
The Ethereum Foundation took the idea seriously enough to launch a dedicated Poseidon Cryptanalysis program, offering bounties and prizes totaling up to $1 million. The program, which includes an advisory board and multiple phases, is set to run through December 2026.
Security concerns pile up
By August 2026, the Ethereum Research community had grown increasingly vocal about potential weaknesses in Poseidon. Discussions centered on concerns around preimage attacks, which involve finding an input that produces a specific hash output, and questions about whether certain round configurations were robust enough for a system securing hundreds of billions of dollars in value.
Traditional hashes catch up
When Buterin first championed Poseidon in February 2025, the performance gap between algebraic hashes and traditional ones inside ZK circuits was substantial. But ZK proving systems have improved rapidly. Optimizations in proof generation, hardware acceleration, and circuit design have collectively narrowed the performance difference, making traditional hashes competitive in modern ZK setups while carrying none of the security question marks that come with a five-year-old algebraic hash.
What this means for Ethereum’s roadmap
Sticking with SHA or BLAKE3 carries a practical benefit beyond security: compatibility. These hashes are already widely supported across existing tooling, hardware, and software stacks.
Ethereum’s long-term roadmap includes preparations for post-quantum security. Both SHA-256 and BLAKE3 are considered more straightforward to evaluate in post-quantum security models, partly because their mathematical foundations are better understood.
The $1 million cryptanalysis program will continue running through December 2026, so the door isn’t fully closed on Poseidon. But as of August 2026, momentum has clearly shifted toward SHA and BLAKE3 within the Ethereum Research community.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
8






English (US) ·