Fun seeing this work in prod - like many things, the constraints of not having G2 precompiles necessitated a bit of an unnatural approach, namely the “key switching” from G2 to G1, which ended up being pretty efficient Props to @jeffburdges, @OanaCiobotaru, Syed and Alistair for their concurrent work ( that while aimed at a different verifier (native vs EVM in my case), also wanted to lighten the load on verifiers with almost the same methods, together with more formal treatment and proofs After Pectra, EIP 2537 and the relative cost of G1 and G2 additions, it’s worth reevaluating at what number of aggregated keys this method becomes cheaper again
bbuddha
bbuddha19.6.2025
nice research post featuring a bunch of our work on bringing BLS signatures onchain (based on previous work from @kobigurk) working in prod rn
3,06K