Evaluated on: · Spec revision: 2023-06-22 · ef0a1320a0
Scope at the cutoff. This revision of EIP-2537 adds nine native precompiles at addresses 0x0c–0x14 for BLS12-381 operations: G1 and G2 addition, multiplication and multiexponentiation, pairing, and mapping Fp to G1 and Fp2 to G2. It defines strict byte encodings: 64-byte padded field elements that must be less than the modulus, (0,0) as the point at infinity, and 32-byte scalars that are not reduced. Every operation has its own error cases, and an error burns all supplied gas. Six precompiles have constant gas. The two multiexponentiation precompiles use a discount table for k up to 128, and pairing has a per-pair formula; all three compute k with floor division on the input length. The pairing call must perform subgroup checks. Activation is a plain block-number condition.
- Evaluator
- LLMChecklist v3
- Confidence
- Medium
- Under-specified at assessment cutoff
- Yes — 4 criteria affected
- Plausible range
- 15–18 (Medium)
- Assessment cutoff
- 2024-01-18 · EIP revision
ef0a1320a0(2023-06-22)
Score bands · Checklist revision 3
- Low <12
- Medium 12–22
- High ≥23
28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.
Complexity profile
Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.
Top complexity drivers
- Added precompiles4
- Edge/boundary conditions3
- Cryptography3
- Unspecified behavior requiring cross-client consensus2
Under-specified at assessment cutoff: Yes
The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.
Why: The pairing gas formula appears twice with different values, 43000*k+65000 and 23000*k+115000. The field-to-curve mapping algorithm and the benchmark vectors are in separate documents that were not supplied. Whether add, mul and multiexponentiation need subgroup checks is only implied by their error-case lists.
Plausible total
15–18
recorded score 17 · plausible tiers Medium
Unresolved questions at the cutoff (4)
- Which pairing gas formula is normative: 43000*k + 65000 or 23000*k + 115000?
- Must G1/G2 mul and multiexponentiation reject points that are on the curve but not in the subgroup?
- What exact SWU and isogeny parameters and cofactor-clearing steps do the mapping precompiles use? The referenced document was not supplied.
- The multiexponentiation gas function returns 0 for inputs shorter than one pair. Is the order of the gas check and the error for empty input observable beyond the burned gas?
Notable ambiguities noted by the assessor (4)
- Contradictory pairing gas formulas between the Gas schedule section and the gas schedule clarifications.
- The mapping precompiles depend on an external field_to_curve.md that was not supplied.
- Subgroup checks are mandatory only for pairing, and the requirement for the other operations is implicit.
- The text says multiexponentiation 'must' use Pippenger's algorithm. That is an implementation detail with no observable consensus effect.
Criterion breakdown
| Criterion | Score | Why this score | Evidence / uncertainty |
|---|---|---|---|
| Added precompilesExceptional | 4 | Several precompiles are added and at least one is complex, which meets level 3. The supplied scope goes well beyond that condition: nine distinct addresses, three of them complex with dynamic gas and their own validation and gas formulas. Exceptional score: Level 3 needs only multiple precompiles with at least one complex. This EIP adds nine distinct addresses. Each has its own encoding, output and error rules. Three take variable-length input with dynamic gas: two use a 128-entry discount table and pairing uses a per-pair formula. That is roughly nine separate per-precompile test families of validity, error, gas and boundary cases, plus three dynamic-gas families. This is substantially more testing work within this criterion than the level-3 condition requires. |
Confidence: Medium Uncertainty: Whether nine precompiles justify the exceptional level is a judgment call. Level 3 is the conservative alternative. |
| Edge/boundary conditionsUnder-specified | 3 | There are several independent boundary-sensitive rules: the field-element range and padding, exact or multiple-of input length, empty input, infinity encoding, scalars at or above the group order, the discount-table cap at k=128, and on-curve versus subgroup membership. The multiexponentiation and pairing gas rules form an elevated matrix. Input length (exact multiple, non-multiple, empty, k=0) interacts with the floor-division gas formula, the gas supplied relative to that cost, and the later encoding error. Together these decide whether the call fails on gas or on encoding, and they cannot be tested independently. |
Confidence: Medium |
| CryptographyUnder-specified | 3 | Several cryptographic mechanisms are added: group arithmetic in two groups, multiexponentiation, pairing with subgroup checks, and SWU map-to-curve. Some behavior differs from standard library APIs. Mapping is only a partial hash-to-curve. Add, mul and multiexponentiation accept on-curve points without subgroup checks. Infinity is encoded as (0,0) with 64-byte padding. These cases need vectors built specifically for this EIP, beyond established resources. That meets level 3. |
Confidence: Medium Uncertainty: The test resources and the mapping specification are in documents that were not supplied. If established vectors cover these exact behaviors, level 2 would apply. |
| Unspecified behavior requiring cross-client consensusUnder-specified | 2 | The two pairing gas formulas give different, observable gas results for the same input. Expected values cannot be fixed until the specification is clarified or clients agree. The contradiction is localized to one precompile, which fits level 2. |
Confidence: High Uncertainty: The missing mapping document is an evidence gap, not an omission in this specification. |
| Patterns affecting pre-existing tests | 1 | The only rework is in baseline cases that treat 0x0c–0x14 as non-precompile or empty accounts. Examples are precompile-range boundary tests and cold/warm access cases that target those addresses. This rework is confined to address-boundary cases within one family. |
Confidence: Medium Uncertainty: How many baseline vectors use these addresses cannot be estimated without a suite. |
| New test-framework primitives | 1 | Tests need BLS12-381 point and field encoding helpers to build precompile inputs and expected outputs. This is a local extension of the existing kind of precompile-input helper, not a new abstraction. |
Confidence: Medium Uncertainty: Whether existing helpers are available is unknown. The score reflects architectural need only. |
| Security risks | 1 | The new security conditions are input validation, on-curve and subgroup checks, and worst-case gas. All of them sit inside the precompiles and can be checked locally, for example by differential fuzzing. No other component's assumptions change. |
Confidence: Medium |
| Performance risksUnder-specified | 1 | Each precompile's worst case needs component benchmarks to confirm pricing. That includes the multiexponentiation discount table up to and beyond k=128, pairing per pair, and the mapping operations. The workload is CPU-bound inside each precompile and does not change baseline end-to-end assumptions. |
Confidence: Medium Uncertainty: The pairing gas formulas contradict each other, so the pricing to benchmark is uncertain. |
| Cross-EIP interactions | 1 | The interactions are local compatibility checks. New precompile addresses must be treated as warm precompiles under the baseline access-list rules. Calls must behave correctly across call types with the existing gas-forwarding rules. Otherwise the target can be tested on its own. |
Confidence: Medium Uncertainty: The interacting EIPs are not named in the document, and no candidate EIPs were supplied. |
Show 19 zero-score criteria
| Criterion | Score | Why this score | Evidence / uncertainty |
|---|---|---|---|
| Added opcodes | 0 | No new instructions. |
|
| Modified opcodes | 0 | New callee behavior reached through unchanged instructions does not count as an opcode change. |
|
| Modified precompiles | 0 | No existing precompile changes. |
|
| Added system contracts | 0 | No system contracts are added. |
|
| Modified system contracts | 0 | No existing system contract changes. |
|
| EVM Gas rule changes | 0 | No execution-gas charging, metering or settlement rule changes. The new precompile fees are ordinary per-function costs and are assessed under Added precompiles. Gas burning on error copies existing precompile behavior. |
Uncertainty: Under the baseline's existing warm-precompile rule, adding precompile addresses changes cold/warm gas for calls to 0x0c–0x14. That is an existing rule applied to new addresses and is scored under PAT, not here. |
| State-access ordering within opcode execution | 0 | No instruction's state-access or gas-charge ordering changes, and the precompiles need no ordering rule. |
|
| Blob gas accounting changes | 0 | Blob-gas accounting is unchanged. |
|
| State gas accounting changes | 0 | No state-gas accounting changes. |
|
| New EVM gas refund | 0 | No refund mechanism is introduced. |
|
| New transaction types | 0 | No new envelope. |
|
| New or modified transaction validity mechanisms | 0 | Transaction validity is unchanged. |
|
| New block / header fields | 0 | No header changes. |
|
| Encoding changes (RLP/SSZ) | 0 | No listed protocol object or interface changes its schema. Precompile input encoding is calldata. |
|
| Block syncing changes | 0 | No block RLP or structural validation changes. |
|
| New fork activation mechanism | 0 | No activation-specific state transition is required. |
|
| Engine API changes | 0 | No Engine API changes. |
|
| Transition-tool interface changes | 0 | No transition-tool interface change is required. |
|
| New invariant on pre-existing tests | 0 | Baseline tests need no new assertion. |
|
Assessment provenance
- Assessed EIP revision
ethereum/EIPs@ef0a1320a0EIPS/eip-2537.md committed 2023-06-22 · information cutoff 2024-01-18- Rubric
- Checklist revision 3 ·
ethspecs/pm@fe2f793b03 - Evaluator
- Opus 5.5 (
claude-opus-5-5) at high effort, one tool-less call per EIP · isolationbubblewrap_claude_p_no_tools_v1 - Source record
- Frozen research record
research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/prague/eip-2537.yaml· sha25658ffc39a4dee