Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-3298: Remove storage-clear refund and refund cap

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 10
Human Available in open PRscore 6 · Checklist revision 2· ethspecs/pm #115

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-3298, as supplied, is a delta on EIP-8037 and EIP-8038. It removes the SSTORE storage-clearing refund (STORAGE_CLEAR_REFUND = 11,616) and the two EIP-8038 refund rules that grant and reverse it. It also removes the EIP-3529 20% refund cap from transaction settlement. The only refund rule left is EIP-8038's net-metered STORAGE_WRITE reversal, applied when a slot returns to its original value. The refund counter keeps its journaling, the EIP-7623/7976 calldata floor still applies after refunds, and block-level execution-gas accounting stays pre-refund under EIP-7778. When EIP-8141 is active, frame-transaction settlement also applies the full refund counter, with no MAX_REFUND_QUOTIENT.

10LowLow
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
No
Plausible range
10–10 (Low)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Cross-EIP interactions4
  2. Patterns affecting pre-existing tests2
  3. Security risks2
  4. EVM Gas rule changes1

Under-specified at assessment cutoff: No

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

The assessor found no material behavior left unresolved by the EIP text at the cutoff.

Notable ambiguities noted by the assessor (3)
  • The EIP-8141 settlement change applies only "When EIP-8141 is active", and EIP-8141 is not in `requires`. Its testing scope depends on whether frame transactions ship in the same fork.
  • EIP-8037 gives both a non-EIP-7778 and an EIP-7778 block-accounting formula. The target explicitly selects the pre-refund (EIP-7778) variant.
  • The PAT score depends on how often baseline vectors hit the 20% cap or clear slots with a non-zero original value. These are likely common (e.g., short transactions with net-metered round trips), which could push PAT toward level 3.

Criterion breakdown

EIP-3298 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Cross-EIP interactionsExceptional4The change couples the EIP-8038 SSTORE refund table, EIP-8037 settlement and state-gas refills, EIP-7778 pre-refund block accounting, the EIP-7623/7976 calldata floor, and EIP-8141 frame settlement. That requires coordinated scenarios across these EIPs (level 3).
  • eip.md · Specification A delta against EIP-8037 and EIP-8038. It assumes EIP-2780 and EIP-7778, and also modifies EIP-8141 settlement.
  • eip.md · Test Cases Requires tests for the EIP-7623 floor binding after an uncapped refund and for EIP-7778 block accounting with refunds.
  • supporting/eip-8037.md · Integration with EIP-7778 Block execution gas is counted before refunds. State-gas refills are separate from refunds.
  • supporting/eip-8141.md · Transaction settlement The baseline applied_refund uses MAX_REFUND_QUOTIENT. The target removes it.
Confidence: Medium
Uncertainty: EIP-8141 is conditional ("When EIP-8141 is active"). Its coordinated cases apply only in a scenario where EIP-8141 is in the same fork.
Interacting EIPs: EIP-8038, EIP-8037, EIP-7778, EIP-7623, EIP-7976, EIP-8141, EIP-3529, EIP-2200, EIP-2780
Patterns affecting pre-existing tests2Expected values change in ordinary SSTORE net-metering cases (any clear of a slot with a non-zero original value). They also change in localized cap-binding cases in settlement, calldata-floor, EIP-7778 and frame-transaction settlement tests. That matches level 2: several families are affected, but the inputs and construction of those tests do not need a common rewrite.
  • supporting/eip-8038.md · SSTORE pricing / case table Several baseline case rows include STORAGE_CLEAR_REFUND grants or reversals (x→x→0, x→y→0, x→0→x, x→0→y). Their expected refunds change.
  • eip.md · Specification / Removal of the refund cap Any baseline case where the 20% cap bound the refund now produces a different gas_used and fee result.
  • eip.md · Test Cases The EIP's own test table re-derives expected refunds for the canonical SSTORE sequences.
Confidence: Medium
Uncertainty: Clearing storage and short transactions with net-metered round trips are common. If cap-binding refunds turn out to be ubiquitous in baseline vectors, this could reach level 3.
Security risks2Removing the cap takes away a defensive bound on what the sender pays. Safety now depends on the refund counter never exceeding STORAGE_WRITE charges paid in the same transaction. That property depends on journaling across call-frame reverts, frame-transaction frames and atomic batches, and on its interaction with state-gas refills and the floor. This is a bounded interaction that needs targeted adversarial cases (level 2).
  • eip.md · Security Considerations "Removing the cap is safe only because the remaining refund is self-bounded and the counter is journaled across reverts; both properties are load-bearing."
  • eip.md · Specification / Removal of the refund cap For EIP-8141, the counter is transaction-scoped and discards reverted frames' changes, so the bound is claimed to hold.
  • supporting/eip-8141.md · Transaction settlement The refund counter accumulates across frames and is discarded for reverted frames and unrolled atomic batches.
Confidence: Medium
Uncertainty: This could be viewed as a local check (level 1) if the journaling semantics are considered already covered by the prerequisites.
EVM Gas rule changes1Existing refund and settlement rules are removed or simplified. No new accounting mechanism is introduced, which matches level 1. Expected gas results of baseline operations change, but level 3 requires a new mechanism, and there is none.
  • eip.md · Specification / SSTORE refund rules STORAGE_CLEAR_REFUND and the two EIP-8038 refund rules that use it are removed. The STORAGE_WRITE reversal rule is unchanged.
  • eip.md · Specification / Removal of the refund cap In settlement, tx_gas_refund = min(tx_gas_used_before_refund // 5, refund_counter) becomes refund_counter. The calldata floor still applies after refunds.
  • supporting/eip-8037.md · Transaction gas used The baseline settlement applies the 20% refund cap.
Confidence: High
Edge/boundary conditions1One boundary-sensitive mechanism changes: refund application at settlement, now uncapped, with the floor still applied afterwards. The cap boundary and the floor boundary both test this same settlement rule.
  • eip.md · Test Cases Tests should cover a refund counter above 20% of pre-refund gas (uncapped) and a refund that pushes tx_gas_used_after_refund below the floor (the floor binds).
Confidence: Medium
Uncertainty: Counting the floor interaction as a separate boundary mechanism would give level 2.
Show 23 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No opcodes are added.
  • eip.md · Specification No new instructions.
Modified opcodes0Only SSTORE's refund contribution changes, which is a gas-only change. Its semantics are unchanged.
  • eip.md · Backwards Compatibility "Refunds are applied only in the end-of-transaction settlement, so removing one cannot affect execution"
Added precompiles0No precompiles are added.
  • eip.md · Specification No precompiles.
Modified precompiles0No existing precompile changes.
  • eip.md · Specification No precompile changes.
Added system contracts0No system contract is added.
  • eip.md · Specification No contract deployment is specified.
Modified system contracts0No existing system contract or its surrounding protocol behavior changes.
  • eip.md · Specification No system contract rules change. Settlement refunds do not apply to system calls.
State-access ordering within opcode execution0No instruction's state-access or gas-charge ordering changes, and no access-list recording changes.
  • eip.md · Specification / SSTORE refund rules The SSTORE charging rules are untouched. Only refund-counter adjustments change.
Blob gas accounting changes0Blob-gas accounting does not change.
  • eip.md · Specification The changes are limited to SSTORE refunds and refund-cap settlement. Blob gas is not mentioned.
State gas accounting changes0State-gas charges, refills and reservoir rules do not change.
  • eip.md · Specification / SSTORE refund rules "the state-gas charges and refills of EIP-8037 are untouched; state-gas refills are not refunds and do not enter the counter"
New EVM gas refund0No new refund mechanism is introduced. Removing an existing refund belongs under GAS.
  • eip.md · Abstract The EIP removes a refund and the cap. The remaining STORAGE_WRITE reversal is inherited unchanged from EIP-8038.
New transaction types0No new transaction type.
  • eip.md · Specification No new transaction envelope. The EIP-8141 settlement change modifies an existing type.
New or modified transaction validity mechanisms0No consensus validity or intrinsic-gas rule changes.
  • eip.md · Specification / Removal of the refund cap Only post-execution settlement changes. Intrinsic gas and inclusion checks are unchanged, and block accounting is unchanged.
New block / header fields0No header or block field is added.
  • eip.md · Specification No header fields.
Encoding changes (RLP/SSZ)0No codec or schema change.
  • eip.md · Specification No serialized schema changes. Receipt fields keep their existing meaning.
Block syncing changes0No block decoding or structural validation rule changes.
  • eip.md · Specification / Removal of the refund cap "Block-level accounting is unchanged". Under EIP-7778 and EIP-8037, the execution dimension counts the pre-refund value.
New fork activation mechanism0Activation only selects different rules. There is no state transition at the fork.
  • eip.md · Backwards Compatibility A gas repricing activated at a scheduled upgrade, with no state migration.
Engine API changes0No Engine API field or endpoint changes.
  • eip.md · Specification No Engine API change is described.
Transition-tool interface changes0No input, output or invocation change is needed in the transition tool.
  • eip.md · Specification / Removal of the refund cap Receipt cumulative_gas_used and the block accounting fields keep their existing semantics. Only their computed values change.
New invariant on pre-existing tests0No new assertion is needed. Changed gas values count as rework under PAT.
  • eip.md · Specification / Removal of the refund cap No new output, field or log is introduced. Only existing gas values change.
New test-framework primitives0Fork gas-calculation logic needs to drop a parameter and the cap, but no new abstraction is required.
  • eip.md · Specification / Removal of the refund cap The settlement formula is simplified. The fork's gas-cost and refund calculation drops the cap and one refund constant.
Uncertainty: A framework-side refund-calculator toggle per fork could be read as a local extension (level 1).
Performance risks0No workload capacity or resource bound changes, so no new performance validation is needed.
  • eip.md · Security Considerations "this EIP does not change worst-case block resource consumption" because EIP-7778 excludes refunds from block accounting.
Cryptography0No cryptographic mechanism changes.
  • eip.md · Specification There is no cryptographic content.
Unspecified behavior requiring cross-client consensus0The supplied rules settle every observable outcome. The struck table entries and the remaining rule are stated precisely.
  • eip.md · Specification / Removal of the refund cap Explicit settlement pseudocode is given, along with the block-accounting rule and the EIP-8141 settlement change.
  • eip.md · Test Cases Explicit expected refund-counter values for the canonical SSTORE sequences.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-3298.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob a618240aad · sha256 623a5db8d64d
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-3298.yaml · sha256 575e30ce0e67
Supporting documents supplied with the EIP
supporting/eip-1153.md, supporting/eip-2200.md, supporting/eip-2780.md, supporting/eip-3529.md, supporting/eip-7623.md, supporting/eip-7702.md, supporting/eip-7778.md, supporting/eip-7976.md, supporting/eip-8037.md, supporting/eip-8038.md, supporting/eip-8141.md

Evaluated on: Not recorded

6LowLow
Evaluator
HumanChecklist v2
Confidence
Not recorded
Under-specified at assessment cutoff
Not recorded in the checklist
Checklist published
2026-08-18
Score bands · Checklist revision 2
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the Human total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Modified system contracts1
  2. EVM Gas rule changes1
  3. Patterns affecting pre-existing tests1
  4. Edge/boundary conditions1

Criterion breakdown

EIP-3298 Hegotá: Human criterion scores and rationale
CriterionScoreWhy this scoreNotes
Modified system contracts1Note: not a direct modification but executing system contracts that touch the state and before incurred in refunds have to be sanity checked. Potentially using already-existing tests.—
EVM Gas rule changes1Existing gas accounting mechanism is updated by removal, which results in great simplification by removal of code.—
Patterns affecting pre-existing tests1Minor subset. Measured rather than estimated: a reference implementation of this EIP against the Amsterdam set fails **63 tests** out of ~11.9k collected under `tests/amsterdam/` — under 1%, and concentrated in refund and SSTORE gas assertions. The affected tests need their expected values updated, not restructuring. `tests/amsterdam/eip7778_block_gas_accounting_without_refunds/` is the one suite retired outright, since its premise (refunds exist but do not count toward the block limit) cannot hold once refunds are gone.—
Edge/boundary conditions1The boundary conditions that have to be tested due to refunds are already present in the test set. This change will only have to modify the outcome expectation of such tests.—
Cross-EIP interactions1**EIP-7778** minimal, it's implied that the mechanism is removed.—
Unspecified behavior requiring cross-client consensus1Amsterdam has two independent refund mechanisms and this EIP (2021) predates the second: the EIP-2200 `refund_counter` in execution gas, which this EIP removes, and `credit_state_gas_refund()` in state gas, which credits `StateGasCosts.STORAGE_SET` back when a slot is cleared (`vm/instructions/storage.py`). The state-gas refund should stay: state paid for and released within the same transaction never persisted, so crediting it is not a refund for good hygiene but correct accounting for state that was never created. That leaves only a statement to add to the EIP, so scored 1 — the resolution is clear and needs no client negotiation.—
Show 22 zero-score criteria
Zero-score criteria (Checklist revision 2)
CriterionScoreWhy this scoreNotes
Added opcodes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Modified opcodes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Added precompiles0No rationale recorded.
Blank cell read as zero because the published total proves it.
Modified precompiles0No rationale recorded.
Blank cell read as zero because the published total proves it.
Added system contracts0No rationale recorded.
Blank cell read as zero because the published total proves it.
State-access ordering within opcode execution0No rationale recorded.
Blank cell read as zero because the published total proves it.
Blob gas accounting changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
State gas accounting changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
New EVM gas refund0No new refund mechanism is introduced; this EIP removes the last one. Hence, this row is marked as zero due to reduction of parametrization of refund tests.—
New transaction types0No rationale recorded.
Blank cell read as zero because the published total proves it.
New or modified transaction validity mechanisms0No rationale recorded.
Blank cell read as zero because the published total proves it.
New block / header fields0No rationale recorded.
Blank cell read as zero because the published total proves it.
Encoding changes (RLP/SSZ)0No rationale recorded.
Blank cell read as zero because the published total proves it.
Block syncing changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
New fork activation mechanism0No rationale recorded.
Blank cell read as zero because the published total proves it.
Engine API changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Transition-tool interface changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
New invariant on pre-existing tests0No rationale recorded.
Blank cell read as zero because the published total proves it.
New test-framework primitives0No rationale recorded.
Blank cell read as zero because the published total proves it.
Security risks0No rationale recorded.
Blank cell read as zero because the published total proves it.
Performance risks0No rationale recorded.
Blank cell read as zero because the published total proves it.
Cryptography0No rationale recorded.
Blank cell read as zero because the published total proves it.
Assessment provenance
Rubric
Checklist revision 2 · ethspecs/pm@3d8c0128c5
Evaluator
STEEL team · ethspecs/pm complexity_assessments
Source record
Open pull request #115: Add EIP-3298 complexity assessment · checklist at 6672c60213 · updated 2026-08-18
blob 760dabfde1 · sha256 75b5454cd77c
Research record
research/tasks/09-hegota-human-assessment-snapshot/outputs/assessments/eip-3298.yaml · sha256 122ee8c31580

The LLM applied checklist revision 3 and the human reviewers revision 2 to EIP-3298 in Hegotá. Revision 3 phrases the same criteria more precisely; differences cover the 28 criteria both revisions share, and each total keeps its own revision. Δ is LLM minus Human.

Using the latest scored LLM evaluation for this checklist: 2026-10-08 · spec 2026-10-07 · 6dac5e7491. The Human and LLM assessments may use different spec revisions.

LLM10Low
Human6Low
Δ total+4Same tier
Criteria23/28agree exactly · 3 differ by 1 · 2 differ by 2+

Complexity profiles side by side

LLM
Human

Largest disagreements: Cross-EIP interactions (+3), Security risks (+2), Patterns affecting pre-existing tests (+1), Modified system contracts (−1), Unspecified behavior requiring cross-client consensus (−1)

Per-criterion scores, Human versus LLM, ordered by the size of the difference
CriterionLLMHumanΔAgreementRationale from each source
Cross-EIP interactions41+3Differ by 2+
Show rationale

LLM The change couples the EIP-8038 SSTORE refund table, EIP-8037 settlement and state-gas refills, EIP-7778 pre-refund block accounting, the EIP-7623/7976 calldata floor, and EIP-8141 frame settlement. That requires coordinated scenarios across these EIPs (level 3).

Human **EIP-7778** minimal, it's implied that the mechanism is removed.

Security risks20+2Differ by 2+
Show rationale

LLM Removing the cap takes away a defensive bound on what the sender pays. Safety now depends on the refund counter never exceeding STORAGE_WRITE charges paid in the same transaction. That property depends on journaling across call-frame reverts, frame-transaction frames and atomic batches, and on its interaction with state-gas refills and the floor. This is a bounded interaction that needs targeted adversarial cases (level 2).

Human No rationale recorded.

Modified system contracts01−1Differ by 1
Show rationale

LLM No existing system contract or its surrounding protocol behavior changes.

Human Note: not a direct modification but executing system contracts that touch the state and before incurred in refunds have to be sanity checked. Potentially using already-existing tests.

Patterns affecting pre-existing tests21+1Differ by 1
Show rationale

LLM Expected values change in ordinary SSTORE net-metering cases (any clear of a slot with a non-zero original value). They also change in localized cap-binding cases in settlement, calldata-floor, EIP-7778 and frame-transaction settlement tests. That matches level 2: several families are affected, but the inputs and construction of those tests do not need a common rewrite.

Human Minor subset. Measured rather than estimated: a reference implementation of this EIP against the Amsterdam set fails **63 tests** out of ~11.9k collected under `tests/amsterdam/` — under 1%, and concentrated in refund and SSTORE gas assertions. The affected tests need their expected values updated, not restructuring. `tests/amsterdam/eip7778_block_gas_accounting_without_refunds/` is the one suite retired outright, since its premise (refunds exist but do not count toward the block limit) cannot hold once refunds are gone.

Unspecified behavior requiring cross-client consensus01−1Differ by 1
Show rationale

LLM The supplied rules settle every observable outcome. The struck table entries and the remaining rule are stated precisely.

Human Amsterdam has two independent refund mechanisms and this EIP (2021) predates the second: the EIP-2200 `refund_counter` in execution gas, which this EIP removes, and `credit_state_gas_refund()` in state gas, which credits `StateGasCosts.STORAGE_SET` back when a slot is cleared (`vm/instructions/storage.py`). The state-gas refund should stay: state paid for and released within the same transaction never persisted, so crediting it is not a refund for good hygiene but correct accounting for state that was never created. That leaves only a statement to add to the EIP, so scored 1 — the resolution is clear and needs no client negotiation.

Added opcodes000Agree
Show rationale

LLM No opcodes are added.

Human No rationale recorded.

Modified opcodes000Agree
Show rationale

LLM Only SSTORE's refund contribution changes, which is a gas-only change. Its semantics are unchanged.

Human No rationale recorded.

Added precompiles000Agree
Show rationale

LLM No precompiles are added.

Human No rationale recorded.

Modified precompiles000Agree
Show rationale

LLM No existing precompile changes.

Human No rationale recorded.

Added system contracts000Agree
Show rationale

LLM No system contract is added.

Human No rationale recorded.

EVM Gas rule changes110Agree
Show rationale

LLM Existing refund and settlement rules are removed or simplified. No new accounting mechanism is introduced, which matches level 1. Expected gas results of baseline operations change, but level 3 requires a new mechanism, and there is none.

Human Existing gas accounting mechanism is updated by removal, which results in great simplification by removal of code.

State-access ordering within opcode execution000Agree
Show rationale

LLM No instruction's state-access or gas-charge ordering changes, and no access-list recording changes.

Human No rationale recorded.

Blob gas accounting changes000Agree
Show rationale

LLM Blob-gas accounting does not change.

Human No rationale recorded.

State gas accounting changes000Agree
Show rationale

LLM State-gas charges, refills and reservoir rules do not change.

Human No rationale recorded.

New EVM gas refund000Agree
Show rationale

LLM No new refund mechanism is introduced. Removing an existing refund belongs under GAS.

Human No new refund mechanism is introduced; this EIP removes the last one. Hence, this row is marked as zero due to reduction of parametrization of refund tests.

New transaction types000Agree
Show rationale

LLM No new transaction type.

Human No rationale recorded.

New or modified transaction validity mechanisms000Agree
Show rationale

LLM No consensus validity or intrinsic-gas rule changes.

Human No rationale recorded.

New block / header fields000Agree
Show rationale

LLM No header or block field is added.

Human No rationale recorded.

Encoding changes (RLP/SSZ)000Agree
Show rationale

LLM No codec or schema change.

Human No rationale recorded.

Block syncing changes000Agree
Show rationale

LLM No block decoding or structural validation rule changes.

Human No rationale recorded.

New fork activation mechanism000Agree
Show rationale

LLM Activation only selects different rules. There is no state transition at the fork.

Human No rationale recorded.

Engine API changes000Agree
Show rationale

LLM No Engine API field or endpoint changes.

Human No rationale recorded.

Transition-tool interface changes000Agree
Show rationale

LLM No input, output or invocation change is needed in the transition tool.

Human No rationale recorded.

New invariant on pre-existing tests000Agree
Show rationale

LLM No new assertion is needed. Changed gas values count as rework under PAT.

Human No rationale recorded.

New test-framework primitives000Agree
Show rationale

LLM Fork gas-calculation logic needs to drop a parameter and the cap, but no new abstraction is required.

Human No rationale recorded.

Performance risks000Agree
Show rationale

LLM No workload capacity or resource bound changes, so no new performance validation is needed.

Human No rationale recorded.

Edge/boundary conditions110Agree
Show rationale

LLM One boundary-sensitive mechanism changes: refund application at settlement, now uncapped, with the floor still applied afterwards. The cap boundary and the floor boundary both test this same settlement rule.

Human The boundary conditions that have to be tested due to refunds are already present in the test set. This change will only have to modify the outcome expectation of such tests.

Cryptography000Agree
Show rationale

LLM No cryptographic mechanism changes.

Human No rationale recorded.

Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.