Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-5920: PAY opcode

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 18
Human Available in open PRscore 14 · Checklist revision 2· ethspecs/pm #116
Other checklist versions (2)

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-5920 adds one EVM instruction, PAY (0xfc). It pops `addr` then `val` and sends `val` wei from the current account to `addr` without running any code at `addr`. If the frame is static (EIP-214) or the upper 12 bytes of `addr` are non-zero, it halts exceptionally. It charges warm/cold access gas (EIP-2929), plus GAS_NEW_ACCOUNT when the recipient does not exist and `val` is non-zero, plus GAS_CALL_VALUE when `val` is non-zero. It then adds `addr` to `accessed_addresses` and pushes 1 on success or 0 if the balance is too low. It relies on EIP-7523 (no empty accounts) and adds no transaction, header, encoding or system-contract changes.

18MediumMedium
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 4 criteria affected
Plausible range
14–20 (Medium)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Edge/boundary conditions3
  2. Added opcodes2
  3. EVM Gas rule changes2
  4. State-access ordering within opcode execution2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The core semantics are clear. Some details depend on baseline mechanisms that are not supplied or are only implied: whether a zero-value PAY to a non-existent address creates or touches an account, how failure paths are recorded in block-level access lists, and how GAS_NEW_ACCOUNT maps onto any state-gas accounting in Amsterdam.

Unresolved questions at the cutoff (4)
  • Does a zero-value PAY to a non-existent address create, touch or leave the account absent?
  • Is addr recorded in the block-level access list when PAY fails for insufficient balance or runs out of gas after the existence check?
  • How does GAS_NEW_ACCOUNT interact with any state-gas or reservoir mechanism in the Amsterdam baseline?
  • Self-PAY (addr == current address): is it a no-op that still charges GAS_CALL_VALUE?
Notable ambiguities noted by the assessor (3)
  • Gas is charged and addr is warmed before the conditional transfer, so a PAY that fails for insufficient balance still pays the full cost, including GAS_NEW_ACCOUNT. This follows from the order of the bullets rather than an explicit statement.
  • The static-frame halt is unconditional, even for val=0, which differs from CALL. The halt also appears to come before the stack pops, but the difference is not observable.
  • The constants are linked to frontier EELS values instead of being given numerically.

Criterion breakdown

EIP-5920 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Edge/boundary conditions3There are several independent boundary-sensitive mechanisms: address-width validation (bit 160 vs. lower bits), the balance >= val comparison (equal, one wei short), and exact-gas out-of-gas points. The gas rule has an elevated matrix: recipient existence × val zero/non-zero decides GAS_NEW_ACCOUNT, and warm/cold adds to it. These cannot be tested independently, so level 3 applies.
  • eip.md · Behavior Has several boundaries: halt if any of the high 12 address bytes are non-zero; transfer only when balance >= val; static-frame halt.
  • eip.md · Gas Cost The new-account charge depends on both recipient existence and whether val is zero, combined with warm/cold access and the value charge.
Confidence: Medium
Uncertainty: The matrix is fairly small (three binary dimensions). A stricter reading of 'elevated' would give 2.
Added opcodes2Exactly one instruction is added. Its gas is dynamic, so it is complex, which gives level 2.
  • eip.md · Behavior PAY (0xfc) pops 2 values, pushes 1 and has no immediate data.
  • eip.md · Gas Cost Gas depends on access state, recipient existence and value.
Confidence: High
EVM Gas rule changesUnder-specified2PAY adds a new dynamic charging rule at a new instruction. It is built from existing components and does not change any existing opcode's gas or baseline gas results. That fits level 2: a new mechanism with no change to existing rules.
  • eip.md · Gas Cost PAY has its own gas function that adds three conditional parts: warm/cold access, GAS_NEW_ACCOUNT when the recipient does not exist and val is non-zero, and GAS_CALL_VALUE when val is non-zero. No stipend or 63/64 forwarding applies.
  • supporting/eip-2929.md · Storage read changes Defines the WARM_STORAGE_READ_COST and COLD_ACCOUNT_ACCESS_COST that PAY reuses. Charges for existing opcodes are not changed by the target.
Confidence: Medium
Uncertainty: One could argue that reusing existing gas components is not a new accounting mechanism, which would give 0. Level 2 is the best-supported reading because the opcode's charging rule is new and conditional.
State-access ordering within opcode executionUnder-specified2PAY is a new state-accessing operation that needs its own ordering rule. The existence read and the warm/cold check come before the charge, and the warming and transfer come after it. No existing opcode's ordering changes. Relevant combinations are cold/warm, existing/non-existing recipient, static/non-static, enough/too little balance, revert/success, and out-of-gas at each gas part.
  • eip.md · Behavior Fixes the order: static check, pop, address-width halt, charge gas, mark addr warm, then a conditional transfer. The gas charge depends on reading whether the recipient exists before the transfer.
  • supporting/eip-2929.md · Specification Changes to access sets are reverted when a scope reverts. This applies to PAY's warming.
Confidence: Medium
Uncertainty: The Amsterdam baseline's block-level access list rules are not supplied. Whether `addr` is recorded on out-of-gas or insufficient-balance paths cannot be checked.
State gas accounting changesUnder-specified2PAY adds a new place where an existing account-creation charge applies, without a new state-gas mechanism. That matches level 2: charging added at a new site using an existing mechanism.
  • eip.md · Gas Cost Charges GAS_NEW_ACCOUNT when the recipient does not exist and val is non-zero. This is a charge for creating a new account in state, at a new site.
  • eip.md · Constants GAS_NEW_ACCOUNT is taken from the frontier EELS constant. No state-gas reservoir or state-byte rule is specified.
Confidence: Low
Uncertainty: Any state-gas mechanism in the Amsterdam baseline is not supplied. If GAS_NEW_ACCOUNT is treated purely as execution gas, this could be 0. If the baseline has a separate state-gas dimension, PAY must also be wired into it, which the EIP does not specify.
Cross-EIP interactions2Coordinated cases are needed with EIP-214 (PAY in static frames, including val=0), EIP-2929 (warming shared with CALL/BALANCE, and warming undone on revert) and EIP-7702 (PAY to a delegated EOA runs no code and charges no delegation-resolution cost). Each of these is a pairwise interaction, not a coupled multi-EIP restructuring, so level 2 applies.
  • eip.md · Behavior Uses EIP-214's static flag and EIP-2929's accessed_addresses.
  • eip.md · Motivation Sending to an EIP-7702 delegated EOA must not run its code.
  • supporting/eip-7702.md · Delegation indicator Only CALL-family opcodes and transactions follow delegation. Resolving delegated code adds a cold-access charge.
  • eip.md · Security Considerations Refers to EIP-6780 SELFDESTRUCT as another way to move value.
Confidence: Medium
Uncertainty: Whether the EIP-6780 cases (PAY to or from a contract created and self-destructed in the same transaction) need coordinated cases or only compatibility checks is a judgement call.
Interacting EIPs: EIP-214, EIP-2929, EIP-7702, EIP-6780, EIP-7523, EIP-1153
Patterns affecting pre-existing tests1Baseline tests that treat 0xfc as an undefined or invalid opcode need new expected results. This rework is limited to particular cases in one family (undefined-opcode coverage).
  • eip.md · Behavior Assigns opcode 0xfc, which was previously undefined.
Confidence: Medium
Uncertainty: No test suite was supplied, so the exact number of affected undefined-opcode cases cannot be measured.
New test-framework primitives1The framework's opcode definitions need a local extension for PAY: its stack arity and a gas calculator for its dynamic cost. No new abstraction is needed.
  • eip.md · Behavior A new opcode 0xfc with two stack inputs and one output.
Confidence: Medium
Uncertainty: This could be 0 if adding an opcode entry does not count as extending a primitive.
Security risks1The new security conditions can be checked locally: static enforcement, address-width halting, insufficient-balance handling, and no code running at the recipient (including delegated EOAs). No other component's assumptions change.
  • eip.md · Security Considerations Moving ETH without calling the recipient was already possible (SELFDESTRUCT, coinbase). PAY makes it cheaper but does not break an invariant.
  • eip.md · Behavior Static-frame halt and address-width halt are the safety checks.
Confidence: Medium
Uncertainty: Some applications that assume value arrives only through code may be affected, but this is outside the protocol and the EIP says it is not a new invariant.
Performance risks1A component benchmark of worst-case PAY workloads (many cold or new-account transfers per block) is enough. Baseline end-to-end performance assumptions do not change.
  • eip.md · Gas Cost Creating accounts and touching cold accounts are priced from existing constants, with no code execution.
  • eip.md · Motivation PAY is cheaper than CALL because the recipient's code is not run or paid for.
Confidence: Medium
Uncertainty: Account-creation throughput per gas is close to CALL with value, but PAY skips loading code. No benchmark evidence was supplied.
Unspecified behavior requiring cross-client consensusUnder-specified1Some local details are omitted: account creation on a zero-value PAY, self-PAY, and access-list recording on failure paths. The surrounding rules (no empty accounts, CALL-like semantics) support one intended outcome for each, so this is level 1.
  • eip.md · Gas Cost 'PAY cannot be implemented on networks with empty accounts.' The EIP does not say whether a zero-value PAY to a non-existent address creates or touches an account.
  • eip.md · Behavior The order of charge, warm and conditional transfer is given, so gas and warming apply even when the balance is too low. Interaction with block-level access lists and with any state-gas dimension in the baseline is not stated.
Confidence: Medium
Uncertainty: The Amsterdam block-level access list and state-gas specifications are not supplied. If they create competing outcomes for recording or charging on out-of-gas or insufficient-balance paths, this would be 2.
Show 17 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Modified opcodes0No existing instruction's semantics or availability change.
  • eip.md · Behavior Only a new opcode is defined. CALL and other existing opcodes are unchanged.
Added precompiles0None added.
  • eip.md · Specification No precompile is introduced.
Modified precompiles0None modified.
  • eip.md · Specification No precompile changes.
Added system contracts0None added.
  • eip.md · Specification No system contract is introduced.
Modified system contracts0No system contract's rules or surrounding protocol behavior change.
  • eip.md · Behavior PAY sends value without running the recipient's code. No system contract's rules change.
Uncertainty: Value can now reach a system contract without its code running. This is an application-level concern and does not change the contracts' rules.
Blob gas accounting changes0No blob-gas rule is affected.
  • eip.md · Specification Covers only an EVM opcode. Blobs are not mentioned.
New EVM gas refund0No refund mechanism is introduced.
  • eip.md · Gas Cost Specifies charges only. No refund is mentioned.
New transaction types0No new transaction type.
  • eip.md · Specification No transaction envelope is defined.
New or modified transaction validity mechanisms0No consensus rule on transaction validity changes.
  • eip.md · Specification Changes only execution. No intrinsic-gas or validity rules change.
New block / header fields0None.
  • eip.md · Specification No header field is added.
Encoding changes (RLP/SSZ)0No schema changes.
  • eip.md · Specification No serialized object or codec changes.
Block syncing changes0No block decoding or structural validation changes.
  • eip.md · Backwards Compatibility Only a hard fork is needed. Block structure is unchanged.
New fork activation mechanism0Only a rule switch at activation. No one-time state transition.
  • eip.md · Backwards Compatibility 'This change requires a hard fork.' No state migration is described.
Engine API changes0No Engine API change.
  • eip.md · Specification No Engine API fields or methods are mentioned.
Transition-tool interface changes0The transition tool's interface does not need to change.
  • eip.md · Specification Changes only EVM execution. No new transaction, block or environment input or output.
New invariant on pre-existing tests0Baseline tests need no new assertion.
  • eip.md · Specification No new log, receipt, header field or protocol storage write is introduced.
Cryptography0No cryptographic mechanism changes.
  • eip.md · Specification No hashing, signing or verification is involved.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-5920.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob f8c6f353cb · sha256 f9b6d2938174
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-5920.yaml · sha256 f3d3de9b94c9
Supporting documents supplied with the EIP
supporting/eip-141.md, supporting/eip-214.md, supporting/eip-1153.md, supporting/eip-1283.md, supporting/eip-2200.md, supporting/eip-2929.md, supporting/eip-6780.md, supporting/eip-7523.md, supporting/eip-7702.md

Evaluated on: Not recorded

14MediumMedium
Evaluator
HumanChecklist v2
Confidence
Not recorded
Under-specified at assessment cutoff
Not recorded in the checklist
Checklist published
2026-08-18
Score bands · Checklist revision 2
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the Human total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Added opcodes2
  2. State-access ordering within opcode execution2
  3. State gas accounting changes2
  4. Security risks2

Criterion breakdown

EIP-5920 Hegotá: Human criterion scores and rationale
CriterionScoreWhy this scoreNotes
Added opcodes2One new complex opcode: `PAY` (`0xfc`), complex via its dynamic gas cost. Was 3 under revision 1; level 3 requires multiple opcodes.—
State-access ordering within opcode execution2New state-accessing operation whose order must be settled. PAY's gas depends on whether `addr` exists, read before the transfer is known to succeed. Unspecified: whether `addr` enters the BAL when PAY returns 0 for insufficient balance, and whether `GAS_NEW_ACCOUNT` is still charged for an account never created.—
State gas accounting changes2New state-gas charging site. PAY creates an account when `addr` is absent and `val` non-zero, costing `StateGasCosts.NEW_ACCOUNT` (183,600 state gas) plus `ACCOUNT_WRITE` (9,000 execution gas). The EIP's gas table has no state-gas term, so this branch is unpriced.—
Security risks2Force-funding without calling is already possible via `SELFDESTRUCT` and coinbase priority fees, so no invariant is newly broken, but `PAY` makes it much cheaper.—
Edge/boundary conditions2Multiple boundary-prone mechanisms, none needing elevated cases: `val` 0, zero-address, `addr` equal to self, the two exceptional halts (high 12 bytes set, static frame), and the gas tree over warm/cold, `addr` exists or not, and `val` zero or not. All within one opcode, so 2 rather than the revision-1 score of 3.—
Cross-EIP interactions2Five interacting EIPs, each individually simple: **EIP-7523** (hard precondition — PAY "cannot be implemented on networks with empty accounts"), **EIP-7708** (should emit a transfer log), **EIP-7928** (BAL entries), **EIP-8037** (state gas), **EIP-6780** (cited as the existing force-send route). Was 0 under revision 1.—
Unspecified behavior requiring cross-client consensus2Predates three live Amsterdam mechanisms and requires an update: whether `PAY` emits an EIP-7708 transfer log, how its accesses and balance changes enter the EIP-7928 BAL, and how account creation is priced under EIP-8037. Self-directed PAY (`addr` equal to the current address) is also unstated.—
Show 21 zero-score criteria
Zero-score criteria (Checklist revision 2)
CriterionScoreWhy this scoreNotes
Modified opcodes0No rationale recorded.—
Added precompiles0No rationale recorded.—
Modified precompiles0No rationale recorded.—
Added system contracts0No rationale recorded.—
Modified system contracts0No rationale recorded.—
EVM Gas rule changes0No new mechanism. PAY composes existing ones: warm/cold access, `GAS_NEW_ACCOUNT`, `GAS_CALL_VALUE`. Its dynamic cost is scored under Added opcodes.—
Blob gas accounting changes0No rationale recorded.—
New EVM gas refund0No rationale recorded.—
New transaction types0No rationale recorded.—
New or modified transaction validity mechanisms0No rationale recorded.—
New block / header fields0No rationale recorded.—
Encoding changes (RLP/SSZ)0No rationale recorded.—
Block syncing changes0No rationale recorded.—
New fork activation mechanism0No rationale recorded.—
Engine API changes0No rationale recorded.—
Transition-tool interface changes0No rationale recorded.—
Patterns affecting pre-existing tests0Purely additive; no existing test changes.—
New invariant on pre-existing tests0No rationale recorded.—
New test-framework primitives0Existing primitives suffice: balance expectations and BAL balance-change primitives already exist.—
Performance risks0No rationale recorded.—
Cryptography0No rationale recorded.—
Assessment provenance
Rubric
Checklist revision 2 · ethspecs/pm@3d8c0128c5
Evaluator
STEEL team · ethspecs/pm complexity_assessments
Source record
Open pull request #116: Update EIP-5920 complexity assessment to checklist revision 2 · checklist at c2b40ca1b8 · updated 2026-08-18
blob ff44f79881 · sha256 6f9c855fe336
Research record
research/tasks/09-hegota-human-assessment-snapshot/outputs/assessments/eip-5920.yaml · sha256 133e9319f25b

The LLM applied checklist revision 3 and the human reviewers revision 2 to EIP-5920 in Hegotá. Revision 3 phrases the same criteria more precisely; differences cover the 28 criteria both revisions share, and each total keeps its own revision. Δ is LLM minus Human.

Using the latest scored LLM evaluation for this checklist: 2026-10-08 · spec 2026-10-07 · 6dac5e7491. The Human and LLM assessments may use different spec revisions.

LLM18Medium
Human14Medium
Δ total+4Same tier
Criteria21/28agree exactly · 6 differ by 1 · 1 differ by 2+

Complexity profiles side by side

LLM
Human

Largest disagreements: EVM Gas rule changes (+2), Patterns affecting pre-existing tests (+1), New test-framework primitives (+1), Edge/boundary conditions (+1), Performance risks (+1)

Per-criterion scores, Human versus LLM, ordered by the size of the difference
CriterionLLMHumanΔAgreementRationale from each source
EVM Gas rule changes20+2Differ by 2+
Show rationale

LLM PAY adds a new dynamic charging rule at a new instruction. It is built from existing components and does not change any existing opcode's gas or baseline gas results. That fits level 2: a new mechanism with no change to existing rules.

Human No new mechanism. PAY composes existing ones: warm/cold access, `GAS_NEW_ACCOUNT`, `GAS_CALL_VALUE`. Its dynamic cost is scored under Added opcodes.

Patterns affecting pre-existing tests10+1Differ by 1
Show rationale

LLM Baseline tests that treat 0xfc as an undefined or invalid opcode need new expected results. This rework is limited to particular cases in one family (undefined-opcode coverage).

Human Purely additive; no existing test changes.

New test-framework primitives10+1Differ by 1
Show rationale

LLM The framework's opcode definitions need a local extension for PAY: its stack arity and a gas calculator for its dynamic cost. No new abstraction is needed.

Human Existing primitives suffice: balance expectations and BAL balance-change primitives already exist.

Security risks12−1Differ by 1
Show rationale

LLM The new security conditions can be checked locally: static enforcement, address-width halting, insufficient-balance handling, and no code running at the recipient (including delegated EOAs). No other component's assumptions change.

Human Force-funding without calling is already possible via `SELFDESTRUCT` and coinbase priority fees, so no invariant is newly broken, but `PAY` makes it much cheaper.

Performance risks10+1Differ by 1
Show rationale

LLM A component benchmark of worst-case PAY workloads (many cold or new-account transfers per block) is enough. Baseline end-to-end performance assumptions do not change.

Human No rationale recorded.

Edge/boundary conditions32+1Differ by 1
Show rationale

LLM There are several independent boundary-sensitive mechanisms: address-width validation (bit 160 vs. lower bits), the balance >= val comparison (equal, one wei short), and exact-gas out-of-gas points. The gas rule has an elevated matrix: recipient existence × val zero/non-zero decides GAS_NEW_ACCOUNT, and warm/cold adds to it. These cannot be tested independently, so level 3 applies.

Human Multiple boundary-prone mechanisms, none needing elevated cases: `val` 0, zero-address, `addr` equal to self, the two exceptional halts (high 12 bytes set, static frame), and the gas tree over warm/cold, `addr` exists or not, and `val` zero or not. All within one opcode, so 2 rather than the revision-1 score of 3.

Unspecified behavior requiring cross-client consensus12−1Differ by 1
Show rationale

LLM Some local details are omitted: account creation on a zero-value PAY, self-PAY, and access-list recording on failure paths. The surrounding rules (no empty accounts, CALL-like semantics) support one intended outcome for each, so this is level 1.

Human Predates three live Amsterdam mechanisms and requires an update: whether `PAY` emits an EIP-7708 transfer log, how its accesses and balance changes enter the EIP-7928 BAL, and how account creation is priced under EIP-8037. Self-directed PAY (`addr` equal to the current address) is also unstated.

Added opcodes220Agree
Show rationale

LLM Exactly one instruction is added. Its gas is dynamic, so it is complex, which gives level 2.

Human One new complex opcode: `PAY` (`0xfc`), complex via its dynamic gas cost. Was 3 under revision 1; level 3 requires multiple opcodes.

Modified opcodes000Agree
Show rationale

LLM No existing instruction's semantics or availability change.

Human No rationale recorded.

Added precompiles000Agree
Show rationale

LLM None added.

Human No rationale recorded.

Modified precompiles000Agree
Show rationale

LLM None modified.

Human No rationale recorded.

Added system contracts000Agree
Show rationale

LLM None added.

Human No rationale recorded.

Modified system contracts000Agree
Show rationale

LLM No system contract's rules or surrounding protocol behavior change.

Human No rationale recorded.

State-access ordering within opcode execution220Agree
Show rationale

LLM PAY is a new state-accessing operation that needs its own ordering rule. The existence read and the warm/cold check come before the charge, and the warming and transfer come after it. No existing opcode's ordering changes. Relevant combinations are cold/warm, existing/non-existing recipient, static/non-static, enough/too little balance, revert/success, and out-of-gas at each gas part.

Human New state-accessing operation whose order must be settled. PAY's gas depends on whether `addr` exists, read before the transfer is known to succeed. Unspecified: whether `addr` enters the BAL when PAY returns 0 for insufficient balance, and whether `GAS_NEW_ACCOUNT` is still charged for an account never created.

Blob gas accounting changes000Agree
Show rationale

LLM No blob-gas rule is affected.

Human No rationale recorded.

State gas accounting changes220Agree
Show rationale

LLM PAY adds a new place where an existing account-creation charge applies, without a new state-gas mechanism. That matches level 2: charging added at a new site using an existing mechanism.

Human New state-gas charging site. PAY creates an account when `addr` is absent and `val` non-zero, costing `StateGasCosts.NEW_ACCOUNT` (183,600 state gas) plus `ACCOUNT_WRITE` (9,000 execution gas). The EIP's gas table has no state-gas term, so this branch is unpriced.

New EVM gas refund000Agree
Show rationale

LLM No refund mechanism is introduced.

Human No rationale recorded.

New transaction types000Agree
Show rationale

LLM No new transaction type.

Human No rationale recorded.

New or modified transaction validity mechanisms000Agree
Show rationale

LLM No consensus rule on transaction validity changes.

Human No rationale recorded.

New block / header fields000Agree
Show rationale

LLM None.

Human No rationale recorded.

Encoding changes (RLP/SSZ)000Agree
Show rationale

LLM No schema changes.

Human No rationale recorded.

Block syncing changes000Agree
Show rationale

LLM No block decoding or structural validation changes.

Human No rationale recorded.

New fork activation mechanism000Agree
Show rationale

LLM Only a rule switch at activation. No one-time state transition.

Human No rationale recorded.

Engine API changes000Agree
Show rationale

LLM No Engine API change.

Human No rationale recorded.

Transition-tool interface changes000Agree
Show rationale

LLM The transition tool's interface does not need to change.

Human No rationale recorded.

New invariant on pre-existing tests000Agree
Show rationale

LLM Baseline tests need no new assertion.

Human No rationale recorded.

Cryptography000Agree
Show rationale

LLM No cryptographic mechanism changes.

Human No rationale recorded.

Cross-EIP interactions220Agree
Show rationale

LLM Coordinated cases are needed with EIP-214 (PAY in static frames, including val=0), EIP-2929 (warming shared with CALL/BALANCE, and warming undone on revert) and EIP-7702 (PAY to a delegated EOA runs no code and charges no delegation-resolution cost). Each of these is a pairwise interaction, not a coupled multi-EIP restructuring, so level 2 applies.

Human Five interacting EIPs, each individually simple: **EIP-7523** (hard precondition — PAY "cannot be implemented on networks with empty accounts"), **EIP-7708** (should emit a transfer log), **EIP-7928** (BAL entries), **EIP-8037** (state gas), **EIP-6780** (cited as the existing force-send route). Was 0 under revision 1.

Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.