Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI
Scope at the cutoff. EIP-8250 changes the EIP-8141 frame transaction payload. The single `nonce` becomes `nonce_keys`, a strictly increasing list of 1 to 16 uint256 keys, plus a shared uint64 `nonce_seq`. `nonce_keys == [0]` keeps using the legacy account nonce. Non-zero keys are stored in a new revert-only system contract, NONCE_MANAGER at 0x…8250, at slot keccak256(sender||key). The protocol checks these sequences for stateful validity and consumes them when a payment-scoped APPROVE succeeds. Each first-use slot costs EIP-8037 state gas, and these accesses do not count toward EIP-2929 warmth or EIP-2200 SSTORE pricing. The EIP also prices the nonce bytes as calldata, makes TXPARAM(0x01) return nonce_seq, adds TXPARAM selectors 0x0D–0x10, and installs NONCE_MANAGER at fork activation. Mempool identity and revalidation rules are updated to match.
- Evaluator
- LLMChecklist v3
- Confidence
- Medium
- Under-specified at assessment cutoff
- Yes — 3 criteria affected
- Plausible range
- 41–44 (High)
- Snapshot
- 2026-10-07 · EIP revision
6dac5e7491(2026-10-07)
Score bands · Checklist revision 3
- Low <12
- Medium 12–22
- High ≥23
28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.
Complexity profile
Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.
Top complexity drivers
- Modified opcodes3
- New or modified transaction validity mechanisms3
- Encoding changes (RLP/SSZ)3
- New fork activation mechanism3
Under-specified at assessment cutoff: Yes
The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.
Why: The rules for floor-token accounting of the nonce bytes, and whether the nonce calldata cost enters frame_tx_intrinsic_gas (EIP-7825 cap and block execution reservation), are ambiguous. Activation semantics for chains whose genesis is at or after the fork, and block-level access list recording of protocol keyed-nonce accesses, are not addressed.
Plausible total
41–44
recorded score 42 · plausible tiers High
Unresolved questions at the cutoff (4)
- Is the nonce_calldata floor contribution tokens_in or floor_tokens_in? EIP-8141 has no `calldata_tokens` variable.
- Does nonce_calldata_cost count toward frame_tx_intrinsic_gas for the EIP-7825 cap and the execution_reservation inclusion check?
- Are NONCE_MANAGER reads and writes made by stateful validity and APPROVE recorded in EIP-7928 block-level access lists?
- How is NONCE_MANAGER installed when a chain activates the fork at genesis, where no parent block is pre-fork?
Notable ambiguities noted by the assessor (4)
- The target says to add nonce tokens to `calldata_tokens`, but EIP-8141 uses calldata_floor_tokens computed with floor_tokens_in.
- nonce_calldata_cost is added to standard_gas_limit only. Its effect on the EIP-7825 cap and the block reservation is unclear.
- Block-level access list treatment of keyed-nonce protocol accesses is unstated.
- Activation at genesis is not covered.
Criterion breakdown
| Criterion | Score | Why this score | Evidence / uncertainty |
|---|---|---|---|
| Modified opcodes | 3 | The semantics of the TXPARAM and APPROVE instructions change, which fits level 3. |
Confidence: High |
| New or modified transaction validity mechanisms | 3 | The replay/nonce validity dependency moves from a single account nonce to multi-domain storage state. Tests must restructure sender-nonce handling and use coordinated multi-transaction block scenarios: overlapping and disjoint key sets, mixes of [0] and keyed transactions, and legacy-nonce changes through CREATE. That fits level 3. |
Confidence: Medium Uncertainty: Whether the nonce calldata cost affects the EIP-7825 cap and block reservation checks is unspecified. |
| Encoding changes (RLP/SSZ) | 3 | The serialized EL transaction schema changes, which fits level 3. |
Confidence: High |
| New fork activation mechanism | 3 | Protocol-mandated code installation at activation, which fits level 3. |
Confidence: High |
| Patterns affecting pre-existing tests | 3 | One common change, the payload schema plus priced nonce bytes, forces ordinary-case rework across distinct EIP-8141 test families after the fork. These include encoding and signature-hash, validity, APPROVE, TXPARAM, gas and fee settlement, and receipts. That fits level 3. |
Confidence: Medium Uncertainty: If EIP-8141 and this EIP activate in the same fork, some of this is authoring the prerequisite suite directly in the new format, which would argue for 2. |
| Security risks | 3 | The shared replay and authorization invariant changes across consensus validity, the APPROVE transition, mempool identity and revalidation, and contract verifiers. This needs coordinated adversarial scenarios, which fits level 3. |
Confidence: Medium |
| Edge/boundary conditions | 3 | Several boundary-sensitive mechanisms are introduced. The APPROVE state-gas check is an elevated matrix: frame limits.state × number of keys × how many keys are fresh vs. used × [0]-with-nonexistent-sender × approval scope 0x1/0x3 × VERIFY (makes the tx invalid) vs. non-VERIFY frame. That fits level 3. |
Confidence: High |
| Cross-EIP interactions | 3 | The target couples EIP-8141 transaction and APPROVE behavior with EIP-8037 state gas, EIP-7623 floor pricing, and EIP-2929 warmth. Coordinated scenarios are needed across these interactions, which fits level 3. |
Confidence: High Uncertainty: Interactions with EIP-7928 and EIP-7976 are suggested by the supporting texts but not established by the target. Interacting EIPs: EIP-8141, EIP-8037, EIP-7623, EIP-2929, EIP-2200 |
| Added system contracts | 2 | Exactly one contract is introduced, and it is stateful, which fits level 2. |
Confidence: High |
| State gas accounting changes | 2 | A new charging site (APPROVE keyed-slot creation) uses the existing EIP-8037 state-gas mechanism and frame state pools. No new mechanism and no change to spill between pools, which fits level 2. |
Confidence: High |
| Block syncing changesUnder-specified | 2 | Several simple structural decode rules are added for frame transactions in imported blocks, which fits level 2. |
Confidence: Low Uncertainty: The timestamp-dependent schema selection could count as a complex rule (level 3). Alternatively, these rules could be attributed only to transaction validity. |
| Transition-tool interface changes | 2 | Several transaction fields change (nonce removed; nonce_keys and nonce_seq added) without a new exchange mechanism. That fits level 2. |
Confidence: Medium Uncertainty: No t8n interface documentation was supplied. Whether parent-timestamp input already exists cannot be verified. |
| New invariant on pre-existing testsUnder-specified | 2 | Post-fork state must include the NONCE_MANAGER account, which affects state-root expectations for fork-transition and fork tests. Keyed storage writes are new-feature outputs. No pre-fork vectors need re-deriving, which fits level 2. |
Confidence: Medium Uncertainty: How genesis-at-fork test networks install NONCE_MANAGER is not specified. If it is pre-allocated, the effect is narrower (level 1). |
| New test-framework primitives | 2 | Tests need a construction abstraction for keyed nonce domains. It must compute NONCE_MANAGER slots, pre-populate them, and track sequences per key instead of auto-incrementing the account nonce. It must also produce frame transactions with key sets. This is a new abstraction within the target suite, but not a shared facility that changes other families, which fits level 2. |
Confidence: Medium Uncertainty: If existing frame-transaction builders are easily extensible, this could be a local extension (level 1). |
| Performance risks | 2 | Targeted integrated benchmarks are needed for blocks full of max-key frame transactions. Their uncharged storage reads and writes all concentrate on one huge contract storage trie. This is a bounded interaction, which fits level 2. |
Confidence: Medium Uncertainty: The costs of invalid-transaction storage reads in the mempool are not quantified. |
| Unspecified behavior requiring cross-client consensus | 2 | Localized competing gas outcomes need agreement: floor token counting for the nonce bytes, and whether the nonce cost enters intrinsic gas for the cap and reservation. That fits level 2. |
Confidence: Medium Uncertainty: EIP-7928 was not supplied, so the access-list point is an evidence gap rather than a confirmed omission. |
| EVM Gas rule changes | 1 | Existing frame-transaction gas formulas gain new inputs: the nonce calldata cost and tokens. This shifts the expected gas of every frame transaction, but no new execution-gas accounting mechanism is introduced. The access exemption is an exclusion, not a new mechanism. That fits level 1. |
Confidence: Medium Uncertainty: It is unclear whether the nonce calldata cost also enters frame_tx_intrinsic_gas for the EIP-7825 cap and the block execution_reservation. It is also unclear which token count feeds the floor. Neither question changes the level. |
| State-access ordering within opcode executionUnder-specified | 1 | Only APPROVE, a prerequisite instruction, has its state-access and charge ordering changed: up to 16 storage reads are inserted before its state-gas charge. No general class-wide ordering rule changes, which fits level 1. |
Confidence: Medium Uncertainty: The EIP does not say whether these protocol reads and writes are recorded in EIP-7928 block-level access lists. If a new recordable-access rule is needed, the score could reach 2. |
Show 10 zero-score criteria
| Criterion | Score | Why this score | Evidence / uncertainty |
|---|---|---|---|
| Added opcodes | 0 | No new instruction. |
|
| Added precompiles | 0 | None. |
|
| Modified precompiles | 0 | None. |
|
| Modified system contracts | 0 | No existing system contract changes. |
|
| Blob gas accounting changes | 0 | No blob-gas rule changes. |
|
| New EVM gas refund | 0 | No new refund mechanism. The only reversal of the keyed-nonce charge is the existing frame rollback. |
|
| New transaction types | 0 | An existing type is modified; no new envelope. |
|
| New block / header fields | 0 | None. |
|
| Engine API changes | 0 | No Engine API change. |
|
| Cryptography | 0 | Unchanged primitives are reused for slot derivation and key-set hashing, and the signing rules are unchanged. Changed message bytes count under encoding, which fits level 0. |
Uncertainty: Someone could treat nonce_keys_hash as a new hash commitment (level 1). |
Assessment provenance
- Assessed EIP revision
ethereum/EIPs@6dac5e7491EIPS/eip-8250.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z- Rubric
- Checklist revision 3 ·
ethspecs/pm@fe2f793b03 - Evaluator
- Opus 5.5 (
claude-opus-5-5) at high effort, one tool-less call per EIP · isolationbubblewrap_claude_p_no_tools_v1 - Source record
- Frozen research record
research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-8250.yaml· sha2560720dee23c20 - Supporting documents supplied with the EIP
supporting/eip-2200.md,supporting/eip-2929.md,supporting/eip-4337.md,supporting/eip-7623.md,supporting/eip-8037.md,supporting/eip-8141.md