protocol
StarkWare floats a Starknet L1 shift at Token2049, framing it as the quantum play
StarkWare CEO Eli Ben-Sasson and the Starknet account say the project is actively considering a move from Ethereum L2 to a standalone L1 to chase 2027 post-quantum security. No proposal yet.
StarkWare CEO Eli Ben-Sasson and the Starknet account used two X posts on October 8 — during Ben-Sasson's Token2049 slot — to publicly float moving Starknet from an Ethereum L2 to a standalone L1, framed as the path to being "the first fully quantum-resistant network" by 2027. The posts are the only primary artifacts so far: Ben-Sasson's poll and the Starknet account's statement that the move is "actively being considered." Bankless' writeup explicitly flags that no SNIP, forum post, or governance vote has been filed.
What was said, and what wasn't
- Ben-Sasson's framing: a "bunker mode" for Starknet against quantum and AI-era risk, borrowing the term from Jameson Lopp's Drake reference. The poll put the shift to his followers rather than to Starknet governance.
- The Starknet account's language is "actively considering," not "will move." The 2027 target is attached to being quantum-resistant, not to the L1 shift itself.
- No proposal. No vote. No published migration plan for the sequencer, the DA path, or the Ethereum-side bridge. The Bankless piece asked the obvious follow-up questions — token economics, settlement guarantees, how the existing
STRKand the Ethereum bridge would be unwound — and did not get an on-the-record answer. - Ethereum's own publicly discussed post-quantum target sits around end of 2029, which is the comparison Ben-Sasson is leaning on.
The prior primary doc
StarkWare's post-quantum roadmap predates this week. The June 2026 blog The Architecture Advantage: Starknet's Quantum Readiness Roadmap lays out how a STARK-based rollup can swap in post-quantum-safe hash and signature primitives without a full re-architecture. It contains no L1 commitment. The L1 question is a Token2049-era addition to that story, not a continuation of it.
Why L1 at all
The pitch is that an L2 inherits its base layer's cryptographic assumptions through the settlement contract on L1. If Ethereum's EVM and its validator set remain on elliptic-curve signatures past the point an operational quantum attack becomes credible, the rollup's finality guarantee is only as strong as its parent. A standalone chain lets Starknet pick its own signature scheme — plausibly a hash-based scheme in line with the direction other post-quantum projects are taking — without waiting on an Ethereum hard fork.
The counterweight, which the Starknet account does not address publicly, is what L1-settled TVL and the Ethereum-side STRK bridge do during such a migration. Shifting consensus and settlement off Ethereum is not a config flag.
Context
Starknet is not the only ZK team pushing a post-quantum timeline this quarter. Zcash's Zakura has committed to hash-based transparent-pool signatures for January (year unspecified), and the broader zkRollup field has been edging from BN254 toward BLS12-381 and beyond for similar reasons. StarkWare's angle is different: STARKs are already hash-based for proof construction, so the quantum pressure is on the settlement path, which is exactly what an L1 move would decouple.
The lede is also a governance one. A roadmap item posted on X by the founder, during a conference, with no SNIP and no forum thread, is not a protocol decision. Treat it as a trial balloon until a Starknet improvement proposal materializes.
What to watch
- A SNIP on the Starknet governance repo, or an equivalent forum thread, laying out the technical plan — consensus, DA, bridge policy, token mechanics — rather than the slogan. That is the first signal this moves from Twitter to protocol work.
- The settlement path. Any serious L1 plan has to say what happens to the Ethereum settlement contract, the
STRKbridge, and the existing L2 state. "Fork and migrate" and "run both in parallel" are very different stories. - Signature-scheme concreteness. The quantum argument lives or dies on what Starknet proposes to use for user signatures and validator signatures. Named candidates (XMSS, SPHINCS+, something custom) with parameter choices will tell operators what to build against.
- Ethereum Foundation response. If Starknet moves off, it is a precedent other L2 teams will cite in their own planning. The reaction from the EF research side matters for whether that becomes a trend.