Skip to content

LibraryPrivacy2020Design paperCorpus record

Slashing Protection Interchange Format

EIP 3076. Michael Sproul , Sacha Saint-Leger , Danny Ryan.

EIP 3076, Slashing Protection Interchange Format. A standard format for transferring a key's signing history allows validators to easily switch between clients without the risk of signing conflicting messages.

Status in the source: Last Call. A reading of the public specification, not a copy of it and not a certification.

Slashing Protection Interchange Format is worth reading for the rule it actually adds: A standard format for transferring a key's signing history allows validators to easily switch between clients without the risk of signing conflicting messages.

The five-minute read

The rule

A standard format for transferring a key's signing history allows validators to easily switch between clients without the risk of signing conflicting messages.

What was already failing

A signature that does not commit to what the user saw can be replayed into a different spend, a different chain, or a different message.

What the number does not mean

The source marks this last call. It is not a live consensus rule just because it has a number.

What a builder should be able to point at

An implementation either constrains Slashing Protection Interchange Format or it is a different design.

One action, walked through

  1. Open EIP 3076 and read the status line before the examples.
  2. Write down the rule in one sentence. A fair version of that sentence is: A standard format for transferring a key's signing history allows validators to easily switch between clients without the risk of signing conflicting messages.
  3. Name the object that changes: Slashing Protection Interchange Format.
  4. Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.

The argument, unpacked

What the text is allowed to settle

Ethereum Improvement Proposal 3076 can settle the shape of Slashing Protection Interchange Format. It cannot settle whether a later client, a later fork, or a later wallet still does this.

What this page will not pretend

There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.

What has to be true

  • You are implementing EIP 3076 at the status the text itself states: Last Call.
  • The object that has to change is Slashing Protection Interchange Format. A neighbouring document with a similar name is not this one.
  • Wallet support is not the same as consensus validity.

What happened after the paper

The source marks this last call. It is not a live consensus rule just because it has a number. Later documents can narrow, replace, or ignore this one. Cite the number you mean.

What to check before you use the idea

  • What is covered by the signed bytes in Slashing Protection Interchange Format?
  • Can the same signature be replayed on another chain, account, or message?
  • Which primitive does the text require: Slashing Protection Interchange Format?

Terms

EIP 3076
The public text titled Slashing Protection Interchange Format.
Last Call
The document's own label for how finished the text is. It is not a market fact.

The problem the paper names

A signature that does not commit to what the user saw can be replayed into a different spend, a different chain, or a different message.

What the design proposes

  • A standard format for transferring a key's signing history allows validators to easily switch between clients without the risk of signing conflicting messages.
  • While a common keystore format provides part of the solution, it does not contain any information about a key's signing history.
  • For a validator moving their keys from client A to client B, this could lead to scenarios in which client B inadvertently signs a message that conflicts with an earlier message signed with client A.

How the mechanism is specified

  • Taken from the specification, the next constraint is: While a common keystore format provides part of the solution, it does not contain any information about a key's signing history.
  • Locate Slashing Protection Interchange Format in EIP 3076 and apply it to one transaction or call.
  • Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.

What this page does not treat as proven

  • A signature scheme is not a privacy system. It hides the signer only if the protocol says so.
  • Wallet support is not the same as consensus validity.
  • The source marks this last call. It is not a live consensus rule just because it has a number.

Why a venture studio still reads it

Use EIP 3076 when a pitch says 'Slashing Protection Interchange Format' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.