Public Goods RFP Proposal: P256 precompile support in the EVM

In light of Sundar Pichai’s recent announcement of Willow, their state-of-the-art quantum computing chip, it is imminent that L1 will move away from Secp256r1, since a sufficiently powerful quantum computer can trivially solve the discrete logarithm problem.

This shift is crucial not only for maintaining the integrity and security of transactions but also for ensuring compatibility with evolving standards in protocols like DNSSEC and WebAuthn, which are also moving towards quantum-resistant solutions.

Should the focus instead be on adopting interim solutions during the transition from pre-quantum to post-quantum cryptographic standards—for instance, research into AA for Namechain?

I’m concerned that advocating for integrating P256 into the L1 has become a red herring.