TIL it was that slow. I worry that benchmarking against the worst case as the new “average” is the wrong goal as this may potentially become the average way of interacting with Bitcoin (unlike using lots of signatures, which seems rare). Basically we should expect ~every block to approach that level of verification cost, so I’d expect we would target something we would be happy with for IBD or at tip with relatively turbulent mempools. waving wildly On the order of 100ms?
edit: Or maybe I’m wrong and the average GSR block would be significantly faster, just like now with sigops.
Might be harder to predict what will actually be deemed useful vs “more sigops” which seem to have marginal utility?