Blockstream researchers published a draft specification on Thursday for SHRINCS, a post-quantum signature scheme built specifically for Bitcoin. They designed it to withstand a quantum computer without sharply reducing the number of transactions that fit in a block, the trade-off that hounds crypto’s post-quantum migration plans.
SHRINCS, short for Shrunken SPHINCS, is built on SHA-256, the hash function already embedded in Bitcoin’s consensus rules and its mining system. It pairs a compact stateful signing path with a stateless fallback for cases where a wallet loses track of its signing state. A public key runs 48 bytes. The smallest stateful signature is 548 bytes and grows by roughly 16 bytes each time the key is reused. The stateless fallback is 5,776 bytes.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Blockstream in May estimated Bitcoin could clear about 6.5 transactions per second if every transaction used Schnorr, dropping to roughly 0.36 under SLH-DSA, the hash-based scheme NIST has standardized. SHRINCS recovers close to three.
Each SHRINCS signature spends a one-time key, so a wallet must remember which keys it has used and never repeat one, across phones, hardware devices, and restored backups. The specification also warns that keys generated using hypertree pruning are incompatible with implementations that lack support for it, and importing across the two may lose funds. The formal security proof is listed as pending, the reference software is unaudited and not meant for production. Nick described SHRINCS as “the first concrete” post-quantum signature proposal designed for Bitcoin while saying it is not intended as the network’s final scheme.
Blockstream demonstrated SHRINCS-signed transactions in March on Liquid, the sidechain it operates. Bitcoin developers have spent the past year divided over migration paths, from BIP-361‘s proposed five-year freeze deadline to wallets that bolt on protection without touching the base layer, while research has pulled Q-Day closer. Ethereum researchers proposed a first step on validator deposit keys on Wednesday. Bringing SHRINCS to Bitcoin would require a soft fork and enough support across the network to activate it.
Related Listen: One Type of Post-Quantum Cryptography Is Most Popular. Why Is Crypto Trying Out Three?
