Blockstream said a widely cited concern in the crypto industry — that existing hardware wallets are too constrained to support post-quantum cryptography — does not hold up, at least for hash-based signature schemes. According to the company, its research team tested five hash-based schemes across four mainstream hardware wallets: Jade, Trezor, Ledger and BitBox02. All tested devices were able to generate signatures.
The results varied by scheme. SLH-DSA took about 53 to 120 seconds per signature, while SPHINCS+ at the 2^40 setting was slightly faster. UXMSS using SHRINCS-B finished in 22 to 42 seconds. UXMSS with SHRINCS-L took much longer at 226 to 573 seconds because of the overgrinding technique, though that fell to just over 3 seconds with the feature disabled. XMSS needed 58 to 118 seconds in cold-start mode, but Blockstream said caching can significantly improve performance.
The team added that the test only covered hash-based signature generation. It did not include firmware verification or other post-quantum approaches such as lattice-based or isogeny-based cryptography. Those engineering questions, including cache optimization, are set to be explored in later research.
Blockstream said on X that a common industry concern — that existing hardware wallets are too difficult to use for post-quantum, or PQ, cryptography — does not hold, at least for hash-based signature schemes.
The research team tested five hash-based signature schemes on four mainstream hardware wallets: Jade, Trezor, Ledger and BitBox02. The schemes were SLH-DSA, SPHINCS+, UXMSS (SHRINCS-B/L) and XMSS. Blockstream said every device in the test was able to generate signatures.
Timing results across the tested schemes
Based on the figures shared by Blockstream, SLH-DSA took about 53 to 120 seconds to generate a signature. SPHINCS+ in the 2^40 version was slightly faster.
UXMSS using SHRINCS-B took 22 to 42 seconds. UXMSS using SHRINCS-L was much slower because it used the overgrinding technique, taking 226 to 573 seconds. With that technique turned off, the time dropped to a little over 3 seconds.
XMSS took 58 to 118 seconds in cold-start mode, though the team said caching can speed it up substantially.
What the test did not cover
The researchers said the work only measured hash-based signature generation. It did not cover firmware verification or other post-quantum approaches, including lattice-based and isogeny-based cryptography. The team said later research will look at engineering issues such as cache optimization.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.