Blockstream study weighs Bitcoin lattice signatures against quantum risk, favors Falcon-1024 if forced to choose
Blockstream Research has published a full review of lattice-based signature schemes for Bitcoin, comparing Dilithium, Falcon, and Hawk as post-quantum replacements for Schnorr and ECDSA. The report starts from a practical concern: Shor’s 1994 result showed that sufficiently powerful quantum computers could break today’s elliptic-curve signatures, so Bitcoin needs a deployment path before that threat becomes real. The study ranks candidates across four criteria that matter specifically to Bitcoin: on-chain cost, implementation complexity, deployment risk, and long-term development potential such as BIP-32-style key derivation. It argues that Bitcoin should target at least NIST security level 3 because outputs may remain unspent for decades. In that framework, Dilithium stands out for simple integer-only implementation and the strongest basis for future key derivation work, but its signatures are large. Hawk had looked attractive on size and memory use, yet a newly disclosed structural attack weakened confidence enough for the team behind it to withdraw the scheme from the NIST process. That leaves Falcon as the most balanced option in the report’s view. Its signatures are compact, verification is the fastest among the three, and its security assumptions are more established. Falcon still has unresolved issues, including floating-point complexity in signing, no practical key derivation method, and a standard that has not yet been finalized. Even so, the report says Falcon-1024 would be the preferred lattice-based choice today, while hash-based signatures remain the more conservative near-term path for Bitcoin.








