‹ BackNewsHAWK

HAWK

Bitcoin
2026-08-29 14:30:00

Blockstream study weighs Bitcoin lattice signatures against quantum risk, favors Falcon-1024 if forced to choose

Blockstream Research has published a full review of lattice-based signature schemes for Bitcoin, comparing Dilithium, Falcon, and Hawk as post-quantum replacements for Schnorr and ECDSA. The report starts from a practical concern: Shor’s 1994 result showed that sufficiently powerful quantum computers could break today’s elliptic-curve signatures, so Bitcoin needs a deployment path before that threat becomes real. The study ranks candidates across four criteria that matter specifically to Bitcoin: on-chain cost, implementation complexity, deployment risk, and long-term development potential such as BIP-32-style key derivation. It argues that Bitcoin should target at least NIST security level 3 because outputs may remain unspent for decades. In that framework, Dilithium stands out for simple integer-only implementation and the strongest basis for future key derivation work, but its signatures are large. Hawk had looked attractive on size and memory use, yet a newly disclosed structural attack weakened confidence enough for the team behind it to withdraw the scheme from the NIST process. That leaves Falcon as the most balanced option in the report’s view. Its signatures are compact, verification is the fastest among the three, and its security assumptions are more established. Falcon still has unresolved issues, including floating-point complexity in signing, no practical key derivation method, and a standard that has not yet been finalized. Even so, the report says Falcon-1024 would be the preferred lattice-based choice today, while hash-based signatures remain the more conservative near-term path for Bitcoin.

1040
Blockstream study weighs Bitcoin lattice signatures against quantum risk, favors Falcon-1024 if forced to choose
Bitcoin
2026-08-27 12:01:38

Blockstream review says Falcon-1024 is the strongest lattice-signature candidate for Bitcoin, while hash-based signatures remain the near-term fallback

Blockstream Research has published a detailed review of post-quantum lattice signatures for Bitcoin, comparing Dilithium, Falcon and Hawk across on-chain footprint, verification cost, implementation difficulty, deployment risk and long-term usability. The report starts from a practical premise: Bitcoin’s current Schnorr and ECDSA signatures are efficient today, but Shor’s 1994 result means a sufficiently capable quantum computer could break them, so migration planning cannot wait until the threat is immediate. The study argues that Bitcoin should target at least NIST security level 3 because coins can remain unspent for decades, leaving funds exposed if future cryptanalysis weakens lower-margin parameters. On that basis, Dilithium stands out for simple integer-only implementation and broad software support, but its size is a major drawback on-chain. Falcon offers much smaller signatures and the fastest verification, though its signing path is harder to implement safely because of floating-point Gaussian sampling. Blockstream says deterministic, integer-simulated Falcon can address that issue at the cost of slower signing. Hawk, once notable for very small signatures and low memory use, has dropped out after Straznickas and Weis of Anthropic found a structural flaw that sharply reduced its estimated security. Blockstream’s bottom line is that if a lattice-based option had to be chosen today, Falcon-1024 would be the pick. Even so, the report says the conservative short-term path for Bitcoin is still hash-based signatures until the FN-DSA standard is finalized and production-grade implementations and hardware support mature.

1090
Blockstream review says Falcon-1024 is the strongest lattice-signature candidate for Bitcoin, while hash-based signatures remain the near-term fallback
Anthropic says Claude found two cryptographic weaknesses without breaking real-world encryption
Anthropic says Claude Mythos found new attacks on HAWK as crypto markets rise ahead of the FOMC
Anthropic says Claude found new attacks on HAWK and reduced-round AES