Blockstream review says Falcon-1024 is the strongest lattice-signature candidate for Bitcoin, while hash-based signatures remain the near-term fallback
Blockstream Research has published a detailed review of post-quantum lattice signatures for Bitcoin, comparing Dilithium, Falcon and Hawk across on-chain footprint, verification cost, implementation difficulty, deployment risk and long-term usability. The report starts from a practical premise: Bitcoin’s current Schnorr and ECDSA signatures are efficient today, but Shor’s 1994 result means a sufficiently capable quantum computer could break them, so migration planning cannot wait until the threat is immediate. The study argues that Bitcoin should target at least NIST security level 3 because coins can remain unspent for decades, leaving funds exposed if future cryptanalysis weakens lower-margin parameters. On that basis, Dilithium stands out for simple integer-only implementation and broad software support, but its size is a major drawback on-chain. Falcon offers much smaller signatures and the fastest verification, though its signing path is harder to implement safely because of floating-point Gaussian sampling. Blockstream says deterministic, integer-simulated Falcon can address that issue at the cost of slower signing. Hawk, once notable for very small signatures and low memory use, has dropped out after Straznickas and Weis of Anthropic found a structural flaw that sharply reduced its estimated security. Blockstream’s bottom line is that if a lattice-based option had to be chosen today, Falcon-1024 would be the pick. Even so, the report says the conservative short-term path for Bitcoin is still hash-based signatures until the FN-DSA standard is finalized and production-grade implementations and hardware support mature.








