SHR

Blockstream
2026-08-27 02:37:07

Blockstream files Bitcoin upgrade proposal for SHRINCS, estimates throughput at about 3 TPS

Blockstream has submitted a Bitcoin Improvement Proposal laying out a specific upgrade path for its post-quantum signature scheme, SHRINCS. The company said SHRINCS has already been tested in production on Blockstream’s Liquid sidechain. Its smallest signature size is 548 bytes, roughly nine times larger than Bitcoin’s current 64-byte Schnorr signature, though still smaller than alternatives such as SPHINCS+, which has been approved by the U.S. National Institute of Standards and Technology, or NIST. According to Blockstream’s research, Bitcoin throughput would remain around 3 transactions per second if SHRINCS were adopted, a level it described as close to the network’s current performance. By comparison, using NIST-approved schemes could cut throughput to between 0.36 and 0.5 TPS. The proposal centers on how Bitcoin could approach a post-quantum signature transition while limiting the hit to network capacity.

240
Blockstream files Bitcoin upgrade proposal for SHRINCS, estimates throughput at about 3 TPS
Bitcoin
2026-08-27 01:26:54

SHRINCS BIP published for Bitcoin quantum security, but trade-offs remain

A Bitcoin Improvement Proposal for the post-quantum signature scheme SHRINCS has been published, putting a concrete Bitcoin-focused option into the debate over how the network could defend itself against future quantum attacks. The proposal comes from research led by Blockstream, whose team has already tested SHRINCS in production on the Liquid sidechain. Blockstream Research’s Jonas Nick described it as the first concrete post-quantum signature proposal designed specifically for Bitcoin, while also stressing that it is not meant to be Bitcoin’s final signature system and is not optimal in every respect. The core appeal is size. Existing post-quantum schemes endorsed by the National Institute of Standards and Technology are far larger than Bitcoin’s current ECDSA and Schnorr signatures, creating a major throughput problem if deployed directly on-chain. SHRINCS is still much bigger than Schnorr, but materially smaller than many alternatives, and Blockstream’s estimates suggest Bitcoin could still run at roughly 3 transactions per second under SHRINCS, versus 0.5 TPS for ML-DSA and 0.36 TPS for SPHINCS+. The catch is that SHRINCS is still early. Its BIP says the security proof remains unfinished, and the design introduces statefulness, signature growth over time, and a large fallback recovery path if a signing device is lost. Blockstream is also exploring lattice-based signatures and zero-knowledge proof aggregation, which it estimates could lift Bitcoin throughput to 6.7 TPS if combined with SHRINCS.

290
SHRINCS BIP published for Bitcoin quantum security, but trade-offs remain
Blockstream
2026-08-24 11:20:12

Blockstream says current hardware wallets can run hash-based post-quantum signatures

Blockstream said a widely cited concern in the crypto industry — that existing hardware wallets are too constrained to support post-quantum cryptography — does not hold up, at least for hash-based signature schemes. According to the company, its research team tested five hash-based schemes across four mainstream hardware wallets: Jade, Trezor, Ledger and BitBox02. All tested devices were able to generate signatures. The results varied by scheme. SLH-DSA took about 53 to 120 seconds per signature, while SPHINCS+ at the 2^40 setting was slightly faster. UXMSS using SHRINCS-B finished in 22 to 42 seconds. UXMSS with SHRINCS-L took much longer at 226 to 573 seconds because of the overgrinding technique, though that fell to just over 3 seconds with the feature disabled. XMSS needed 58 to 118 seconds in cold-start mode, but Blockstream said caching can significantly improve performance. The team added that the test only covered hash-based signature generation. It did not include firmware verification or other post-quantum approaches such as lattice-based or isogeny-based cryptography. Those engineering questions, including cache optimization, are set to be explored in later research.

430
Blockstream says current hardware wallets can run hash-based post-quantum signatures