Invest1 distinct publisher3 min readPublished
Blockstream's SHRINCS is the first post-quantum signature scheme written to Bitcoin's block economics, and Jonas Nick says up front it is not optimal. The argument now is about price.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
Take the shrink factor at face value. Blockstream's more palatable path is to compress NIST-approved hash-based post-quantum signatures by around 13.23 times [8], and the current NIST-endorsed hash and lattice schemes run 38 to 123 times larger than Bitcoin's ECDSA and Schnorr signatures [4]. Divide one by the other and you get a range of about 2.9x to 9.3x [2], which is how a post-quantum signature ends up roughly nine times a 64-byte Schnorr [14]. That holds at the floor: 548 bytes plus a 48-byte public key, so 596 bytes of new material per spend [10][6]. The ceiling is where it stops holding. At 4,619 bytes [10], a SHRINCS signature is about 72 times a Schnorr one [1], back inside the band the design exists to escape [4].
The throughput table has the same shape. Blockstream's earlier research, at slightly different parameters, put Bitcoin at 6.5 transactions per second if everyone used Taproot's Schnorr, and notes that about 80% of users do not [16]; the lattice-based ML-DSA lands at 0.5 and the hash-based SPHINCS+ at 0.36 [17]; SHRINCS comes in at 3, which Cointelegraph describes as similar to today [18]. So SHRINCS keeps 46% of the all-Schnorr estimate [3] while delivering roughly 8.3 times the throughput of SPHINCS+ [4]. Note which comparison is real: the 6.5 figure describes a chain nobody runs [16], and a fraction of 1 TPS is what any of the unmodified NIST options would deliver [5].
The other road is the one Ethereum's post-quantum team is taking, aggregating signatures into one small zero-knowledge proof per block, which in Bitcoin would leave the chain running faster than it does now because a single proof takes less blockspace than a pile of signatures [6]. It would also, per Cointelegraph, be a fairly radical change facing a steep uphill fight to activation, and Blockstream kept it apart from the SHRINCS proposal [7][8]. That separation is the tell. What gets filed alone is the conservative offer: security resting on the SHA-256 assumptions Bitcoin mining already depends on, with BIP-39 seed recovery intact, in the words of PostQuantum.com author Marin Ivezic [11]. Ivezic rates it the strongest answer yet to going post-quantum without wrecking Bitcoin's block economics, and in the same breath says it is early, unaudited, and has not had the years of public cryptanalysis the NIST signatures absorbed [12][13].
Jonas Nick's own framing does more work than any single byte count. A proposal whose author states it is not intended to be Bitcoin's final signature scheme and is not optimal along every axis [3] is not asking to be ratified; it is naming a price and waiting for counteroffers. Nobody disputes the threat, only its date [20]. What is in dispute is the bill: witness weight per signature, at a parameter set somebody has to choose, from code that has signed real transactions on Liquid mainnet [13] and almost nothing else.
Ranked by verification strength, evidence, and original report placement.
Blockstream has proven its experimental post-quantum signature scheme SHRINCS works in production on its Liquid sidechain, and a Bitcoin Improvement Proposal for SHRINCS was published the day of the report.
Blockstream researchers Jonas Nick and Mikhail Kudinov unveiled the SHRINCS signature scheme in December 2025, and the opcode proposal was published in May.
SHRINCS is a hash-based post-quantum signature scheme with a minimum size of 548 bytes plus a 48-byte public key, but it can grow as large as 4,619 bytes.
Marin Ivezic, author of PostQuantum.com and founder of Applied Quantum, called SHRINCS "the most Bitcoin-native post-quantum signature design anyone has produced", with "full BIP-39 seed recovery, and security resting on the same SHA-256 assumptions Bitcoin mining already depends on."
Ivezic says the scheme is still at an early stage and has not been audited, nor has it benefited from the years of public cryptanalysis the NIST signatures have weathered.
Ivezic says SHRINCS "is real code that has signed real transactions on Liquid mainnet, and I rate it the strongest answer yet to going post-quantum without wrecking Bitcoin's block economics."
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific and self-documented, but unaudited and single-sourced
The reporting carries unusually concrete artefacts: a published BIP, named authors, byte-level size figures, and transactions signed on a live sidechain. Against that, every number originates with the proposer, the scheme is unaudited, the BIP concedes a missing security proof, and only one publisher covers it, so there is no independent verification of either the cryptography or the throughput estimates.
Real code on a sidechain, nothing on Bitcoin
Adoption is limited to the proposer's own stack: a March production test on Blockstream's Liquid sidechain plus a December 2025 scheme release, a May opcode proposal and now a BIP. There is no evidence of Bitcoin consensus adoption, wallet integration, exchange or custodian support, or third-party implementation.
Mildly overstated by framing, largely self-corrected in text
The 'quantum-secure Bitcoin' framing and the 'strongest answer yet' endorsement run ahead of an unaudited scheme with no security proof and zero Bitcoin adoption, and the 3 TPS 'similar to today' line rests on the proposer's own parameters. The gap stays small because the same article concedes the tradeoffs up front — Nick's 'not optimal along every axis', the audit gap, and a critic's complexity objection.
Proposer-authored evidence plus commercially interested commentators
Blockstream authored the scheme, the BIP, the throughput estimates and the sidechain used for the production demo, so it supplies both the claim and its proof. The supporting expert founded a post-quantum consultancy and runs a post-quantum publication, while the critic founded a competing technology company. None of these positions is examined in the article.
Moderate: verifiable artefacts, one publisher, unresolved cryptography
Confidence is held down by single-publisher sourcing, dates given only to the month for two of the four adoption events, a truncated final passage in the supplied body, and the fact that the central technical question — whether SHRINCS is secure — is explicitly unresolved. It is held up by the specificity of the published BIP, named researchers and concrete byte and throughput figures.
invest
Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good1 distinct publisher
invest
Crypto's signature swap now has a date, a price tag, and no owner1 distinct publisher
leadership
Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic1 distinct publisher
build
Hybrid Post-Quantum TLS: Same Protocol, a 1,216-Byte Key Share1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026