Thursday, August 27, 2026
HomeCrypto NewsSHRINCS BIP Published: Quantum-Secure Bitcoin Comes With A Catch

SHRINCS BIP Published: Quantum-Secure Bitcoin Comes With A Catch

Blockstream co-founder and CEO Adam Back has a reputation as a quantum computer skeptic who believes the technology is so immature the threat won’t materialize for decades.

Which makes it all the more fascinating that his company is one of the leaders in researching practical solutions to the issue. Back told Cointelegraph earlier this year “the safe thing” is to prepare for the threat well in advance.

Blockstream has already proven its experimental post-quantum signature scheme called SHRINCS works in production on its Liquid sidechain and a Bitcoin Improvement Proposal for SHRINCS was published earlier today.

Blockstream Research’s Jonas Nick called it “the first concrete proposal for a post-quantum signature scheme designed specifically for Bitcoin.” But he added that “SHRINCS is not intended to be Bitcoin’s ‘final’ signature scheme, and it is not optimal along every axis.

”I do think it is a very good trade-off among the options we have now.”

Source: Jonas Nick

While the timeline is hotly debated, scientists agree that sufficiently advanced quantum computers will be able to reverse engineer private keys from public keys, thereby undermining Bitcoin’s security and enabling the theft of billions. That’s why the race is on to develop ways to upgrade Bitcoin to make it safe from attack. 

Shrinking the size of post quantum signatures

One of Blockstream’s most promising areas of study has been in optimizing post-quantum signature schemes for Bitcoin’s requirements to enable the blockchain to keep more of the existing properties Bitcoiners hold dear.

The current crop of post-quantum secure hash and lattice-based signature schemes endorsed by the National Institute of Standards and Technology are between 38 and 123 times larger than Bitcoin’s existing ECDSA and Schnorr signatures.

Deploying any of them in Bitcoin could slow the blockchain down to a fraction of 1 TPS. Ethereum’s post-quantum team plans to deal with this issue by aggregating signatures using a tiny zero-knowledge proof for each block. That’s under consideration for Bitcoin too, and if implemented, it would see Bitcoin actually run faster than it does today, as a single proof takes less blockspace than a bunch of signatures. But in the Bitcoin world, adding zero-knowledge proofs would be a fairly radical change and face a steep uphill battle to garner enough support for activation. 

Blockstream is considering that option too, but has wisely separated the proposal from the much more palatable option of figuring out how to shrink the size of NIST-approved hash based post-quantum signatures by around 13.23 times.

Related: Bitcoin’s quantum dilemma — Bigger blocks or STARK proofs?

Bitcoin optimized small(er) signatures

In December 2025, Blockstream researchers Jonas Nick and Mikhail Kudinov unveiled the SHRINCS signature scheme, and the opcode proposal was published in May. It’s a hash-based post-quantum signature scheme that has a minimum size of 548 bytes (plus the 48 byte public key) but can grow as large as 4,619 bytes.

“SHRINCS is the most Bitcoin-native post-quantum signature design anyone has produced,” explains Marin Ivezic, author of PostQuantum.com and founder of Applied Quantum.

“[It has] full BIP-39 seed recovery, and security resting on the same SHA-256 assumptions Bitcoin mining already depends on.” 

He tells Magazine the scheme is still at an early stage and hasn’t been audited, nor has it benefited from the years of public cryptanalysis the NIST signatures have weathered.

But he says even at this early stage, it’s a serious contender.

“It is real code that has signed real transactions on Liquid mainnet, and I rate it the strongest answer yet to going post-quantum without wrecking Bitcoin’s block economics.”

Despite being much smaller than most post-quantum signatures, SHRINCS will still be around nine times larger than Bitcoin’s existing Schnorr signatures, which are 64 bytes, or the older ECDSA signatures, which are 70 bytes. 

It might seem logical to assume that a signature nine times larger than the current ones would require Bitcoin’s block size to increase nine times to compensate, but Ivezic explains that’s not the case due to Bitcoin’s Segregated Witness.

“Under SegWit, signature bytes fit in the witness and take a quarter as much as other transaction data,” he says. 

According to estimates published in Blockstream’s earlier research (using slightly different parameters), Bitcoin could run at 6.5 transactions per second if everyone used Taproot’s Schnorr signatures (about 80% of people don’t). The blockchain’s speed would drop to 0.5 TPS if Bitcoin used the NIST-approved lattice-based signature ML-DSA and to just 0.36 TPS using the NIST-approved hash-based signature SPHINCS+.

But employing SHRINCS, the blockchain could run at 3 TPS, which is similar to today.

SHRINCS was tested in production on the Liquid sidechain in March this year — they even included a…

cointelegraph.com

RELATED ARTICLES

Most Popular

Recent Comments