Blockstream researchers have proposed SHRINCS, a new way to sign bitcoin transactions that would resist quantum computers without collapsing the network's transaction capacity. The design keeps throughput near three transactions per second, against under one transaction per second under existing quantum-safe standards, but it still lacks a completed security proof and would need a soft fork to reach Bitcoin.
Researchers at Blockstream published a proposal on Thursday for SHRINCS, a way of signing bitcoin transactions that could withstand quantum computers without sharply reducing the number of transactions that fit in a block. Jonas Nick designed the scheme with fellow Blockstream researcher Mikhail Kudinov.
A theoretical threat to bitcoin's signatures
Bitcoin proves ownership through digital signatures built on elliptic-curve cryptography, letting someone prove they hold a private key without revealing it. It is theorized that a sufficiently powerful quantum computer running Shor's algorithm could eventually break that protection, working backwards from a public key visible on the blockchain to calculate the private key and forge a spend. Over 1.1 million bitcoin belonging to Satoshi Nakamoto already sits at addresses where public keys have been exposed, CoinDesk reported in July.
Solving the size problem
Post-quantum signatures standardized by NIST can run dozens of times larger than Bitcoin's current signatures, and larger signatures leave room for fewer transactions per block. Blockstream estimated that Bitcoin could process around 6.5 transactions per second using today's Schnorr signatures, falling to about 0.36 with NIST's SLH-DSA scheme. SHRINCS instead gets throughput back to roughly three transactions per second, with signatures starting around 324 bytes against Schnorr's 64 and growing by about 16 bytes each time a key is used.
SHRINCS is built on SHA-256, the hash function Bitcoin already uses throughout its mining system, so it does not require introducing a new underlying mathematical assumption. Nick called it the first concrete post-quantum signature proposal designed specifically for Bitcoin, though he added it is not intended as Bitcoin's final signature system and is not the best option on every measure.
Still early, and not without trade-offs
The scheme uses a fresh one-time key every time a wallet signs, so the wallet must track which keys are already used and never reuse one, a record that has to stay consistent across phones, hardware wallets, and backups. The proposal's formal security proof is still pending, and its reference software has not undergone a security audit and is not meant for production use. Blockstream demonstrated SHRINCS-signed transactions in March on Liquid, a separate blockchain it operates. Reaching Bitcoin itself would require a soft fork and network-wide agreement to activate it.
The proposal follows Ethereum researchers moving in a similar direction earlier this week, proposing changes to how validators deposit funds so the network can eventually accept new types of cryptographic keys.
Source: CoinDesk
Trading involves risk.