1 hr ago3 min readBitcoin researchers propose quantum fix that would not crowd out transactions.SummaryBlockstream researchers published a proposal for SHRINCS, a way of signing bitcoin transactions that would hold up against quantum computers, which could otherwise work backwards from a public key on the blockchain to the private key controlling the coins.Quantum-safe signatures approved by NIST would cut Bitcoin from roughly 6.5 transactions per second to under one, because bigger signatures fill blocks faster. SHRINCS keeps about three by starting at 324 bytes against Schnorr's 64.The draft has no completed security proof, the reference software is not meant for production, and it warns that moving certain keys between incompatible wallets can lose funds. Reaching Bitcoin needs a soft fork and network-wide agreement.Researchers at Blockstream, a bitcoin infrastructure firm whose engineers have contributed to the Bitcoin blockchain’s core software for more than a decade, published a proposal on Thursday for SHRINCS, a way of signing bitcoin transactions that could withstand quantum computers without sharply reducing the number of transactions that fit in a block.Bitcoin proves ownership using digital signatures built on a branch of mathematics known as elliptic-curve cryptography. Those signatures allow someone to prove they hold the private key controlling their bitcoin without revealing the key itself.But it is theorized that a sufficiently powerful quantum computer running Shor's algorithm — the 1994 method that lets a quantum machine unpick the maths ordinary computers would take millions of years to solve — could eventually break that protection.Such a system could work backwards from a public key visible on the blockchain to calculate the private key, allowing an attacker to forge a signature and spend the coins.Read more: How a quantum computer can be used to actually steal your bitcoin in '9 minutes'A large amount of bitcoin already sits at addresses where public keys have been exposed, either because of how older addresses were constructed or because coins from them have previously been spent. This includes over 1.1 million bitcoin belonging to the network’s pseudonymous creator Satoshi Nakamoto, as CoinDesk reported in July.Solution for the size problemReplacing those signatures runs into a size problem. Post-quantum signatures standardized by the U.S. National Institute of Standards and Technology (NIST) can be dozens of times larger than the signatures Bitcoin uses today, and Bitcoin blocks have limited space, so larger signatures leave room for fewer transactions.Blockstream estimated that Bitcoin could process around 6.5 transactions per second if every transaction used today's compact Schnorr signatures, falling to about 0.36 with SLH-DSA, the hash-based scheme NIST has standardized.SHRINCS gets that back to roughly three transactions per second. Its signatures start at about 324 bytes, compared to 64 for Schnorr, growing by around 16 bytes each time a key is used, with the configuration reaching three transactions per second using 580-byte signatures.As such, five times larger does not cost five times the space because SegWit, a 2017 upgrade, gives the part of a transaction that holds signatures a discount.Quantum-safe signatures come at a cost to Bitcoin. (Shaurya Malwa/CoinDesk)SHRINCS is built using SHA-256, the same hash function already used throughout Bitcoin, including its mining system. That means its security does not depend on introducing an entirely new underlying mathematical assumption.Jonas Nick, who designed SHRINCS with fellow Blockstream researcher Mikhail Kudinov, called it the first concrete post-quantum signature proposal designed specifically for Bitcoin.He added that it is not intended to be Bitcoin's final signature system and is not the best option on every measure.SHRINCS uses a fresh one-time key whenever a wallet signs a transaction. The wallet therefore has to keep track of which keys have already been used and ensure they are never accidentally reused, and that record would need to remain correct across phones, hardware wallets, and backups. Restoring an old wallet copy or losing that information could make spending more cumbersome.The system is still early, however. The proposal states that its formal security proof is still pending, while the reference software has not undergone a formal security audit and is not intended for production use.Blockstream demonstrated SHRINCS-signed transactions in March on Liquid, a separate blockchain it operates that allows bitcoin and other assets to move between participants more quickly and privately.Bringing SHRINCS to Bitcoin itself would require a soft fork, or a backwards-compatible change to Bitcoin's rules, along with enough support across the network to activate it.The proposal comes as Ethereum researchers moved in the same direction earlier this week, proposing changes to the system validators use to deposit funds so it can eventually accept new types of cryptographic keys.12345678910Anvil: The Missing Collateral LayerAnvil: The Missing Collateral LayerAnvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.Jul 29, 2026Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.Why it matters:Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.View Full Report