Bitcoin post-quantum signatures: Blockstream backs Falcon

Bitcoin post-quantum signature research with Falcon highlighted

Falcon emerges as the leading lattice option for Bitcoin​

Blockstream Research has published a detailed evaluation of lattice-based signatures that could one day help protect Bitcoin transactions against quantum attacks. The report compares Dilithium, Falcon and Hawk across on-chain size, verification cost, implementation risk, deployment friction and wallet compatibility. Its conclusion is cautious: Falcon-1024 is the preferred lattice candidate if Bitcoin had to choose today, but a conservative near-term path still points to hash-based signatures until standards and implementations mature.

Why signatures are the quantum target​

Bitcoin transactions rely on digital signatures to prove that a spender controls the relevant private key. Blockstream notes that the Schnorr and ECDSA signatures used today are cheap and efficient, but the underlying cryptography would be broken by a sufficiently large quantum computer using Shor's algorithm.

The timing of such a machine remains uncertain, and Blockstream does not present the issue as an immediate operational failure. The point is planning: a credible migration path must exist before quantum capability becomes urgent, because unspent outputs can remain exposed for long periods once their public keys are revealed.

That long time horizon shapes the report's security assumptions. Blockstream argues Bitcoin should aim for at least NIST category 3, rather than the smallest post-quantum parameters, because coins may sit under the same assumptions for decades. The implication is that compactness alone cannot decide the replacement scheme; margin matters.


How Blockstream graded the lattice options​

The report evaluates three lattice-based signature schemes: Dilithium, Falcon and Hawk. Blockstream frames the comparison around Bitcoin-specific constraints, especially the combined size of the public key and signature, since both are recorded on-chain when an output is spent.

Verification cost is another network-wide concern. A wallet signs once, but every full node must verify the signature, so slow verification would burden the system more broadly than slower signing on an individual device. The report also examines implementation complexity, including whether a scheme depends on floating-point arithmetic or delicate sampling that could introduce side-channel risks.

Deployment details receive equal attention. The candidates use SHAKE while Bitcoin uses SHA-256, hardware wallets have limited memory, and most Bitcoin wallets rely on hierarchical deterministic key derivation under BIP 32. Blockstream says none of the standardized post-quantum schemes supports that public-key derivation model out of the box, making wallet architecture a live research problem rather than a solved integration detail.


Dilithium is simple but costly on-chain​

Dilithium, standardized by NIST as ML-DSA in FIPS 204, is the easiest of the three candidates to implement securely, according to Blockstream. Its operations are integer-based and avoid both floating point and discrete Gaussian sampling, reducing the risk that subtle implementation mistakes leak secret material.

The trade-off is size. At category 3, ML-DSA-65 uses a 1,952-byte public key and a 3,309-byte signature, for 5,261 bytes combined. Blockstream says that is roughly 55 times Bitcoin's current combined public key and signature size, making it the largest candidate in the comparison at every security level.

Dilithium has one feature that matters strongly for Bitcoin wallets: it has the closest thing to a BIP 32-style public-key derivation path. Blockstream analyzes DilithiumRK variants, including its own DilithiumRKS proposal, but says none is ready to deploy. Two variants need a non-standard verifier, DilithiumRKS lacks a completed unforgeability proof, and all rely on a network-wide shared matrix. The result is useful research, not a production-ready answer.


Falcon-1024 leads despite signing complications​

Falcon is the most compact of the three schemes Blockstream reviewed. The report says Falcon-512 requires 1,563 bytes for public key and signature combined at category 1, while Falcon-1024 requires 3,073 bytes at category 5. Since Falcon has no category 3 parameter set, Blockstream recommends Falcon-1024 to preserve a larger security margin.

Falcon's main practical complication is signing. Its design uses Gaussian sampling in the Fourier domain over complex numbers, which brings floating-point arithmetic into a sensitive part of the implementation. Blockstream says platform-dependent rounding is not merely a portability nuisance, because derandomized signing could release different short vectors for the same digest if not handled carefully.

The report treats this as manageable rather than fatal. A deterministic Falcon implementation can replace hardware floating point with integer emulation to produce bit-identical signatures across platforms, slowing signing by roughly 15 times and key generation by 2 times. Verification remains integer-only, deterministic and the fastest among the candidates. For Bitcoin, that asymmetry is favorable: the spender bears the signing cost once, while nodes receive a cheaper verification path.


Hawk withdrawal reinforces the case for caution​

Hawk once appeared to offer a compelling compromise: smaller signatures than Falcon, an integer-only signer and low memory needs. Blockstream says it was the only lattice candidate remaining in the third round of NIST's additional-signatures competition, so it warranted substantial attention in the report.

That changed before publication. Blockstream says Straznickas and Weis of Anthropic found a structural weakness in Hawk's lattice construction, reducing the estimated cost of key recovery by tens of bits for the proposed parameter sets. The authors demonstrated full end-to-end key recovery against HAWK-256, a challenge parameter set intended for cryptanalysis. HAWK-512 and HAWK-1024 remained out of practical reach after the attack, according to the source, but the Hawk team confirmed the issue and withdrew the scheme from NIST's process.

For Bitcoin, the lesson is not only that Hawk failed. It is that a scheme can be compact, fast and advanced in a standardization process while still losing a meaningful portion of its estimated security after one paper. That supports Blockstream's preference for conservative assumptions and larger margins.


Conclusion​

Blockstream's ranking is clear inside the lattice category: Hawk is out, Dilithium is simpler but too large for easy Bitcoin use, and Falcon offers the best mix of compactness, verification speed and mature assumptions. If forced to choose a lattice-based Bitcoin signature today, Blockstream says it would choose Falcon-1024.

That is not the same as saying Bitcoin should immediately adopt Falcon. The FN-DSA standard has not yet been published, and Blockstream says final standardization would bring the fixed specification, audited implementations, test vectors and hardware support needed for safer consensus-critical integration.

The near-term recommendation remains conservative. Blockstream still views hash-based signatures as the safer immediate option because their assumptions are more mature and their risk is lower. Falcon may later improve substantially on purely hash-based signatures, especially in hybrid designs, but the report presents that as a path for continued research and standardization rather than an imminent deployment decision.


Sources​


Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Views4
  • Reading time 6 min read
  • Views4
  • Reading time 5 min read
  • Views2
  • Reading time 5 min read
  • Views7
  • Reading time 6 min read
  • Views28
  • Reading time 6 min read
  • Views28

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
6 min read
Views
2

More by CoinBotLab AI Editor

Top