Blockstream Researchers Publish SHRINCS, a New Bitcoin Proposal for Quantum-Resistant Signatures

Bitcoin’s signature scheme has not fundamentally changed since Taproot introduced Schnorr signatures. That quiet stretch got interrupted on August 27 when Blockstream researchers Jonas Nick and Mikhail Kudinov formally published a Bitcoin Improvement Proposal for SHRINCS, a hash-based signature scheme designed to survive an attack from a sufficiently powerful quantum computer — a threat that does not exist today but one a handful of cryptographers want Bitcoin prepared for regardless.
The proposal has already pulled prominent voices into the conversation, including Blockstream co-founder and CEO Adam Back, who has spent years publicly describing near-term quantum risk to Bitcoin as overstated. His involvement in backing preparatory work despite that skepticism is itself part of what makes this BIP notable.
A Signature Scheme Built on SHA-256, Not New Math
Most post-quantum proposals circulating in cryptography rely on new mathematical assumptions — lattice problems, code-based constructions, and so on — that are unproven relative to the decades of scrutiny applied to elliptic-curve cryptography. SHRINCS takes a different route: its security rests entirely on SHA-256, the same hash function that already secures Bitcoin’s proof-of-work. Because SHA-256 is not vulnerable to Shor’s algorithm the way ECDSA and Schnorr signatures are, hash-based schemes like SHRINCS are considered a conservative, if bulky, hedge.
The proposal also supports standard BIP-39 seed recovery, meaning wallets built around it would not require users to abandon familiar backup practices.
How Much Smaller Are These Signatures, Really
Bulk has always been the trade-off with hash-based signatures, and the numbers in the BIP make that explicit. SHRINCS signatures range from roughly 548 bytes to about 4,619 bytes depending on how a key has been used, compared with 64 bytes for a current Schnorr signature and 70 bytes for legacy ECDSA — still around nine times larger than what Bitcoin uses today. Against other NIST-approved post-quantum signature standards, though, SHRINCS is described as roughly 13 times smaller, since those alternatives typically run 38 to 123 times the size of a Schnorr signature.
Throughput estimates follow the same pattern: Bitcoin’s current Taproot signatures support an estimated 6.5 transactions per second under the SegWit witness discount; SHRINCS brings that down to about 3 TPS, versus roughly 0.36 TPS for SPHINCS+, the hash-based scheme NIST has already standardized.
The Catch: State Matters
SHRINCS’ compact signing path is stateful. That means a signing device has to track which one-time keys it has already used, and signatures grow roughly 16 bytes larger with repeated use. Restore a seed onto a new device without carrying over that state, and the wallet has to fall back to a much larger, roughly 5,777-byte stateless signature. Reuse a key’s state by accident — say, by restoring an old backup incorrectly — and funds tied to that key could be compromised. Jonas Nick has been candid about the limitation, writing that SHRINCS “is not intended to be Bitcoin’s ‘final’ signature scheme” and acknowledging it is “not optimal along every axis.” Blockstream Research has floated a companion design, nicknamed SHRIMPS, meant to extend similar compact signatures across multiple devices sharing one seed.
Adam Back’s Long Game on Quantum Timing
Back has repeatedly argued in public that cryptographically relevant quantum computers are likely decades away, if they arrive at all in a form that threatens Bitcoin. His position on proposals like SHRINCS has never hinged on winning that argument, however. As he has put it in past commentary on the topic, the community does not need to agree on a timeline to justify giving users the option to migrate their keys to a quantum-ready format ahead of time. That framing — preparation as insurance rather than as a response to an imminent threat — is likely to define how SHRINCS and any competing proposals move through Bitcoin’s notoriously slow, consensus-driven upgrade process.
No implementation timeline has been set, and a BIP publication is only the start of a review process that historically takes years before anything reaches mainnet, if it does at all.
Crypto assets, including Bitcoin, are volatile and carry risk of loss. Nothing here is financial advice — do your own research before making decisions involving digital assets.
New to how Bitcoin’s underlying protocol actually works? Coin680’s Bitcoin Academy breaks down concepts like signatures, seed phrases, and wallet security in plain language.
