Register and share your invite link to earn from video plays and referrals.

Blockstream Research
@blksresearch
24 Following    3.8K Followers
Lattice-based Signature Schemes for Bitcoin A self-contained review of three lattice-based signature schemes, with Bitcoin's post-quantum transition as the motivating application. Read the full paper at
Show more
NOW LIVE 🎥: Formal Functional Correctness of libsecp256k1's Modular Inverse Featuring: Russell O’Connor
Standardized parameter sets for hash-based signatures weren’t chosen for Bitcoin. For a SHRINCS proposal, we can trade some of SLH-DSA's enormous signature budget for smaller signatures and cheaper verification. We searched 25,935 parameter sets and found a 5.7 kB candidate, 26% smaller. That trade-off reduces the signature budget from 2^64 to 2^40. In return, signing is 23% cheaper and verification 28% cheaper. Try the parameter explorer: Read the post:
Show more
An aggregate signature lets multiple signers each sign a different message, then combine everything into one compact signature that proves who signed what. @real_or_random explains the primitive behind Cross-Input Signature Aggregation. Full talk at Eurocrypt below. ⬇️
Show more
Aaand, it got solved! The challenge was to find a hidden mnemonic in the Taproot leaves of the 12 provided UTXOs. Will definitely create another CTF in the future, but much more difficult this time. So stay tuned. Congratulations to the solver!
Show more
Stateful signatures trade systemic risk for localized risk. The failure mode is confined to individual wallets, not the network. @n1ckler at @TheBitcoinConf 2026 on why that's the better trade-off to explore.
Show more
After 7 years, Blockstream Research Director @n1ckler is stepping back as a libsecp256k1 maintainer, leaving the library in the strong hands of its other long-time maintainers. @blksresearch remains a key contributor. Learn more about this cryptographic library that secures every Bitcoin and @Liquid_BTC transaction. ⬇️
Show more
Systemic risk vs localized risk. That's the core argument for exploring stateful hash-based signatures in Bitcoin. @blksresearch Director @n1ckler on why standardized post-quantum schemes create risks for everyone, and why SHRINCS moves that risk to where it can be managed.
Show more
I'm hyped to announce that I am Brink's first-ever grantee to focus on Bitcoin's post-quantum crypto R&D 🎉🤓 This funding will help me focus full-time as I collaborate with @blksresearch to draft a balanced, efficient, and secure PQ signature upgrade.
Show more
At @OPNEXT2026, our Director @n1ckler explained how a soft fork could add post-quantum security to Bitcoin's Taproot tree. Outputs commit to both Schnorr and PQ keys. Schnorr signatures stay cheap. The PQ path sits dormant until a cryptographically relevant quantum computer emerges.
Show more
The results are in from the Blockstream Turin Simplicity Hackathon. 20 developers spent a weekend building real smart contracts on Simplicity covenant DEXs, inheritance tools, post-quantum wallets, and more. First place goes to: PQ Liquid Wallet, taking home $3,000 in bitcoin: PQ Liquid Wallet is the first wallet to test Blockstream's research on protecting Bitcoin from future quantum computers.
Show more
How can we build Schnorr-like signatures from lattice assumptions? In Ep. 1 of the Blockstream Research Seminar, @ZamDmytro explains lattice-based signatures and their role in the search for practical post-quantum cryptography for Bitcoin. Watch here:
Show more
Hash-based signatures are the most conservative post-quantum option for Bitcoin. Lattice-based cryptography could be what comes next, potentially opening the door to post-quantum multisignatures, zero-knowledge proofs, and confidential assets. Read the latest from @blksresearch. 🔗 ⬇️
Show more
Optimized stateful hash-based signatures can offer better trade-offs than the standard schemes available today. SHRINCS is live on @Liquid_BTC in production today via Simplicity. @n1ckler at @OPNEXT2026 on why this may allow Bitcoin to operate in a post-quantum world without betting on specific future software.
Show more
There is no concrete post-quantum signature scheme for Bitcoin today. But over the last year @blksresearch has been working on exactly this. Director Jonas Nick (@n1ckler) lays out the proposal: OP_CHECKSHRINCS, a hash-based signature opcode for post-quantum Bitcoin.
Show more
SHRINCS reaches up to 3 TPS on the compact path. 580-byte signatures from a dedicated signing device. A stateless fallback always available. Already demonstrated on @Liquid_BTC. The C++ implementation, Simplicity verifier, & draft spec are all on GitHub.
Show more
Our Director @n1ckler on SHRINCS and SHRIMPS at @OPNEXT2026: SHRINCS converts systemic quantum network risk into localized device risk. Localized risk can be managed. SHRIMPS adds a second compact path for backup devices: ~3,000 bytes vs 580 bytes primary, 0.87 TPS vs 0.36 TPS baseline.
Show more
BITCOIN RAILS #59#: Post-Quantum Bitcoin Signatures (+ their tradeoffs) | with BIP 360 co-author @Ethan_Heilman and @Blockstream Head of Research @n1ckler 🔗 YOUTUBE: 🌿 SPOTIFY: According to BIP 360 co-author Ethan Heilman, Bitcoin needs a minimum of two soft forks to become quantum resistant: P2MR (or an output type that can safely execute PQ signatures) + a post-quantum checksig (signature scheme). Ethan and the BIP 360 team (including myself and @cryptoquick) introduced the P2MR part via a BIP 360 update late last year—but the question remains, what’s the most appropriate PQ signature scheme for Bitcoin? They all have substantive tradeoffs, but hash-based signatures seem to be leading technical discourse—likely due to recent optimizations by @n1ckler and the broader @Blockstream research team. It was an honor to sit down with both of these men - arguably the two most influential and productive cryptographers in Bitcoin quantum mitigation right now - for an in-depth review of the leading PQ signature schemes and a temperature check on Bitcoin’s post-quantum planning process. TBH, if you want to skip the noise and jump straight to the signal on quantum, this is the interview to watch. In this episode, we discuss: - What needs to happen at the soft fork, infra, and mitigation levels to fully quantum-harden Bitcoin - Recent updates to BIP 360 + breakdown of the leading hash-based signatures schemes for Bitcoin (SHRINCS + SHRIMPS) - Why we may actually get consensus around a stateful scheme for Bitcoin - Comparisons of hash-based signatures vs Lattice and Isogeny-based schemes - Assessing the risks of both waiting too long and acting too fast (and why quantum is a better threat to be facing than a potential classical attack) This episode of Bitcoin Rails is brought to you by my NEW sponsors: - LayerTwo Labs @LayerTwoLabs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) - Hashi on @SuiNetwork — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity - BitBox @BitBoxSwiss — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 Intro 02:18 Ethan’s Quantum Wakeup 05:18 How Blockstream Enters Post Quantum 09:25 BIP 360 Explained 12:11 How Bitcoin Transitions to PQ 17:35 Choosing Post Quantum Signatures 23:20 How Blockstream Created SHRINCS 27:22 Signature Budgets Importance Explained 41:13 What are SHRIMPS? 44:51 SHRIMPS vs SHRINCS 47:48 Why SLH-DSA Alone Won’t Cut It 49:24 Is a SHRIMPS + SHRINCS BIP Coming? 51:51 Blockstream’s Big Plans for Liquid 59:04 Quantum Readiness Roadmap 01:02:22 Importance of a PQ Recovery Plan 01:05:35 How Long Would a PQ Migration Take 01:11:17 Quantum Watchlist Recommendations
Show more