Last week at
@OPNEXT2026 I presented a toy proposal for hash-based sigs in Bitcoin (incl. SHRINCS).
Open questions:
• What are acceptable sign/verify costs? Higher → smaller sigs
• How to design safe stateful setups?
• Optimizations beyond SHRINCS?
• L2s and stateful sigs?