Bitcoin and quantum computers: what Blockstream proposes, and what QuietProof is
There is no post-quantum signature in Bitcoin yet. Blockstream's research team has the most concrete design so far. A plain-language guide before the Lugano talks.
Your bitcoin is protected by a digital signature: only the holder of the private key can sign a valid transaction. Powerful quantum computers could, in theory, break the kind of signatures Bitcoin uses today. In May 2026 Blockstream's director of research Jonas Nick wrote that "there is no concrete proposal for a post-quantum signature scheme in Bitcoin today." His team is working on one, and he presents it in Lugano.
The idea: signatures built from hashes
Bitcoin already trusts one kind of cryptography very deeply: hash functions such as SHA-256, which secure mining and addresses. Signatures can be built from hash functions alone. Researchers consider this a conservative choice, because it adds no new mathematical assumptions.
The catch is size. Today's Schnorr signature is 64 bytes. The NIST-standard hash-based scheme, SLH-DSA, produces signatures of about 7.8 KB. Blockstream estimates that with signatures that big, Bitcoin could process only about 0.36 transactions per second.
SHRINCS and SHRIMPS
Blockstream Research proposes two designs that shrink these signatures:
- SHRINCS gives one key two ways to sign. The everyday path makes signatures from 324 bytes, growing by about 16 bytes with each further signature. If the device loses its saved state, a backup path still works, with signatures of about 5.7 KB, roughly 25% smaller than SLH-DSA.
- SHRIMPS (March 2026) lets one seed backup be loaded into several signing devices, each making signatures of about 2.5 KB.
A draft BIP for SHRINCS lists six authors, including Jonas Nick. Blockstream also sketched a new script command, OP_CHECKSHRINCS, for using it in Bitcoin.
| Signature | Size |
|---|---|
| Schnorr (today) | 64 bytes |
| SHRINCS, everyday path | from 324 bytes |
| SHRIMPS, extra devices | ~2.5 KB |
| SHRINCS, backup path | ~5.7 KB |
| SLH-DSA (NIST standard) | ~7.8 KB |
What would have to happen
Adding a new signature type to Bitcoin needs a soft fork: a rule change that wallets, nodes and miners adopt. Today there is a draft specification and research, not an activation plan. As the recent BIP-110 episode showed, a rule change without broad support fails.
We do not expect a soft-fork date to be announced in Lugano. Expect research results and trade-offs.
What is QuietProof?
The forum says Jaromil, scientific director of the Plan ₿ Foundation, will premiere QuietProof in Lugano: a zero-knowledge proof that lets you prove you own bitcoin without revealing your key. The same post mentions Bitcoin Roots, which aims to make running your own node at home easy.
No technical details of QuietProof are public yet. We will explain it after the premiere.
In Lugano
- 23 Oct, 15:30 Lugano / 16:30 MSK, UTXO Room: "BlindZap, Private Bitcoin Rights and Post-Quantum Proofs", Jaromil (masterclass, advanced level)
- 24 Oct, 15:30 / 16:30, P2P Stage: "Post-Quantum Signatures for Bitcoin", Jonas Nick (Blockstream)
- 24 Oct, 15:30 / 16:30, UTXO Room: "CISA: Aggregating Signatures For Bitcoin Transactions", Fabian Jahr (Brink). CISA would combine several signatures in a transaction into one.
Sources
- Blockstream: OP_CHECKSHRINCS, a hash-based signature opcode for post-quantum Bitcoin (Jonas Nick, 12 May 2026) blog.blockstream.com
- Blockstream: SHRIMPS, 2.5 KB post-quantum signatures across multiple devices (27 Mar 2026) blog.blockstream.com
- Blockstream: Searching for SHRINCS parameters blog.blockstream.com
- SHRINCS draft BIP github.com
- Kudinov & Nick: Hash-based Signature Schemes for Bitcoin (IACR ePrint 2025/2203) eprint.iacr.org
- @LuganoPlanB: Jaromil on QuietProof and Bitcoin Roots (6 Oct 2026) x.com
- Plan ₿ Forum agenda planb.lugano.ch
Times are Lugano (CEST, UTC+2) and Moscow (UTC+3). Not investment advice.
Read next
BIP-110 post-mortem: why a soft fork backed by 2.5% of miners stalled after two blocks
On 8 August 2026 nodes enforcing BIP-110 split from Bitcoin at block 961,632. Here is what happened, why the new chain froze, and what it means for you.
The Coldcard seed bug: what happened, who is at risk, and a 7-step checklist
A 2021 firmware mistake made some Coldcard seeds guessable. Since 30 July 2026 attackers have taken around 1,400–2,050 BTC. What went wrong and what to do now.