Blockstream Publishes SHRINCS Proposal for Bitcoin Quantum Security
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Blockstream introduced SHRINCS to prepare Bitcoin for possible future quantum attacks.
- SHRINCS uses smaller signatures than many alternatives, but it adds new wallet and recovery risks.
- New tests are giving developers more options to improve Bitcoin quantum security.
Blockstream has published a Bitcoin Improvement Proposal that introduces SHRINCS, a signature system designed to protect Bitcoin from future quantum attacks. Bitcoin uses digital signatures to confirm that owners can spend their coins. However, future quantum computers could weaken the technology behind those signatures. A powerful quantum computer could calculate a private key from a public key that appears on Bitcoin. An attacker could then use that private key to access the linked funds.
Blockstream publishes Bitcoin Improvement Proposal for SHRINCS, a quantum-resistant signature scheme tested on Liquid sidechain.
— MSB Intel (@MSBIntel) August 27, 2026
Blockstream developed SHRINCS to prepare for this possible threat before quantum computers become powerful enough. Researchers Jonas Nick and Mikhail Kudinov introduced the system in December last year. Blockstream tested SHRINCS on Liquid, its Bitcoin-based sidechain, through real transactions in March. Researchers also placed a copy of the Bitcoin white paper inside the production test. The new BIP now gives Bitcoin developers a detailed proposal they can study and discuss.
Today, we're publishing BIP SHRINCS, the first concrete proposal for a post-quantum signature scheme designed specifically for Bitcoin.
The BIP draft turns what began as a rough idea into exact algorithms with an executable reference implementation.
This is an important… pic.twitter.com/7xGri2ggtP— Jonas Nick (@n1ckler) August 26, 2026
Blockstream does not present SHRINCS as Bitcoin’s final post-quantum solution. Researchers have not completed a formal proof showing that SHRINCS provides the security its design promises. The system has also received less public security testing than post-quantum signatures approved by the US National Institute of Standards and Technology.
SHRINCS Brings Smaller Signatures and New Risks
Post-quantum signatures create a problem for Bitcoin because they usually need much more transaction data than today’s signatures. Bitcoin’s Schnorr signatures use 64 bytes, while SHRINCS signatures start at 548 bytes. SHRINCS also uses a 48-byte public key. Therefore, its smallest signature remains about nine times larger than a Schnorr signature. SHRINCS signatures can also grow to 4,619 bytes.
However, several NIST-approved post-quantum signatures are much larger than SHRINCS. Such signatures can be 38 to 123 times larger than Bitcoin’s current ECDSA and Schnorr signatures. Blockstream designed SHRINCS to reduce that size while keeping its security tied to hash functions.
Larger signatures matter because Bitcoin blocks have limited room for transaction data. Blockstream estimates SHRINCS could allow Bitcoin to process about three transactions per second. Some larger post-quantum alternatives could reduce that rate below one transaction per second. However, a signature nine times larger would not require Bitcoin blocks to become nine times larger.
SHRINCS keeps its signatures smaller by asking wallets to remember which one-time signing keys they have already used. Wallets need this record because users should not reuse those keys. Each additional use also increases a SHRINCS signature by about 16 bytes. If a user loses the stored record, SHRINCS provides a larger fallback transaction of about 5,777 bytes. This fallback allows the user to recover the funds without the missing signing history.
New Tests Expand Bitcoin Quantum Security
Blockstream has been testing SHRINCS and other post-quantum systems on standard hardware wallets. The tests checked whether small hardware wallets could handle the extra work required by larger post-quantum signatures. Blockstream has also worked on ways to improve wallet backups.
A popular concern says post-quantum signatures cannot run on the hardware wallets people already own.@blksresearch implemented hash-based schemes on four popular devices. All four signed. SLH-DSA, the NIST standard, in about two minutes at worst.https://t.co/1DK02LFH0m
— Blockstream (@Blockstream) August 19, 2026
One project called SHRIMPS helps backup devices created from the same seed sign transactions safely. Blockstream is also studying ways to reduce the block space that post-quantum signatures use. One option would combine several signatures into one smaller proof using zero-knowledge technology. Blockstream estimates this approach could raise Bitcoin’s modeled capacity from three to about 6.7 transactions per second.
In a related development concerning Bitcoin security, researcher Avihu Levy completed a Quantum-safe Bitcoin transaction on Aug. 26, according to StarkWare. His method required no new Bitcoin opcode, soft fork, or software change from network nodes.
StarkWare Researcher Executes First Quantum-Safe Bitcoin Transaction on Mainnet
StarkWare researcher Avihu Levy’s Quantum-Safe Bitcoin (QSB) scheme has completed its first confirmed transaction on the Bitcoin mainnet, demonstrating a way to protect transactions from… pic.twitter.com/ZiCoQdMuhD
— Wu Blockchain (@WuBlockchain) August 27, 2026
Quantum-safe Bitcoin uses hash-based protection instead of relying only on Bitcoin’s current signature system. Unlike SHRINCS, Levy’s method worked under Bitcoin’s existing rules for the tested output.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







