Points of Focus
- Blockstream Research names Falcon-1024 its pick among post-quantum signatures.
- Rival candidate Hawk was withdrawn after a structural weakness was found.
- Every candidate is dramatically larger than Bitcoin’s current signature scheme.
Blockstream Research published a full evaluation of three lattice-based signature schemes that could eventually replace Bitcoin’s Schnorr and Elliptic Curve Digital Signature Algorithm (ECDSA) signatures, both of which a sufficiently powerful quantum computer would break.
If Bitcoin had to choose a lattice signature today, it would be Falcon-1024.@blksresearch has published a full report on Dilithium, Falcon and Hawk: what each costs on-chain, how hard each is to implement safely, and which assumptions you are trusting.https://t.co/7hlkC0gPZt
— Blockstream (@Blockstream) August 26, 2026
One of the three candidates didn’t survive the report’s timeline.
Blockstream’s Bitcoin quantum signature pick is Falcon-1024
Blockstream’s conclusion, if Bitcoin needed to select a lattice-based scheme today, is Falcon-1024, selected by the US National Institute of Standards and Technology (NIST) for eventual standardization.
At its highest security level, Falcon-1024 needs 3,073 bytes combined for a public key and signature, versus 96 bytes for Bitcoin’s current setup, a roughly 32-fold increase every full node would store and verify for each transaction. Even so, it’s the smallest of the three candidates studied, and its verification step, the one performed by every node on every transaction, is integer-only and the fastest of the three.

Falcon’s real complication sits in signing rather than verifying: Its default signer relies on floating-point math that produces different results across processors and compilers, a genuine security risk under its design proof.
A deterministic version fixes this using integer emulation, at the cost of signing roughly 15 times slower, a tradeoff Blockstream calls manageable since signing happens once per transaction, while verification happens constantly across the entire network.
Why Blockstream still recommends hash-based signatures for now
Despite naming Falcon-1024 its pick among the lattice candidates, Blockstream’s near-term recommendation for Bitcoin remains a hash-based signature scheme instead, the more conservative option relying on the most established assumptions.
Falcon’s NIST standard hasn’t been finalized, and until it is, audited implementations and hardware support don’t exist yet, making it what the report calls a moving target rather than something ready to deploy.
A rival Bitcoin signature scheme collapses under scrutiny
The third candidate, Hawk, promised the smallest signatures of the group at 555 bytes and had been the only lattice-based scheme remaining in the third round of a NIST signature competition.
Shortly before Blockstream finished its report, researchers at Anthropic found a structural weakness in Hawk’s underlying lattice construction, showing its key-recovery security actually relied on solving a hard lattice problem in roughly half the dimension its designers had assumed.
The finding cut 10 bits from Hawk’s estimated security and produced a working key-recovery attack against its smallest published parameter set. Hawk’s team confirmed the attack and withdrew the scheme from the NIST’s process, noting that fixing it would erase the compact size that made it attractive in the first place.
What’s still unsolved for Bitcoin’s quantum-safe future
None of the three schemes natively support Bitcoin’s hierarchical deterministic wallet standard, known as BIP-32, the mechanism nearly every Bitcoin (BTC) wallet uses to generate unlimited addresses from a single master key without exposing the private key.
Dilithium has the most developed approach, but Blockstream describes even that as a proof of concept rather than something ready to ship. Falcon currently has no workable version at all, something the report flags as one of the most important open problems it identifies.
Blockstream frames this as likely a transitional period for Bitcoin: hash-based signatures now, with Falcon potentially improving on that approach substantially once its NIST standard is finalized and hardware support catches up. Whether that transition takes years or decades depends on a timeline nobody, including Blockstream, claims to know.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


