SHRINCS Targets Bitcoin’s Quantum Threat Without Crushing Throughput

Blockstream’s SHRINCS proposal targets Bitcoin’s quantum threat, preserving far more throughput than larger post-quantum signature schemes.

Quantum processor and secure Bitcoin-inspired circuitry illustrating post-quantum protection for the Bitcoin network

Blockstream published a Bitcoin Improvement Proposal for SHRINCS on Aug. 26, 2026, formalizing a post-quantum signature scheme that has already signed real transactions on the company’s Liquid sidechain. The BIP matters because it is the first concrete, Bitcoin-specific answer to a threat every serious cryptographer agrees is coming eventually: a sufficiently powerful quantum computer reverse-engineering private keys from exposed public keys.

What the SHRINCS BIP actually proposes

SHRINCS is a hash-based signature scheme unveiled in December 2025 by Blockstream Research’s Jonas Nick and Mikhail Kudinov, with an opcode proposal published in May and the full BIP dropping this week, according to the Cointelegraph report on the filing. The scheme’s minimum signature size is 548 bytes plus a 48-byte public key, scaling up to 4,619 bytes depending on use – small by post-quantum standards, but still roughly nine times larger than Bitcoin’s existing Schnorr signatures (64 bytes) or the older ECDSA signatures (70 bytes).

Context matters here: NIST-approved lattice- and hash-based post-quantum schemes run 38 to 123 times larger than what Bitcoin uses today, a size penalty that would crater throughput to a fraction of 1 transaction per second if deployed as-is. SHRINCS shrinks the NIST-approved hash-based baseline by roughly 13.23 times, which is the entire point of the exercise – keep Bitcoin’s block economics survivable while closing the quantum gap.

Detailed 3D render of a quantum computing dilution refrigerator with a close-up of a SPINQ quantum processor chip.
The SPINQ quantum processor hardware integrated within a cryogenic dilution refrigerator.

Nick called SHRINCS “the first concrete proposal for a post-quantum signature scheme designed specifically for Bitcoin,” while cautioning that “SHRINCS is not intended to be Bitcoin’s ‘final’ signature scheme, and it is not optimal along every axis.” His verdict: “I do think it is a very good trade-off among the options we have now.”

The throughput math investors should care about

Blockstream’s own estimates, using slightly different parameters in earlier research, put current Bitcoin throughput at 6.5 TPS if every wallet used Taproot’s Schnorr signatures – though roughly 80% of users don’t. Switching to the NIST-approved lattice scheme ML-DSA would drop that to 0.5 TPS; the NIST-approved hash-based SPHINCS+ would drag it down to 0.36 TPS. SHRINCS lands at roughly 3 TPS, close to where the network already sits today.

Marin Ivezic, founder of Applied Quantum and author of PostQuantum.com, explained why the size penalty doesn’t translate one-for-one into block bloat: “Under SegWit, signature bytes fit in the witness and take a quarter as much as other transaction data.” He called SHRINCS “the most Bitcoin-native post-quantum signature design anyone has produced,” pointing to full BIP-39 seed recovery and security resting on the same SHA-256 assumptions Bitcoin mining already depends on.

Ivezic was direct about the upside: “It is real code that has signed real transactions on Liquid mainnet, and I rate it the strongest answer yet to going post-quantum without wrecking Bitcoin’s block economics.” Blockstream also floated pairing SHRINCS with zero-knowledge proof aggregation, which it estimates could push throughput to 6.7 TPS – but that’s a separate, more radical proposal the company has deliberately kept off the SHRINCS ballot to avoid sinking both at once.

The catch: statefulness and failure modes

The BIP itself flags that “a security proof is TODO” – SHRINCS hasn’t been audited and hasn’t weathered the years of public cryptanalysis NIST’s signatures have. That alone should temper any assumption this ships as-is.

The bigger structural trade-off is statefulness. SPHINCS+ stays stateless by wrapping one-time keys in a multi-layer hash tree, which is a major reason it’s so large. SHRINCS drops that structure to save space and instead stores used keys on the device itself, checking for key reuse locally – but signatures grow 16 bytes with every use, and losing the device forces a stateless fallback transaction around 5,777 bytes to recover funds.

Yoon Auh, founder of BOLTS Technologies, put the risk plainly: SHRINCS’ designers added “statefulness, compact signing paths, fallbacks, assumptions about how many times a seed is initialized, and rules for when devices must switch to larger stateless signatures.” He warned that “that may be pragmatic engineering, but it is also complexity and fragility introduced largely to maximize throughput and minimize computation cycles. In Bitcoin, every new consensus rule becomes a permanent maintenance obligation, and every wallet-side assumption becomes a possible user failure mode.”

The BIP also carries a specific operational warning: keys generated with hypertree pruning for the stateless fallback component are not compatible with implementations that skip pruning, and importing a key across incompatible setups could result in lost funds. That’s the kind of edge case that historically shows up in exchange and custodian incident reports rather than press releases – a dynamic similar to the operational risks flagged around other recent Bitcoin protocol changes affecting exchanges and custodians.

Governance, not cryptography, is the bottleneck

Blockstream tested SHRINCS in production on the Liquid sidechain in March, including a transaction embedding a copy of the Bitcoin white paper, and demonstrated last week that it can run on common hardware wallets. Separately, the company has been researching lattice-based signatures – generally smaller but less battle-tested – and continues evaluating whether the companion SHRIMPS scheme, meant to let backup devices initialized from the same seed sign transactions, gets folded into the final proposal. It’s not yet clear from the draft BIP whether that happens.

Ivezic framed the real obstacle as political, not technical: “The binding constraint in Bitcoin’s quantum migration isn’t cryptography, it’s governance. Between BIP-360, BIP-361, SHRINCS and STARKs, the engineering menu is filling up fast. What Bitcoin lacks is a mechanism for choosing from it before the clock runs out.” Any consensus change of this magnitude faces the same coordination hurdles that have historically defined how Bitcoin miners and node operators negotiate contentious protocol upgrades, where activation thresholds and timing disputes can matter as much as the underlying code.

Notably, Blockstream CEO Adam Back – who has publicly argued quantum computers remain too immature for the threat to materialize for decades – still backs the preparation work, telling Cointelegraph earlier this year that “the safe thing” is to get ahead of the risk regardless of timeline uncertainty. That tension between skepticism on urgency and aggressive R&D spending is itself a signal worth watching: the people closest to Bitcoin’s cryptography are hedging even while publicly downplaying the near-term odds.

Adam Back, Co-founder and CEO of Blockstream, during a CNBC interview at Consensus Hong Kong
Adam Back, Co-founder and CEO of Blockstream, speaking at Consensus Hong Kong.

What comes next

For now, SHRINCS remains a proposal, not an activated consensus rule – no security proof, no audit trail, and no resolution on whether SHRIMPS or ZK aggregation get bundled in. Investors tracking Bitcoin’s long-tail security roadmap should watch for audit results, hardware-wallet integration progress, and whether the broader BIP ecosystem (360, 361, SHRINCS, STARKs) starts converging rather than fragmenting further.

Follow CoinNews on X and Telegram for ongoing coverage of Bitcoin’s quantum-security roadmap and other market-moving protocol developments.

About Author

Ifeanyi Egede

About Author

Ifeanyi Egede

Ifeanyi Egede

Ifeanyi Egede is a seasoned crypto journalist with six years of experience covering the dynamic world of cryptocurrencies and blockchain technology. Specializing in coin news, market analysis, crypto reviews, and comprehensive guides, Ifeanyi delivers insightful and accurate content that empowers readers to navigate the complexities of the crypto space. With a keen eye for market trends and a deep understanding of blockchain innovations, his work combines technical expertise with clear, engaging storytelling. Ifeanyi's contributions have been featured in leading crypto publications, establishing him as a trusted voice in the industry.
ABOUT COINNEWS
100k+
Active Monthly Users Around the World
50+
Guides and Reviews Articles
3
Years on the Market
8+
In-house Authors
At Coinnews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2022, Coinnews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.