Paper 2025/2203

Hash-based Signature Schemes for Bitcoin

Mikhail Kudinov, Blockstream Research
Jonas Nick, Blockstream Research
Abstract

Hash-based signature schemes offer a promising post-quantum alternative for Bitcoin, as their security relies solely on hash function assumptions similar to those already underpinning Bitcoin's design. We provide a comprehensive overview of these schemes, from basic primitives to SPHINCS+ and its variants, and investigate parameter selection tailored to Bitcoin's specific requirements. By applying recent optimizations such as SPHINCS+C, TL-WOTS-TW, and PORS+FP, and by reducing the allowed number of signatures per public key, we achieve significant size improvements over the standardized SPHINCS+ (SLH-DSA).We provide public scripts for reproducibility and discuss limitations regarding key derivation, multi-signatures, and threshold signatures.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Post-QuantumHash-basedSignaturesBitcoin
Contact author(s)
mishel kudinov @ gmail com
jonas @ n-ck net
History
2025-12-08: approved
2025-12-05: received
See all versions
Short URL
https://ia.cr/2025/2203
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2203,
      author = {Mikhail Kudinov and Jonas Nick},
      title = {Hash-based Signature Schemes for Bitcoin},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2203},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2203}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.