Falcon Emerges as Top Post-Quantum Signature Candidate for Bitcoin
Blockstream Research has assessed Dilithium, Falcon and Hawk as potential post-quantum signatures for Bitcoin, which may eventually need protection from quantum attacks against ECDSA and Schnorr signatures. The report recommends at least NIST security level 3 because Bitcoin outputs may remain unspent for decades.
Falcon-1024 is the report’s preferred lattice-based signature if Bitcoin had to choose a solution today. It offers a smaller on-chain footprint and faster verification than Dilithium, while its main implementation challenge—floating-point Gaussian sampling—can be addressed with deterministic integer-based methods. However, Falcon lacks a practical BIP-32-style public-key derivation scheme, and the FN-DSA standard has not yet been finalised. Falcon-1024 also requires substantial memory during signing, although hardware-wallet optimisations can reduce the requirement.
Dilithium, standardised by NIST as ML-DSA under FIPS 204, is easier to implement because it uses integer arithmetic and avoids floating-point operations. Its drawback is size: the level-3 version has a 1,952-byte public key and a 3,309-byte signature, totalling 5,261 bytes. Proposed key-derivation variants remain experimental.
Hawk was withdrawn from the NIST process after researchers including Anthropic’s Straznickas and Weis found a structural weakness that reduced its effective security. The report says hash-based signatures remain the most conservative near-term option, while a hybrid deployment with lattice-based signatures could become viable after standards, audits and hardware support mature.
Neutral
The immediate market impact is likely neutral. The report is a research assessment rather than a Bitcoin protocol upgrade, production deployment or confirmed quantum threat. It does not change Bitcoin’s current transaction rules, network capacity or near-term security assumptions, so traders are unlikely to reprice BTC solely because of the findings.
Short term, the news could create limited narrative volatility around Bitcoin’s long-term quantum risk. Hawk’s withdrawal may reinforce concerns about the maturity of post-quantum cryptography, while Falcon-1024’s comparatively strong assessment could support confidence in a future migration path. However, neither development directly affects current BTC supply, demand, liquidity or institutional flows.
Long term, the report is modestly constructive for Bitcoin’s security roadmap. It identifies Falcon as a potential compact and efficient option, while highlighting unresolved issues involving key derivation, standardisation, hardware-wallet memory and implementation safety. A successful post-quantum upgrade could reduce tail risk and strengthen investor confidence, but a rushed or vulnerable migration could increase operational and consensus risk. Similar cryptographic research announcements have historically had limited immediate price effects unless followed by a live exploit, urgent security patch or formal network upgrade. Traders should therefore monitor NIST’s FN-DSA standard, Bitcoin improvement proposals, wallet support and any evidence of quantum-capable attacks rather than treat this report as a direct bullish or bearish catalyst.