Hashes, Lattices, and the Shape of Bitcoin’s Quantum Defense
BTC Before Light: Issue 47 ☀️
Good morning,
Today, I’m discussing the latest debate over Bitcoin’s post-quantum signature options, specifically hash-based signatures vs. lattice-based signatures.
Hash-based signatures are among the leading options, but evidence is mounting in favor of lattice-based signatures as a long-term, or even complementary, option because they better preserve advanced Bitcoin wallet functionality, such as multisignatures, threshold signatures, hierarchical deterministic wallets, and other complex constructions.
The discussion is quite technical and dense, and it doesn't offer immediate takeaways regarding Bitcoin's value or narrative. So, for those wanting just a quick, high-level update on Bitcoin development, I am highlighting up front that there’s nothing urgent to report this week. Bitcoin developers are plugging away, continuing work on the next major Core release, quantum, and other protocol priorities.
But if you're interested and have the time this morning to delve into the technical weeds of the debate on post-quantum secure signature schemes, read on!
Let’s get into it.
Yours truly,
Christine D. Kim
☁️ To get early access to this week’s BTC Before Light newsletter, make sure you are signed up for a premium subscription:
⛅ Interested in being a featured sponsor of this newsletter? Learn more about sponsorship opportunities available for BTC Before Light:
☀️ I also run a research and advisory firm called Protocol Watch for businesses building on Bitcoin and Ethereum. Learn more about how I can help your business understand and stay ahead of protocol changes:
The starter 🍳
The main 🥞
In May, the Blockstream research team published a blog post discussing the four broad types of post-quantum signature schemes: hash-based, lattice-based, code-based, and isogeny-based cryptography.
Hash-based signatures rely on hash functions, which turn data into fixed-length outputs that are easy to verify but hard to reverse.
Lattice-based signatures rely on hard mathematical problems involving lattices, or infinite grids of points. Patterns or connections on the grid are difficult to decipher without knowledge of the secret information about these pathways.
Code-based signatures are built from error-correcting codes, the same broad field of math used to recover corrupted data.
Isogeny-based signatures rely on special relationships, called isogenies, between elliptic curves. Their security comes from the difficulty of finding the hidden path between two related elliptic curves without secret information.
Each of these four categories represents a distinct mathematical approach to constructing digital signatures that are believed to be quantum-secure.
Of these, hash-based signatures are among the most widely discussed options for Bitcoin.
Pseudonymous Bitcoin developer “conduition” expanded on the main reasons why Bitcoin developers are looking into hash-based signatures in a response on the Bitcoin Developers Mailing List.
Conduition wrote:
Hash based signatures are incredibly conservative. They rely on strictly weaker assumptions than what we already depend on for other things. No other family of signatures can claim this property, and for something as inflexible-yet-sensitive as Bitcoin, conservativism is appealing.
However, the Blockstream post from May was written to encourage developers to take lattice-based solutions more seriously because of their “algebraic flexibility,” which could support more advanced Bitcoin wallet functionality, such as multisignatures, threshold signing, and other constructions.
As the post explains:
This means lattices potentially open the door for advanced modifications like post-quantum multisignatures, zero-knowledge proofs, and confidential assets.
The main pushback
The main pushback against lattice-based signatures, compared with hash-based ones, is that the former are generally considered riskier to implement on Bitcoin.
Bitcoin already relies heavily on hash functions across the protocol, including in mining, transaction IDs, Merkle trees, and address construction. Thus, a hash-based signature scheme would rely on cryptographic assumptions that Bitcoin already uses today, whereas lattice-based schemes would introduce new assumptions and more experimental constructions into the protocol.
In an email thread discussing lattice vs hash-based schemes, Conduition wrote:
Lattice threshold and key-rerandomization schemes will likely improve from where they are now, but until proven otherwise we should make choices about consensus based on what we have, not what we hope we will have someday.
That said, Conduition added that hash-based schemes do not preclude research and development of other schemes for consideration as a long-term replacement for or in addition to hash-based schemes.
Keeping options open
Given the promising potential of non-hash-based signature schemes, developers are actively discussing ways to address their safety concerns.
One option under discussion is to implement lattice-based signatures in a hybrid manner that couples them with existing Bitcoin signature schemes, such as Schnorr signatures (i.e, BIP-340). The idea is that the lattice-based signature would provide post-quantum security, while the Schnorr component could provide additional protection against cryptographic weaknesses or implementation bugs in the newer lattice-based scheme.
In a Delving Bitcoin post discussing hybrid post-quantum signature schemes, Bitcoin Core developer Pieter Wuille, also known as “sipa”, wrote:
Longer term, if schemes based on other more novel assumptions were added (like lattices or isogenies) I think it would be entirely reasonable to consider them only in a hybrid form,
Speaking to the potential for a hybrid lattice-based signature scheme, Kvanta5, a post-quantum blockchain development team, noted that for their protocol, which relies exclusively on ML-DSA-87, a lattice-based signature scheme, the additional Schnorr-related overhead in a hybrid signature construction is likely to be marginal compared with the already large post-quantum signature data.
In response to the Delving post on hybrid signature schemes, they wrote:
This is consistent with sipa’s observation that the [post quantum] blob is “the dominant element” — the Schnorr R (32 bytes) is essentially rounding error at this scale. Whether that argues for or against hybridization probably depends on your threat model, but in terms of block space budgeting, the [post quantum] signature is the entire conversation.
Bottom line
Despite their experimental nature and the open questions about how to safely integrate them into Bitcoin, the body of relevant research and literature on lattice-based signature schemes is growing quickly.
While hash-based signatures remain the most conservative option, lattice-based schemes are emerging as strong long-term candidates for preserving advanced Bitcoin wallet functionality in a post‑quantum era.
Temp check 🗳️
Further reading 🛋️
Bitcoin Core v32 release schedule (GitHub)
Binaries for Bitcoin Core version v30.3rc1 are now available for testing and review (Bitcoin Developers Mailing List)
Binaries for Bitcoin Core version v29.4rc1 are now available for testing and review (Bitcoin Developers Mailing List)
Transcript of last Thursday’s, July 2, Bitcoin Core Developers meeting (Chaincode)
Summary of Bitcoin Core development activity from the past week (This Week in Bitcoin)
Call for feedback on btc-verified, an experimental research project that seeks to formally model and verify properties of Bitcoin’s protocol using the Lean4 programming language and proof assistant. (Bitcoin Developers Mailing List)
An LLM-generated testing report on the latest Erlay implementation. Erlay is a proposed bandwidth-saving protocol for relaying Bitcoin transactions. (GitHub, Bitcoin/bitcoin)
🙏 Thank you for reading. If you liked today’s issue, consider sharing it with a friend who might also enjoy the content.
💥If today’s post sparked any thoughts, opinions, or questions, I’d love to hear them. Please share your feedback on today’s newsletter by leaving a comment.
🌟 Finally, if you’re a premium subscriber, don’t forget to join the subscriber channel on Telegram. It’s an exclusive space to discuss the evolution of Bitcoin Core and Ethereum with fellow readers. The invite link to join is posted here:
Newsletter credits:
Special thanks to Shinhye Kim for the illustrations in this newsletter.




