Falcon-1024 Identified as Candidate for Bitcoin's Next Signature Scheme

By: www.tokenpost.kr|2026/08/30 11:46:26

The discussion surrounding Bitcoin (BTC) and its response to quantum computers is shifting from the selection of signature algorithms to issues concerning wallet and node infrastructure design. The key consideration is not just stronger mathematical structures, but the costs and deployment conditions that can be practically applied to the Bitcoin chain.

On the 26th, Blockstream, a Bitcoin infrastructure development company, compared Dilithium, Falcon, and Hawk as candidates for Bitcoin's next signature scheme in a research paper. Blockstream viewed the combined size of the public key and signature as a core cost, as every full node must download and store that byte each time it is used.

According to the figures presented by Blockstream, the level 3 Dilithium has a public key size of 1952 bytes and a signature size of 3309 bytes, totaling 5261 bytes. Falcon-512 totals 1563 bytes, while Falcon-1024 totals 3073 bytes. Hawk had the advantage of a 555-byte signature but has currently been withdrawn from the standardization candidates.

These figures illustrate the burden compared to the existing Bitcoin signature structure. The Schnorr signature currently in use has a public key size of 32 bytes and a signature size of 64 bytes, totaling 96 bytes. Introducing a new signature scheme into Bitcoin would affect not only wallet updates but also node validation, block capacity, and fee structures.

Dilithium was evaluated as a candidate with simple implementation. It uses integer operations and does not require floating-point or discrete Gaussian sampling, resulting in relatively low constant-time implementation burdens. However, its high on-chain costs at level 3 are seen as a weakness.

Dilithium also has the advantage of being the candidate closest to BIP-32 style key derivation. However, Blockstream noted that the published variants are not yet at a deployable level. Issues remain, such as differences from standard validators, lack of complete non-malleability proofs, and the security of all keys being tied to a single common matrix.

Falcon has been classified as a leading candidate in terms of size and verification speed. The National Institute of Standards and Technology (NIST) has chosen Falcon as a candidate for FN-DSA standardization and is developing it under FIPS 206. Blockstream assessed Falcon as the smallest and fastest to verify among the three candidates.

However, Falcon also has significant deployment burdens. Blockstream explained that Falcon-1024 requires a sampler that uses about 90kB of RAM. Using deterministic integer emulation slows down signature speed by about 15 times and key generation by about 2 times.

Hawk has remained a cautionary example in recent comparisons. Anthropic announced on July 28 that it had discovered structural weaknesses in the Hawk design. NIST later stated that the Hawk development team withdrew the algorithm from standardization review, explaining that this discovery does not affect established standards like ML-DSA.

Post-quantum cryptography starts from the premise that sufficiently large quantum computers can attack existing public key cryptography. Bitcoin's transaction approvals involve signatures, and the blockchain structure requires all nodes to validate and store this data. The size of signatures and verification costs act as more direct constraints compared to general information technology systems.

NIST confirmed ML-DSA, SLH-DSA, and ML-KEM as post-quantum cryptography standards on August 13, 2024. The transition to post-quantum cryptography has been treated as a long-term security issue for both Bitcoin and Ethereum. However, the mere establishment of standards does not dictate how they will be applied to Bitcoin.

Discussions continue on the Bitcoin developer mailing list. On the 26th and 27th, drafts for "Post-Quantum Path of BIP 324" and "Hash-Based Signature SHRINCS for Bitcoin" were posted. In the BIP-360 update thread for February 2025, Falcon was considered a top candidate, but issues such as BIP-32 compatibility, watch-only xpub, and multi-signature processing were highlighted.

The market structure involves a wide range of stakeholders. Full nodes must store larger signature data long-term, while hardware wallet manufacturers must generate signatures within limited RAM and computational performance. Exchanges and custodial businesses may need to change their multi-signature and key management procedures.

For domestic investors, this discussion holds significance beyond a simple technical paper. The methods of storing Bitcoin, transaction fees, and wallet compatibility are direct issues for long-term holders and custodial service users. However, this discussion is not about price forecasts or short-term market materials, but rather a review of protocol security design.

Blockstream stated that if it had to choose one based solely on lattice-based signatures, it would select Falcon-1024. However, the short-term fallback remains hash-based signatures. The discussion on Bitcoin's quantum resistance has entered a stage where deployment conditions such as chain costs, hardware wallet RAM, key derivation, and multi-signature are prioritized over candidate names.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com