The scheme uses hash-based signatures and includes a stateless fallback
A BIP proposal has been published for SHRINCS, a post-quantum signature scheme designed for Bitcoin. Blockstream tested the scheme in production on the Liquid sidechain in March 2026.
SHRINCS uses hash-based signatures, with a minimum size of 548 bytes plus a 48-byte public key. The signature can reach 4,619 bytes, compared with 64 bytes for Schnorr signatures. According to estimates from Blockstream’s previous research, SHRINCS could allow around three transactions per second.
The scheme uses one-time keys and stores the state of keys already used on the device. Signatures grow by 16 bytes with each use; if the device is lost, recovery requires a stateless fallback transaction of around 5,777 bytes. The proposal warns that the security proof is still incomplete and notes possible incompatibilities between implementations, with a risk of fund loss during key import.
Blockstream also demonstrated SHRINCS and other post-quantum schemes running on hardware wallets. The proposal also cites SHRIMPS, a complementary scheme intended to allow backup devices initialized from the same seed to sign transactions; it is unclear whether it will be included in the BIP.





