Bitcoin Development Mailinglist
 help / color / mirror / Atom feed
* [bitcoindev] Falcon Post-Quantum Signature Scheme Proposal
@ 2026-01-22  7:01 Giulio Golinelli
  2026-01-22 12:48 ` [bitcoindev] " waxwing/ AdamISZ
  2026-01-22 14:35 ` [bitcoindev] " 'conduition' via Bitcoin Development Mailing List
  0 siblings, 2 replies; 13+ messages in thread
From: Giulio Golinelli @ 2026-01-22  7:01 UTC (permalink / raw)
  To: Bitcoin Development Mailing List


[-- Attachment #1.1: Type: text/plain, Size: 2543 bytes --]

Hi everyone,

I am to share a technical demonstration and benchmarking project that 
integrates the Falcon post-quantum signature scheme (Falcon-512) into 
Bitcoin Core, implemented as a soft-fork within the classic P2WPKH mode. 
This work aims to provide a practical reference for possible future Falcon 
adoption, especially as it approaches FIPS standardization.
You can find details at this fork 
<https://github.com/thisisnotgcsar/bitcoin-falcon>.

*Why Falcon?*
Falcon is a lattice-based, post-quantum digital signature scheme designed 
to be secure against quantum attacks. Unlike other PQC candidates such as 
SPHINCS+ and ML-DSA, Falcon offers significantly smaller signature and 
public key sizes, as well as efficient signing and verification times. It 
is implemented in pure C and does not require external dependencies.

*Benchmarking & Results*
Aspect                           Falcon    ECDSA
Public Key Size (B) 897         33
Signature Size (B) 655         71
Verification Time (μs) 57         120

Verification time is more critical than signature creation time in Bitcoin, 
since signature creation is performed by clients (wallets), while nodes 
focus on verification.

*Integration*

   - Falcon was included into the codebase from the original GitHub 
   repository.
   - The build system (CMakeLists.txt) was updated to support Falcon.
   - Falcon verification has been soft-fork enabled via a new script 
   verification flag.

*Next Steps & Reference*
This project serves as a practical demonstration of Falcon’s promising 
performance, highlighting its advantages over currently selected 
post-quantum signature algorithms such as SPHINCS+ and ML-DSA, which face 
significant time and space limitations. As Falcon approaches FIPS 
standardization, this work aims to provide a reference for future adoption 
and integration in Bitcoin.

Let me know what you think and if this could be of interest for which case 
I can complement the project by integrating Falcon into all the other 
spending paths. I also look forward to development/integration corrections.

Best regards,
Giulio

-- 
You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/16e01530-e9dd-481f-8c7f-ca9ccafcfcden%40googlegroups.com.

[-- Attachment #1.2: Type: text/html, Size: 3153 bytes --]

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-02-02 23:37 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-22  7:01 [bitcoindev] Falcon Post-Quantum Signature Scheme Proposal Giulio Golinelli
2026-01-22 12:48 ` [bitcoindev] " waxwing/ AdamISZ
2026-01-23  3:45   ` Giulio Golinelli
2026-01-22 14:35 ` [bitcoindev] " 'conduition' via Bitcoin Development Mailing List
2026-01-23  7:12   ` Giulio Golinelli
2026-01-23 15:36     ` 'Mikhail Kudinov' via Bitcoin Development Mailing List
2026-01-24 13:04       ` waxwing/ AdamISZ
2026-01-25 21:54         ` cassio gusson
2026-01-26 10:33           ` 'Mikhail Kudinov' via Bitcoin Development Mailing List
2026-01-26 15:21             ` waxwing/ AdamISZ
2026-01-27 16:07               ` 'conduition' via Bitcoin Development Mailing List
2026-01-24 13:31       ` Giulio Golinelli
2026-01-27 16:39     ` 'conduition' via Bitcoin Development Mailing List

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox