Technology

Blockstream Evaluates Falcon and Dilithium as Hawk Falls From Bitcoin's PQ Shortlist

Blockstream Research published a full evaluation of lattice-based post-quantum signatures for Bitcoin, rating Falcon, Dilithium, and Hawk against on-chain cost, implementation complexity, and deployment risk. Hawk was withdrawn from NIST standardization after Anthropic's AI found a key-recovery

5 min read
A tangle of fiber-optic cables glowing electric blue snakes across a dark server room floor, illuminated by the cold overhead fluorescence of a data center, while in the soft background a
Share

Hawk was the only NIST-additional-round lattice candidate with a distinct mathematical profile from Falcon and Dilithium. Its collapse in 60 hours narrows the post-quantum design space for Bitcoin's next soft fork.

Key takeaways

  • Blockstream Research published a peer-reviewed evaluation of three lattice-based post-quantum signature schemes for Bitcoin (Falcon, Dilithium, Hawk), arguing Bitcoin should target NIST security Category 3, not Category 1, given that outputs can sit unspent for decades.
  • Hawk, the only lattice-based scheme among NIST's nine third-round additional signature candidates, was withdrawn from standardization after Anthropic's AI found a key-recovery attack in approximately 60 hours, cutting the lattice candidate field and removing the main source of mathematical diversity from NIST's additional process.
  • Neither Falcon nor Dilithium supports BIP-32 hierarchical deterministic key derivation natively, meaning any lattice-based soft fork must solve the HD wallet problem before self-custody at scale is preserved.

Blockstream Research published a full peer-reviewed evaluation of lattice-based post-quantum signature schemes for Bitcoin on August 6, 2026, covering Falcon, Dilithium, and Hawk, and concluding that Bitcoin's post-quantum upgrade should target NIST security Category 3 at minimum. The paper landed against an active backdrop: Hawk, the only lattice-based scheme among NIST's nine third-round additional candidates, had just been withdrawn from standardization after a key-recovery attack was discovered in roughly 60 hours by Anthropic's AI.

The full paper is available at ePrint 2026/1628. NIST confirmed the withdrawal: "The HAWK development team subsequently withdrew its algorithm from consideration, and it will not be standardized or deployed."

Why Category 3 Is the Floor, Not a Preference

The security level question is where the paper makes its sharpest argument. NIST defines security categories 1 through 5. Higher categories mean stronger security, larger keys, and larger signatures. The Blockstream team argues Category 1 is not appropriate for Bitcoin because outputs can remain unspent for decades, and a key weakened by future cryptanalysis stays vulnerable indefinitely.

The cost of that margin is concrete. Moving Dilithium from Category 2 to Category 3 adds roughly 1.5 KB to the combined public key and signature footprint recorded on-chain. Every full node downloads and stores both. That is not a trivial cost for a protocol with tens of millions of UTXOs.

The caution is not unique to Blockstream. Apple excludes Category 1 lattice parameters entirely from its iMessage PQ3 protocol, using Category 3 and 5 throughout. Cloudflare deploys ML-KEM-768 (Category 3) in its post-quantum TLS rollout. Bitcoin's time horizon is longer than both.

Hawk's collapse makes the conservative posture harder to argue against. An AI broke a NIST candidate in roughly 60 hours. That result arrives before deployment, which is useful.

But it confirms that the threat model for evaluating cryptographic soundness has shifted. Speed of attack discovery no longer maps to human researcher cycles.

What Remains, and What Is Still Broken

Two candidates survive in NIST's lattice standardization track. Dilithium, standardized as ML-DSA under FIPS 204, runs on integer arithmetic throughout. That makes it straightforward to implement securely and audit.

Falcon, selected as FN-DSA and expected under FIPS 206, offers smaller combined sizes at equivalent security levels but requires Gaussian sampling and floating-point arithmetic. A pure integer simulation of Falcon's floating-point operations is possible, as noted in Bitcoin Optech #412, but that simulation must pass adversarial review before the implementation complexity concern goes away.

The falsifiable thesis here is direct. Falcon is the stronger lattice candidate for Bitcoin's post-quantum soft fork given its size advantage over Dilithium at Category 3, and Hawk's exit removes the only meaningfully different lattice path in NIST's additional process.

But Falcon's Gaussian sampling and floating-point requirements are the single biggest deployment risk. A published side-channel attack or implementation flaw in an integer-only Falcon build would collapse that argument. So would a cryptanalytic break against the NTRU or module-lattice assumptions underlying both Falcon and Dilithium, which would hand hash-based approaches like SHRINCS the field by default.

The Treasury's quantum readiness task force has Bitcoin's PQ roadmap on a policy clock. That external pressure adds urgency to getting the algorithm decision right, not just fast.

One problem the paper surfaces that sits underreported: none of the leading lattice schemes support BIP-32 hierarchical deterministic key derivation out of the box. BIP-360 (Pay-to-Merkle-Root / P2MR) defines the output type for a post-quantum upgrade but does not prescribe an algorithm. The algorithm choice is where the actual fight is, and any lattice path that does not solve HD derivation requires a new key management model for wallets before self-custody at scale works.

Hardware wallet RAM budgets add another constraint the paper flags. Existing devices were not designed around 1.5-plus KB signature stacks. Any soft fork deployment timeline must account for the upgrade cycle on the hardware side, not just the protocol side.

What to Watch

BIP-360's algorithm slot remains open. The Blockstream evaluation does not declare a single winner between Falcon and Dilithium, and the paper is explicit about the trade-offs rather than resolving them.

What changes after this paper is that the lattice design space is narrower. Hawk's exit removed the only NIST-additional-round candidate with a different mathematical profile. Developers tracking Bitcoin's post-quantum roadmap now have fewer moving targets on the lattice side, which means the pressure on the HD wallet derivation problem and the integer-only Falcon implementation question will intensify. Watch for adversarial review results on integer Falcon implementations and any BIP activity addressing HD derivation for post-quantum schemes.

Sources

Frequently Asked Questions

Both are lattice-based post-quantum signature schemes selected by NIST. Dilithium (ML-DSA, FIPS 204) uses integer arithmetic throughout and is simpler to implement securely.

Falcon (FN-DSA, anticipated under FIPS 206) uses a different lattice structure (NTRU-based) with Gaussian sampling and floating-point arithmetic. At equivalent security levels, Falcon generally produces smaller combined public key and signature sizes. The Blockstream paper compares parameter sets across all available NIST security categories; the full size tables are in ePrint 2026/1628. At Category 3, both carry materially larger on-chain footprints than Schnorr.

No. Hawk's failure affects only Hawk. Bitcoin's current Schnorr and ECDSA signatures are based on elliptic-curve discrete logarithm assumptions, which are entirely separate from Hawk's lattice construction.

NIST confirmed the Hawk finding does not affect any already-finalized post-quantum standards, including ML-DSA (Dilithium) or ML-KEM. The threat to Schnorr comes from Shor's algorithm running on a sufficiently large quantum computer, which does not exist today.

Not without hardware upgrades for most devices. The Blockstream paper explicitly flags hardware wallet RAM budgets as a deployment constraint. Lattice-based signatures at Category 3 produce combined key and signature sizes that exceed the memory envelopes of most current signing devices. Any post-quantum soft fork deployment timeline must account for a hardware wallet generation cycle, not just protocol activation.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.