Standardized parameter sets for hash-based signatures weren’t chosen for Bitcoin.
For a SHRINCS proposal, we can trade some of SLH-DSA's enormous signature budget for smaller signatures and cheaper verification. We searched 25,935 parameter sets and found a 5.7 kB candidate, 26%
Joined October 2022
- An aggregate signature lets multiple signers each sign a different message, then combine everything into one compact signature that proves who signed what. @real_or_random explains the primitive behind Cross-Input Signature Aggregation. Full talk at Eurocrypt below. ⬇️
- Full aggregation for BIP340 signatures, now as a draft BIP. It specifies DahLIAS, an aggregate signature scheme and can serve as a basis for future cross-input signature aggregation (CISA) proposals. Thanks to @fjahr for the spec work. More background on DahLIAS 👇
- The DahLIAS Eurocrypt talk by @real_or_random is online now! It focuses on what it takes to deploy signature aggregation in Bitcoin: pitfalls, attacks, and practical requirements. DahLIAS is not post-quantum, but many of these issues matter for PQ aggregate sigs too. 👇Excited to share that our DahLIAS paper has been accepted to Eurocrypt 2026! 🎉 DahLIAS enables cross-input signature aggregation (CISA) on Bitcoin’s secp256k1 curve. See you in Rome, May 10–14! Thanks to @yannickseurin (@Ledger), @real_or_random & @n1ckler (@blksresearch)!
- Stateful signatures trade systemic risk for localized risk. The failure mode is confined to individual wallets, not the network. @n1ckler at @TheBitcoinConf 2026 on why that's the better trade-off to explore.



