Falcon vs ML-DSA vs SLH-DSA vs Winternitz: Picking a Quantum-Safe Signature

Updated | 3 min read | QUANTUM (QNT) community

Two families, one goal

Every serious post-quantum signature falls into one of two camps. Lattice-based schemes (ML-DSA and Falcon) rely on hard geometry problems. Hash-based schemes (SLH-DSA, XMSS, Winternitz, Lamport) rely only on the strength of a hash function such as SHA-256. Hash-based designs have the simplest security argument, which is why cautious engineers love them. Lattice designs are smaller and faster, which is why throughput-minded engineers love them. Both are considered resistant to known quantum attacks. For the basics see quantum-resistant signatures explained.

ML-DSA (FIPS 204)

ML-DSA, formerly called Dilithium, was finalized by NIST on August 13, 2024. It is the general purpose pick: reasonably simple to implement, fast to verify, and with signatures reported at 2,420 bytes (ML-DSA-44), 3,309 (ML-DSA-65) and 4,627 (ML-DSA-87). Sui says it chose ML-DSA-65 for everyday accounts, and QRL reports using ML-DSA-87 in its second generation network. Strengths: standardized, well understood tooling. Weakness: far bigger than ECDSA.

Falcon (FN-DSA, FIPS 206 pending)

Falcon is the compact lattice scheme. The Falcon-512 signature is reported at 666 bytes with an 897 byte public key, roughly one third of ML-DSA-44 in total footprint. The catch is implementation: it uses floating point math during signing, which is easy to get subtly wrong and harder to run on constrained devices. Algorand is the standout adopter. Its page says it signs State Proofs with Falcon and that native Falcon-1024 accounts went live on Mainnet in August 2026. Algorand also says Falcon-512 signatures are roughly half the size of Falcon-1024 ones.

SLH-DSA (FIPS 205)

SLH-DSA, formerly SPHINCS+, is stateless and hash-based. Its security rests on hash functions alone, so if lattice math were ever weakened, SLH-DSA would be unaffected. The trade: reported signatures of 7,856 bytes for the small variant and 17,088 bytes for the fast variant. Aptos has proposed it (AIP-137) as an optional account type, and Sui plans it inside Move contracts for high-value vaults. It is the "belt and braces" choice.

Winternitz and Lamport one-time signatures

Lamport signatures are the original hash-based idea: reveal half of a secret per bit of the message hash. Winternitz one-time signatures (WOTS) compress that by chaining hashes, giving far smaller signatures. The big rule is in the name: one time. Each signature reveals part of the private key, so a key must never sign twice. Solana's Winternitz Vault, published in January 2025 by researcher Dean Little, handles this by creating a fresh key pair for each transfer, with a Merkle root of public keys and a refund account for leftover funds. Ethereum's plan reportedly uses a Winternitz-style design (leanXMSS) for validator signatures, where state is managed by the protocol. Stateful schemes are efficient but unforgiving of wallet backup mistakes.

Side by side

SchemeFamilySize (reported)Best forWatch out for
ML-DSALattice2.4 to 4.6 KBEveryday accountsLarge keys
FalconLatticeAbout 0.7 KB (512)Block space sensitive chainsTricky implementation
SLH-DSAHash7.9 to 17 KBHigh-value vaults, long-term safetyBig and slow
Winternitz / LamportHash, one-timeSmall to moderateSingle-use vaults, validatorsKey reuse breaks it

Why chains mix them

An August 2026 Sui post makes the logic plain: the two families rest on different math, so a weakness in one would not necessarily hit the other. The same post mentions a July 2026 incident in which an AI model rapidly weakened a different candidate, HAWK, as one reason for choosing a higher security level. That is a healthy reminder that new schemes keep getting stress-tested, and it is why crypto agility (the ability to swap schemes later) matters so much.

Bottom line

There is no single winner. Expect chains to offer a menu, with wallets hiding the choice from users. This is education only, not financial advice, and it says nothing about the price of any token.

Sources and further reading

Reported as of 2026-10-09. Roadmaps and proposals change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.

Frequently asked questions

Which post-quantum signature is best?

None wins on every measure. ML-DSA is the standardized all-rounder, Falcon is more compact, SLH-DSA is the most conservative, and one-time hash signatures are tiny but must never be reused.

What does one-time signature mean?

Each key may sign only once, because a signature reveals part of the private key. A wallet using them must create a fresh key for every transaction.

Why not just use the biggest, safest scheme everywhere?

Block space is limited. Bigger signatures mean fewer transactions per block, so chains weigh safety against cost.

Share on X

Keep reading

All Quantum computing guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.