Falcon vs ML-DSA vs SLH-DSA vs Winternitz: Picking a Quantum-Safe Signature
Two families, one goal
Every serious post-quantum signature falls into one of two camps. Lattice-based schemes (ML-DSA and Falcon) rely on hard geometry problems. Hash-based schemes (SLH-DSA, XMSS, Winternitz, Lamport) rely only on the strength of a hash function such as SHA-256. Hash-based designs have the simplest security argument, which is why cautious engineers love them. Lattice designs are smaller and faster, which is why throughput-minded engineers love them. Both are considered resistant to known quantum attacks. For the basics see quantum-resistant signatures explained.
ML-DSA (FIPS 204)
ML-DSA, formerly called Dilithium, was finalized by NIST on August 13, 2024. It is the general purpose pick: reasonably simple to implement, fast to verify, and with signatures reported at 2,420 bytes (ML-DSA-44), 3,309 (ML-DSA-65) and 4,627 (ML-DSA-87). Sui says it chose ML-DSA-65 for everyday accounts, and QRL reports using ML-DSA-87 in its second generation network. Strengths: standardized, well understood tooling. Weakness: far bigger than ECDSA.
Falcon (FN-DSA, FIPS 206 pending)
Falcon is the compact lattice scheme. The Falcon-512 signature is reported at 666 bytes with an 897 byte public key, roughly one third of ML-DSA-44 in total footprint. The catch is implementation: it uses floating point math during signing, which is easy to get subtly wrong and harder to run on constrained devices. Algorand is the standout adopter. Its page says it signs State Proofs with Falcon and that native Falcon-1024 accounts went live on Mainnet in August 2026. Algorand also says Falcon-512 signatures are roughly half the size of Falcon-1024 ones.
SLH-DSA (FIPS 205)
SLH-DSA, formerly SPHINCS+, is stateless and hash-based. Its security rests on hash functions alone, so if lattice math were ever weakened, SLH-DSA would be unaffected. The trade: reported signatures of 7,856 bytes for the small variant and 17,088 bytes for the fast variant. Aptos has proposed it (AIP-137) as an optional account type, and Sui plans it inside Move contracts for high-value vaults. It is the "belt and braces" choice.
Winternitz and Lamport one-time signatures
Lamport signatures are the original hash-based idea: reveal half of a secret per bit of the message hash. Winternitz one-time signatures (WOTS) compress that by chaining hashes, giving far smaller signatures. The big rule is in the name: one time. Each signature reveals part of the private key, so a key must never sign twice. Solana's Winternitz Vault, published in January 2025 by researcher Dean Little, handles this by creating a fresh key pair for each transfer, with a Merkle root of public keys and a refund account for leftover funds. Ethereum's plan reportedly uses a Winternitz-style design (leanXMSS) for validator signatures, where state is managed by the protocol. Stateful schemes are efficient but unforgiving of wallet backup mistakes.
Side by side
| Scheme | Family | Size (reported) | Best for | Watch out for |
|---|---|---|---|---|
| ML-DSA | Lattice | 2.4 to 4.6 KB | Everyday accounts | Large keys |
| Falcon | Lattice | About 0.7 KB (512) | Block space sensitive chains | Tricky implementation |
| SLH-DSA | Hash | 7.9 to 17 KB | High-value vaults, long-term safety | Big and slow |
| Winternitz / Lamport | Hash, one-time | Small to moderate | Single-use vaults, validators | Key reuse breaks it |
Why chains mix them
An August 2026 Sui post makes the logic plain: the two families rest on different math, so a weakness in one would not necessarily hit the other. The same post mentions a July 2026 incident in which an AI model rapidly weakened a different candidate, HAWK, as one reason for choosing a higher security level. That is a healthy reminder that new schemes keep getting stress-tested, and it is why crypto agility (the ability to swap schemes later) matters so much.
Bottom line
There is no single winner. Expect chains to offer a menu, with wallets hiding the choice from users. This is education only, not financial advice, and it says nothing about the price of any token.
Sources and further reading
- PostQuantum.com: fixing Bitcoin, signature sizes and throughput
- Sui: making Sui quantum ready
- Algorand: leading on post-quantum technology
- NIST: FIPS 204 (ML-DSA)
- The Quantum Insider: Solana Winternitz Vault
- Decrypt: Solana and Aptos harden against quantum attacks
Reported as of 2026-10-09. Roadmaps and proposals change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
Which post-quantum signature is best?
None wins on every measure. ML-DSA is the standardized all-rounder, Falcon is more compact, SLH-DSA is the most conservative, and one-time hash signatures are tiny but must never be reused.
What does one-time signature mean?
Each key may sign only once, because a signature reveals part of the private key. A wallet using them must create a fresh key for every transaction.
Why not just use the biggest, safest scheme everywhere?
Block space is limited. Bigger signatures mean fewer transactions per block, so chains weigh safety against cost.
Keep reading
- Post-Quantum Signature Sizes and Block Space: Why Blockchains Feel the Squeeze
Post-quantum signatures are many times bigger than today's. Here is what that means for block space, fees and throughput, in plain English. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - Crypto Agility Explained: Preparing for Algorithm Change
Crypto agility is the ability to swap cryptographic algorithms without rebuilding a system. Learn why it matters for the post-quantum shift and for blockchains.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary