Post-Quantum Signature Sizes and Block Space: Why Blockchains Feel the Squeeze
The problem in one sentence
A blockchain is a shared notebook with a limited number of pages per minute. Every payment needs a signature proving the owner approved it, and the quantum-safe signatures chosen by standards bodies are far bigger than the ones in use today. Bigger signatures mean fewer payments per page. That is the main engineering puzzle behind the whole post-quantum story, and it is why this topic is more than a simple software swap.
Quick background: a large, error-corrected quantum computer running Shor's algorithm could in theory break the elliptic curve signatures that crypto uses. Nobody has built such a machine yet. The work below is preparation, and preparation is a good sign of a maturing field.
The numbers, as reported
One technical analysis (see Sources) lists these approximate sizes. Treat them as reported figures for the standard parameter sets, and check the standards for your exact use.
| Scheme | Signature | Public key |
|---|---|---|
| ECDSA today | 64 to 72 bytes | 33 bytes |
| Falcon-512 (FN-DSA, FIPS 206 pending) | 666 bytes | 897 bytes |
| ML-DSA-44 | 2,420 bytes | 1,312 bytes |
| ML-DSA-65 | 3,309 bytes | 1,952 bytes |
| ML-DSA-87 | 4,627 bytes | 2,592 bytes |
| SLH-DSA-SHA2-128s | 7,856 bytes | 32 to 64 bytes |
| SLH-DSA-SHA2-128f | 17,088 bytes | 32 to 64 bytes |
So a post-quantum signature is roughly 10 to over 100 times the size of an ECDSA one. Ethereum's own roadmap page reports that a planned hash-based validator signature (leanXMSS) is roughly 3,000 bytes, compared with 96 bytes for today's BLS signatures.
What it does to a Bitcoin-style block
Bitcoin gives witness data (where signatures live) a discount: 1 weight unit per byte instead of 4, inside a 4 million weight unit block limit. Even with that discount, the analysis cited above reports that a hybrid ML-DSA-44 plus Schnorr spend would add roughly 3,800 weight units per input, against about 110 for a Schnorr-only spend. It reports that a block holding roughly 2,500 to 3,000 standard transactions might hold only 500 to 700 post-quantum ones, a 4 to 5 times drop. In a Blockstream model it cites, throughput falls from about 6.5 transactions per second for Schnorr to roughly 0.5 for ML-DSA and 0.36 for SLH-DSA. These are modelled estimates, not a measured network, but they show why designers care so much.
Four ways chains fight the squeeze
- Pick smaller schemes. Falcon-512 is the compact option, at about one third the size of ML-DSA-44 per the same analysis. The price is more delicate math to implement safely (see the scheme comparison).
- Aggregate with proofs. Ethereum's plan is to use zero-knowledge proofs to combine many signatures into one small proof. The ethereum.org page says its leanVM would compress aggregated data by about 250 times to offset the larger size. See Ethereum plans.
- Design cleverer schemes. The same analysis mentions Blockstream's SHRINCS idea with a reported 324 byte compact first signature, a stateful design that falls back to larger stateless signatures. It is a research sketch, not a deployed standard.
- Make bigger room. Chains with higher capacity per second have more headroom, and some designs let only high-value accounts pay for the heavier signatures.
Why this is an optimistic story
Larger signatures are a cost problem, not a "the math is broken" problem. Costs are exactly what engineers are good at squeezing. NIST finalized ML-DSA (FIPS 204) on August 13, 2024, so the building blocks exist and have been studied for years (how NIST chose them). Plenty of teams are now measuring real sizes on real test networks instead of guessing.
What it means for you
If you hold crypto, the practical effect later may be wallets that sign with larger keys and slightly higher fees for the first generation of quantum-safe transactions. You do not need to act today because of size alone. For the larger picture see the roadmaps compared. This is education, not financial advice, and nothing here predicts the price of any asset including QNT, which is an independent memecoin with no link to Quantinuum Ltd.
Sources and further reading
- PostQuantum.com: fixing Bitcoin, signature sizes and throughput
- ethereum.org: quantum resistance roadmap
- NIST: FIPS 204 (ML-DSA)
- BIP-360 text (Pay-to-Merkle-Root), bitcoin/bips
Reported as of 2026-10-09. Roadmaps and proposals change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
How big is a post-quantum signature?
Reported sizes range from about 666 bytes for Falcon-512 to 2,420 to 4,627 bytes for ML-DSA and about 7,856 bytes for SLH-DSA-SHA2-128s, compared with roughly 64 to 72 bytes for ECDSA today.
Will post-quantum signatures make fees higher?
Possibly, because bigger signatures use more block space. Compression through proofs and compact schemes aims to limit this, and the real effect depends on each chain's design.
Does the quantum threat exist today?
No machine that can break elliptic curve signatures has been built. Chains are preparing early because migrations take years.
Keep reading
- Falcon vs ML-DSA vs SLH-DSA vs Winternitz: Picking a Quantum-Safe Signature
A readable comparison of the main post-quantum signature families that blockchains are considering, with their trade-offs. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - Bitcoin BIP-360 and BIP-361 Explained: The Quantum Upgrade Proposals
What the draft Bitcoin proposals P2MR (BIP-360) and the migration and sunset plan (BIP-361) actually say, and what they leave open.
All Quantum events, catalysts and roadmap guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary