Ethereum Researchers Propose SPHINCS- Signature Scheme For Post-Quantum Wallets

bitcoinistPublished on 2026-06-13Last updated on 2026-06-13

Abstract

Ethereum researchers have proposed SPHINCS-, a stateless post-quantum signature verification scheme optimized for the Ethereum Virtual Machine (EVM). Designed to function within the existing EVM without protocol changes or new precompiles, it replaces standard hash functions with EVM-native KECCAK256, enabling a Solidity implementation. The scheme is tailored for wallet use, targeting a more practical signature budget (2^14 to 2^20 signatures per key) rather than the standard astronomical limit, reflecting typical Ethereum address transaction patterns. A key variant, C13, is reported to verify signatures at about 127,000 gas with a 3,704-byte signature. The proposal, credited to researcher nicocsgy with acknowledgments to Vitalik Buterin, is currently a non-standard research concept, not a finished standard. It highlights trade-offs, such as long signing times on certain hardware wallets, but contributes to the broader, essential conversation on preparing Ethereum's account security for a future with quantum computers.

TL;DR

  • An Ethereum Research post proposes SPHINCS-, a stateless post-quantum signature verification scheme optimized for the EVM.
  • The design replaces standard SHAKE256 functions with EVM-native KECCAK256, allowing a Solidity implementation without protocol changes or precompiles.
  • The C13 variant is described as verifying at about 127,000 gas with a 3,704-byte signature.
  • The proposal is non-standard and research-stage, but it adds to Ethereum’s growing post-quantum security conversation.

Ethereum researchers are exploring a new post-quantum signature design that could allow wallets to verify quantum-resistant signatures directly on the Ethereum Virtual Machine without requiring protocol changes.

The proposal, published on Ethereum Research on June 12, introduces SPHINCS-, pronounced as “SPHINCS minus,” as an efficient stateless post-quantum signature verification scheme designed for EVM compatibility. The post credits nicocsgy as author and includes special thanks to Vitalik Buterin and other contributors.

Post-Quantum Signatures For Ethereum Wallets

The basic problem is that today’s blockchain wallets rely on cryptographic assumptions that could eventually be weakened by sufficiently powerful quantum computers. That threat is not immediate, but Ethereum researchers and cryptographers are increasingly discussing how accounts could migrate to quantum-resistant signature schemes over time.

SPHINCS- is designed around a practical constraint: it should work inside the EVM as it exists today. Instead of requiring new precompiles or protocol-level changes, the proposal replaces standard SLH-DSA hash functions such as SHAKE256 with KECCAK256, which is native to Ethereum.

That design choice allows the verification logic to be implemented in Solidity. In other words, the proposal is not asking Ethereum to change its base protocol immediately. It is exploring how far post-quantum wallet verification can be pushed using existing EVM tools.

Lower Signature Budget, Lower Costs

The post also scales down the signature budget to a range more relevant for blockchain wallets. Instead of targeting the standard 2^64 signatures per key, SPHINCS- focuses on a budget between 2^14 and 2^20 signatures per key.

The argument is that normal Ethereum addresses do not need an astronomical number of signatures. The post says the average annual 99.9th percentile of Ethereum transactions is around 431 per address since the Merge, which suggests wallet-specific parameters can be more efficient than broad general-purpose standards.

For its C13 variant, the proposal reports verification costs of about 127,000 gas and a signature size of 3,704 bytes. It compares that with standard SLH-DSA-SHA2-128-24, which the post says costs 142,000 gas with a 3,856-byte signature and requires about 1.07 billion hash calls for signing.

Still Research, Not A Standard

The proposal is careful to note trade-offs. SPHINCS- is non-standard and does not strictly match FIPS 205 parameters because it uses Keccak and limited signing budgets. That means it should be treated as research rather than a finished Ethereum account standard.

There are also practical wallet constraints. The post says C11 and C12 variants are compatible with hardware wallets, but signing times on an ST33K1M5 secure element are listed at 390 seconds and 47.5 seconds respectively. That highlights the gap between theoretical verification efficiency and real user experience.

Even so, the direction is important. Ethereum’s long-term account security will likely require multiple approaches, including new signature schemes, account abstraction tools, migration paths and better wallet UX.

Why It Matters

Post-quantum security is still a future-facing issue, but blockchain networks cannot wait until quantum attacks are practical before thinking about migration. Wallet upgrades, standards, user education and ecosystem coordination can take years.

SPHINCS- does not solve that entire problem. But it gives Ethereum researchers another concrete design to test: a stateless, EVM-native, post-quantum verification path that may work without waiting for base-layer changes.

Trending Cryptos

Related Questions

QWhat is SPHINCS- and what is its main purpose as proposed for Ethereum?

ASPHINCS- is a stateless post-quantum signature verification scheme designed to be EVM-compatible, with the main purpose of allowing wallets to verify quantum-resistant signatures directly on the Ethereum Virtual Machine without requiring protocol changes.

QHow does SPHINCS- achieve EVM compatibility without needing protocol changes?

AIt achieves EVM compatibility by replacing standard SLH-DSA hash functions like SHAKE256 with the EVM-native KECCAK256 function, enabling the verification logic to be implemented in Solidity.

QWhat are the reported gas cost and signature size for the C13 variant of SPHINCS-?

AFor the C13 variant, the reported verification cost is about 127,000 gas, and the signature size is 3,704 bytes.

QWhy does the proposal scale down the signature budget for SPHINCS- compared to standard parameters?

AIt scales down the signature budget to a range between 2^14 and 2^20 signatures per key because the average Ethereum address does not need an astronomical number of signatures, and this allows for more wallet-specific efficiency compared to general-purpose standards.

QWhat is the current status of the SPHINCS- proposal, and what are some of its noted limitations?

AThe SPHINCS- proposal is non-standard, research-stage, and not a finished Ethereum account standard. Key limitations include it not strictly matching FIPS 205 parameters and having long signing times on certain hardware wallets (e.g., 390 seconds for C11 on an ST33K1M5 secure element).

Related Reads

In Jinjiang, Fujian, a Storage Super Unicorn Lies Quiet

In Fujian's Jinjiang, a city known for sportswear, lies a quiet semiconductor giant: Fujian Jinhua Integrated Circuit Co. (JHICC). Once a promising domestic DRAM manufacturer alongside Yangtze Memory and ChangXin Memory Technologies (CXMT), its journey was derailed in 2018 when the U.S. placed it on an Entity List and filed criminal charges for alleged trade secret theft. This halted production for years. A turning point came in February 2024 when a U.S. federal court found JHICC not guilty. However, it had lost crucial time. While CXMT soared to become a top-valued A-share company in 2024, JHICC, with an estimated valuation of 80 billion RMB, was just restarting. Its current output is primarily customized DDR4 chips, not the advanced DDR5/HBM demanded for AI, but it still benefits from the broader memory chip upcycle. JHICC's story is tied to Chen Zhengkun, a veteran engineer who left Micron to lead the venture. Founded in 2016 with state-backed funding, JHICC partnered with Taiwan's UMC to develop DRAM technology. Rapid progress was cut short by the U.S. actions, which Micron initiated, partly due to its heavy reliance on the Chinese market. Post-sanctions, Chen's team worked to rebuild the production line with reduced reliance on U.S. technology. According to its records, JHICC achieved small-scale production and revenue growth under immense pressure. It now focuses on the stable "niche" DRAM market (e.g., TVs, routers) with a monthly capacity of ~40,000 wafers, aiming for 60,000 by 2026. It holds over 1,000 patents but remains on the Entity List. For Jinjiang, investing in JHICC was a bold industrial leap. The local government provided unwavering financial and logistical support during the crisis, helping the company survive. JHICC has become the anchor for a growing local semiconductor cluster. Though its scale lags behind domestic peers, JHICC's persistence symbolizes a hard-won foothold in a global market long dominated by Samsung, SK Hynix, and Micron. Having missed one boom, it seeks a place in the new AI-driven memory supercycle.

marsbit47m ago

In Jinjiang, Fujian, a Storage Super Unicorn Lies Quiet

marsbit47m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片