Ethereum Researchers Propose SPHINCS- Signature Scheme For Post-Quantum Wallets

bitcoinistPublished on 2026-06-13Last updated on 2026-06-13

Abstract

Ethereum researchers have proposed SPHINCS-, a stateless post-quantum signature verification scheme optimized for the Ethereum Virtual Machine (EVM). Designed to function within the existing EVM without protocol changes or new precompiles, it replaces standard hash functions with EVM-native KECCAK256, enabling a Solidity implementation. The scheme is tailored for wallet use, targeting a more practical signature budget (2^14 to 2^20 signatures per key) rather than the standard astronomical limit, reflecting typical Ethereum address transaction patterns. A key variant, C13, is reported to verify signatures at about 127,000 gas with a 3,704-byte signature. The proposal, credited to researcher nicocsgy with acknowledgments to Vitalik Buterin, is currently a non-standard research concept, not a finished standard. It highlights trade-offs, such as long signing times on certain hardware wallets, but contributes to the broader, essential conversation on preparing Ethereum's account security for a future with quantum computers.

TL;DR

  • An Ethereum Research post proposes SPHINCS-, a stateless post-quantum signature verification scheme optimized for the EVM.
  • The design replaces standard SHAKE256 functions with EVM-native KECCAK256, allowing a Solidity implementation without protocol changes or precompiles.
  • The C13 variant is described as verifying at about 127,000 gas with a 3,704-byte signature.
  • The proposal is non-standard and research-stage, but it adds to Ethereum’s growing post-quantum security conversation.

Ethereum researchers are exploring a new post-quantum signature design that could allow wallets to verify quantum-resistant signatures directly on the Ethereum Virtual Machine without requiring protocol changes.

The proposal, published on Ethereum Research on June 12, introduces SPHINCS-, pronounced as “SPHINCS minus,” as an efficient stateless post-quantum signature verification scheme designed for EVM compatibility. The post credits nicocsgy as author and includes special thanks to Vitalik Buterin and other contributors.

Post-Quantum Signatures For Ethereum Wallets

The basic problem is that today’s blockchain wallets rely on cryptographic assumptions that could eventually be weakened by sufficiently powerful quantum computers. That threat is not immediate, but Ethereum researchers and cryptographers are increasingly discussing how accounts could migrate to quantum-resistant signature schemes over time.

SPHINCS- is designed around a practical constraint: it should work inside the EVM as it exists today. Instead of requiring new precompiles or protocol-level changes, the proposal replaces standard SLH-DSA hash functions such as SHAKE256 with KECCAK256, which is native to Ethereum.

That design choice allows the verification logic to be implemented in Solidity. In other words, the proposal is not asking Ethereum to change its base protocol immediately. It is exploring how far post-quantum wallet verification can be pushed using existing EVM tools.

Lower Signature Budget, Lower Costs

The post also scales down the signature budget to a range more relevant for blockchain wallets. Instead of targeting the standard 2^64 signatures per key, SPHINCS- focuses on a budget between 2^14 and 2^20 signatures per key.

The argument is that normal Ethereum addresses do not need an astronomical number of signatures. The post says the average annual 99.9th percentile of Ethereum transactions is around 431 per address since the Merge, which suggests wallet-specific parameters can be more efficient than broad general-purpose standards.

For its C13 variant, the proposal reports verification costs of about 127,000 gas and a signature size of 3,704 bytes. It compares that with standard SLH-DSA-SHA2-128-24, which the post says costs 142,000 gas with a 3,856-byte signature and requires about 1.07 billion hash calls for signing.

Still Research, Not A Standard

The proposal is careful to note trade-offs. SPHINCS- is non-standard and does not strictly match FIPS 205 parameters because it uses Keccak and limited signing budgets. That means it should be treated as research rather than a finished Ethereum account standard.

There are also practical wallet constraints. The post says C11 and C12 variants are compatible with hardware wallets, but signing times on an ST33K1M5 secure element are listed at 390 seconds and 47.5 seconds respectively. That highlights the gap between theoretical verification efficiency and real user experience.

Even so, the direction is important. Ethereum’s long-term account security will likely require multiple approaches, including new signature schemes, account abstraction tools, migration paths and better wallet UX.

Why It Matters

Post-quantum security is still a future-facing issue, but blockchain networks cannot wait until quantum attacks are practical before thinking about migration. Wallet upgrades, standards, user education and ecosystem coordination can take years.

SPHINCS- does not solve that entire problem. But it gives Ethereum researchers another concrete design to test: a stateless, EVM-native, post-quantum verification path that may work without waiting for base-layer changes.

Trending Cryptos

Related Questions

QWhat is SPHINCS- and what is its main purpose as proposed for Ethereum?

ASPHINCS- is a stateless post-quantum signature verification scheme designed to be EVM-compatible, with the main purpose of allowing wallets to verify quantum-resistant signatures directly on the Ethereum Virtual Machine without requiring protocol changes.

QHow does SPHINCS- achieve EVM compatibility without needing protocol changes?

AIt achieves EVM compatibility by replacing standard SLH-DSA hash functions like SHAKE256 with the EVM-native KECCAK256 function, enabling the verification logic to be implemented in Solidity.

QWhat are the reported gas cost and signature size for the C13 variant of SPHINCS-?

AFor the C13 variant, the reported verification cost is about 127,000 gas, and the signature size is 3,704 bytes.

QWhy does the proposal scale down the signature budget for SPHINCS- compared to standard parameters?

AIt scales down the signature budget to a range between 2^14 and 2^20 signatures per key because the average Ethereum address does not need an astronomical number of signatures, and this allows for more wallet-specific efficiency compared to general-purpose standards.

QWhat is the current status of the SPHINCS- proposal, and what are some of its noted limitations?

AThe SPHINCS- proposal is non-standard, research-stage, and not a finished Ethereum account standard. Key limitations include it not strictly matching FIPS 205 parameters and having long signing times on certain hardware wallets (e.g., 390 seconds for C11 on an ST33K1M5 secure element).

Related Reads

How to Regulate Single-Stock Leveraged ETFs? On Thursday, the Entire Market Is Watching This Korean Government Meeting

The highest-level economic coordination body in South Korea, the "F4" comprising the Ministry of Economy and Finance, the Financial Services Commission, the Bank of Korea, and the Financial Supervisory Service, will hold an emergency meeting on Thursday to discuss regulatory measures for single-stock leveraged ETFs. These products, launched just six weeks ago, have been widely blamed for exacerbating market volatility. The KOSPI's 8% plunge on Monday triggered the year's seventh trading halt, intensifying scrutiny. Regulators have expressed rare public regret over approving the products. FSS Governor Lee Bok-hyun stated he "regretted not doing everything possible to prevent" their introduction and acknowledged structural problems, citing massive retail investments and legal complications from a rushed rollout. Possible countermeasures under discussion include raising margin requirements, imposing daily price limits, and adjusting leverage caps. However, officials admit these may be temporary fixes. Data confirms the amplified volatility. Since the ETFs' launch, days with KOSPI moves exceeding 3% have nearly doubled. Trading halts have reached record levels, surpassing the 2008 financial crisis peak. The products allow 2x leveraged bets on giants like Samsung Electronics and SK Hynix. Their daily rebalancing to match returns is seen as mechanically fueling market swings. The outcome of Thursday's F4 meeting is highly anticipated, with expectations leaning towards stricter controls on leverage, investor access, or other structural constraints to curb the products' market impact.

marsbit2m ago

How to Regulate Single-Stock Leveraged ETFs? On Thursday, the Entire Market Is Watching This Korean Government Meeting

marsbit2m ago

AI Overhauled Terence Tao's 30-Year-Old Website, Uncovering Two Bugs Hidden for Over Two Decades in the Process

AI Revamps Terence Tao's 30-Year-Old Website, Unearthing Two 20-Year-Old Bugs in His Code Terence Tao, a renowned mathematician, has enlisted an AI agent to overhaul his personal academic website, which was built in 1997 with a static HTML, manually-maintained "Web 1.0" architecture. In just one day, the agent migrated 560 papers and preprints, 374 travel logs, 68 courses, 19 books, and 29 old math applets to a new system on GitHub Pages. The new site is structured around YAML files as the "single source of truth," with static HTML pages automatically generated from this data—a fundamental shift from maintaining individual documents to managing a centralized database. During the migration, the AI uncovered inconsistencies, outdated entries, and broken links that had accumulated over nearly three decades of manual updates. It also successfully ported a set of small educational Java 1.0 applets to JavaScript. Notably, while reviewing this translation, Tao found only one new bug introduced by the AI. Conversely, the AI identified two subtle bugs in his original Java code that he was previously unaware of. Tao emphasizes the project highlights AI's potential for automating tedious "digital housekeeping"—routine tasks like data migration and website maintenance that are costly and error-prone when done manually. He also revived a 27-year-old stalled project: a special relativity visualizer or "Minkowskian Inkscape." With AI assistance, a working alpha version was built in two hours. While AI still requires human oversight for critical work, Tao argues that for such structured, non-core tasks, "AI + human review" can result in lower error rates and drastically lower correction costs compared to purely manual maintenance over decades.

marsbit2m ago

AI Overhauled Terence Tao's 30-Year-Old Website, Uncovering Two Bugs Hidden for Over Two Decades in the Process

marsbit2m ago

ZORA Plunges 95%, Coinbase Finally Admits Creator Coins Failed

On July 13th, Coinbase CEO Brian Armstrong publicly declared the failure of Base network's year-long "content coins" strategy. Initially launched in 2025 via the Zora platform and integrated into Coinbase's wallet as a core feature, the model aimed to turn every social media post into a tradeable token. Each post or creator account would generate 1 billion ERC-20 tokens, with creators receiving an initial allocation. The concept briefly propelled Base to become the largest L2 by new token issuance. However, the model proved unsustainable. These tokens, explicitly not granting ownership or revenue shares, primarily functioned as speculative assets dependent on new buyers. While activity surged in mid-2025—with millions of tokens minted and billions in trading volume—it failed to build lasting user engagement or value. High-profile token launches, including one by Base's official account, experienced extreme volatility, often crashing shortly after spikes. The supporting infrastructure token, ZORA, plummeted approximately 95% from its August 2025 peak, losing nearly $520 million in market capitalization. Armstrong acknowledged the misstep, stating "it didn't work" and that Base had shifted focus earlier in the year toward its core competencies of trading and stablecoin payments. This pivot follows internal criticism that the content coin experiment consumed excessive resources, harmed other Base projects, and ultimately resulted in significant financial losses for participating users.

Foresight News19m ago

ZORA Plunges 95%, Coinbase Finally Admits Creator Coins Failed

Foresight News19m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片