Isabel Foxen Duke
History of Metaprotocols on Bitcoin | ADAM KRELLENSTEIN
updated
The proposal introduces a full specification for “SHRINCS,” a hash-based signature scheme initially conceived by Jonas Nick and Mikhail Kudinov of Blockstream Research — with specification details added by new co-authors Conduition, Remix7531 and BIP 360 co-author Ethan Heilman.
Today, I’m honored to share a full whiteboard explanation of the scheme by its co-author Conduition, as well as thorough discussion of the scheme’s key tradeoffs when compared to Bitcoin’s existing elliptic-curve signatures and competing post-quantum alternatives.
In more detail, this interview includes:
— A full whiteboard walkthrough of the scheme’s key components and its relationship to the NIST-standardized scheme SPHINCS+
— SHRINCs’ introduction of a compact stateful path - yes, I said stateful 🌶️
— Whiteboard explanations of all relevant cryptographic subschemes, including FORS, WOTS+C, and XMSS
— Thorough discussion of the scheme’s tradeoffs and implications for Bitcoin’s existing functionality
If you have a vested interest in understanding what may be the future signature scheme protecting Bitcoin transactions in a post-quantum world, this episode is a must-watch.
WARNING: this episode is fairly technical — don't beat yourself up if you don't catch everything, or need to watch it a few times to grok the details.
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs @LayerTwoLabs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on @SuiNetwork — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox @BitBoxSwiss — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 — Intro
01:26 — The SHRINCS BIP and how conduition got here
05:26 — Building slhvk and joining the Blockstream working group
08:34 — Why hash-based signatures, even without quantum
14:08 — What SPHINCS is and what stateless really means
18:45 — Losing count and why state is dangerous
24:44 — SHRINCS and the stateless backup
WHITEBOARD SESSION STARTS HERE:
30:30 — Inside the SHRINCS public key
34:39 — Winternitz signatures and hypertrees
43:18 — Signature sizes and witness discount
51:42 — Inside the stateful side and FXMSS
1:01:25 — Where the stateful and stateless sides differ
1:08:50 — UXMSS, BXMSS and getting wallet devs up to speed
1:19:03 — FORS and the forest of random subsets
1:34:24 — What Bitcoin gives up with hash-based signatures
1:39:08 — Migration and where SHRINCS could be deployed
But cryptographic assumptions are only one dimension of security.
Different signature schemes introduce different implementation and operational risks. How should Bitcoin weigh cryptographic conservatism against the complexity required to deploy that cryptography safely?
While hash-based signatures are often favored for their conservative assumptions, CTO of Ledger, Charles Guillemet argues that evaluating primitives in isolation can obscure consequential risks at the systems level.
Stateful hash-based schemes, in particular, introduce state-management requirements where operational or user error can have catastrophic consequences —despite their conservative cryptographic foundations.
In this interview, Charles and I examine the tradeoffs of hash-based signatures and his case for greater consideration of lattice-based alternatives, i.e. ML-DSA.
A very juicy episode for anyone seriously assessing Bitcoin's post-quantum design landscape.
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on Sui Network — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 — Intro
01:45 — How the quantum threat became real for Ledger
09:06 — NIST influence and what Ledger built into its SDK
21:25 — ML-DSA and why Falcon might not be the right choice
25:33 — The problem with hash-based signatures
31:38 — Stateful signatures and the throughput problem
36:48 — Does user error outweigh the security difference?
42:27 — Bitcoin post-quantum migration scenario
45:15 — Maintaining multisig capabilities in a post-quantum world
55:54 — NIST standardization process and the backdoor question
1:01:06 — Trezor's approach and device authentication
1:06:09 — Ledger’s approach to post-quantum signatures
Following our previous episode introducing his proposed Bitcoin hard fork, eCash, we discuss how the project has evolved in recent months, what to expect when the fork launches on mainnet, and Paul's perspectives on today's Layer 2 landscape and the soon-to-activate BIP 110 soft fork.
An entertaining, popcorn-style conversation with one of Bitcoin's most unconventional thinkers, this episode offers diverse—and at times irreverent—commentary on some of the most important technical debates shaping Bitcoin's future.
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on Sui Network — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 — Intro
00:16 — The Coldcard exploit
09:37 — Can Bitcoin still soft fork?
15:30 — Paul's hard fork
26:12 — BIP 110's fork and the ghost of SegWit
42:03 — How drivechains work and eCash
53:00 — Quantum resistance and OP_CAT
1:01:44 — Launching a drivechain and the OP_RETURN debate
1:08:57 — The BIP 110 endgame: Udi trolling, hashrate, and Ocean
1:13:54 — Why Stratum V2 is a bad idea
1:20:33 — The decline of maximalism and the road ahead
My impression was that River had made a different bet: prioritizing product and security over rapid customer acquisition. In hindsight, that strategy paid off. As exchange and custody failures shook the industry during the 2022 bear market, River emerged as one of the most trusted names in Bitcoin.
River CEO Alex Leishman joins me to discuss the technical, operational, and commercial decisions that have differentiated the company—and why many of those decisions have influenced the way the industry thinks about Bitcoin custody today.
In more detail, we discuss:
- Why River chose to remain Bitcoin-only despite the short-term revenue tradeoffs
- The philosophical differences between Bitcoin banks and trader-driven crypto exchanges
- Why River manages its own custody stack—and what actually matters when choosing a Bitcoin custodian
- A recap of the industry's biggest custody failures: what went wrong and how to avoid repeating those mistakes
- How Bitcoin custody has evolved over the past decade—and how it may need to evolve again in a post-quantum world
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on Sui Network — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 — Intro
00:57 — How Alex found Bitcoin
09:16 — A monetary revolution
11:35 — River as the bank of the future
13:42 — Exchanges, hacks, and why trading isn't a lasting business
18:02 — Who River is built for
21:07 — Is non-Bitcoin crypto dying?
25:35 — Store of value, spending, and the long-term fee question
30:34 — Bitcoin banking and the role of fiat
40:10 — Stablecoins as "KYC-free dollars" and Bitcoin lending
45:44 — Inside River's custody: cold storage and security
54:28 — Proof of reserves and accountability
1:09:32 — How custody works: MPC vs multisig
1:13:59 — How exchanges are handling quantum


