NIST finalized 3 algorithms: Why Blockchains Struggle with 38-72× Larger Signatures
ML-KEM ciphertexts are ~1KB. ML-DSA sigs are 2.4-4.6KB. That's 38-72× bigger than Ed25519.
Here's what you're actually working with ↓
First, what did NIST finalise?
August 2024: three standards shipped.
> ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205). These replace RSA, ECDH, and ECDSA.
ML-KEM handles key establishment. ML-DSA handles signing. SLH-DSA is the hash-based backup.
Two more coming but not finalised yet: FN-DSA (FIPS 206, draft stuck in publishing) and HQC (selected March 2025, standard expected 2027).
ML-KEM (FIPS 203) - Key encapsulation
Replaces RSA key transport and ECDH in TLS, SSH, and VPNs.
• Derived from CRYSTALS-Kyber
• Lattice-based
• Ciphertext size: 800-1,568 bytes depending on security level
• ML-KEM-768 (security category 3) is the standard pick: 1,088 bytes
ML-DSA (FIPS 204) - Digital signatures
This is the big one. Replaces ECDSA and EdDSA.
• Derived from CRYSTALS-Dilithium
• Lattice-based
• Signature sizes: 2,420 to 4,627 bytes
• Ed25519 or Schnorr: 64 bytes
• That's 38-72× bigger
For Ethereum, where every tx signature goes onchain? Read about
@ethereum Frame txs.
SLH-DSA (FIPS 205) - Hash-based signatures
Most conservative option. Security relies on hash functions, which are well understood.
• Derived from SPHINCS+
• Stateless, hash-based
• Signature sizes: 7,856 to 49,856 bytes
• Yes, up to 50KB per signature
FN-DSA (FIPS 206) - Compact signatures, but not ready yet
Based on FALCON. Smaller than ML-DSA.
• Expected sigs: ~1.25KB
• Keys: ~1.75KB
• Way better for bandwidth-constrained systems
Catch: Initial Public Draft was prepared August 2025 but still stuck in NIST's publishing pipeline as of May 2026. Won't be finalized until 2027 at earliest.
Also requires floating point arithmetic during signing. Implementation complexity is brutal.
HQC - Second KEM option, also not ready
Selected by NIST in March 2025.
• Not lattice-based
• Diversifies hardness assumptions
• If lattice crypto somehow breaks, HQC survives
Downside: larger messages, slower performance. Won't replace ML-KEM as the default.
Draft standard expected ~1 year, finalisation 2027.
The numbers everyone needs to know right now:
ML-KEM:
• ML-KEM-512: 768B ciphertext
• ML-KEM-768: 1,088B ciphertext (most common)
• ML-KEM-1024: 1,568B ciphertext
ML-DSA:
• ML-DSA-44: 2,420B sig
• ML-DSA-65: 3,309B sig (most common)
• ML-DSA-87: 4,627B sig
SLH-DSA:
• 7.8KB - 49KB depending on variant
Recap:
Finalised and ready:
> ML-KEM (FIPS 203): ~1KB ciphertexts, handles key establishment
> ML-DSA (FIPS 204): 2.4-4.6KB sigs, replaces ECDSA
> SLH-DSA (FIPS 205): 7.8-50KB sigs, conservative hash-based option
Still in progress:
X FN-DSA (FIPS 206): ~1.25KB sigs, draft stuck, 2027 target
X HQC: diversifies assumptions, 2027 target