pk+sig size in the witness will be about 2,000 vB. For comparison, pk+sig for Schnorr is about 25 vB.
Quantum signature size is almost 100x bigger. PQC does not scale on Bitcoin.
It also seems kind of silly to me to be worrying about quantum resistance now when Shor's algorithm on a quantum computer has seen no progress since 2012 when the number 21 was factored.
Quantum signature size is almost 100x bigger. PQC does not scale on Bitcoin.
It also seems kind of silly to me to be worrying about quantum resistance now when Shor's algorithm on a quantum computer has seen no progress since 2012 when the number 21 was factored.