Zero Knowledge Podcast

lean Ethereum Part 2: PQ Signatures and Poseidon with Dmitry and Benedikt

February 25, 2026·35 min·2 clips
Post-quantum LeanSig signatures are 2-4 kilobytes versus BLS's 96 bytes — and that size gap is why researchers spent years making hash outputs smaller without breaking security.
The miniseries stays close to the machinery. Anna Rose frames the episode as part of a six-part Lean Ethereum run, then hands things to Nico for a technical conversation with two Ethereum Foundation cryptography researchers, Benedikt Wagner and Dmitry Korvatovich. The topic is LeanSig, a hash-based multi-signature scheme introduced as a quantum-secure replacement for BLS in Ethereum consensus. Nico slows the stack down in a useful way. He asks why a signature design needs a SNARK at all, and that pushes the discussion away from simple signing and toward aggregation. BLS works so well because separate signatures can collapse into one short aggregate signature for a much longer list. Post-quantum schemes do not give that up easily. The guest explains that no known post-quantum scheme has the same clean, non-interactive aggregation feature that BLS has. Hash-based assumptions are attractive because they are minimal, but hash functions are short on algebraic structure by design. That removes the native path to aggregation, so LeanSig moves the job up a layer. Instead of making the signature scheme aggregate itself, a generic SNARK proves knowledge of a long witness containing many valid signatures. The proof becomes the aggregate signature. Nice trick, but not free. The burden moves into proving systems, encoding choices, and the hash function underneath. Poseidon sits right in that pressure point. The intro notes ongoing cryptanalysis around Poseidon and says the episode was recorded before recent attacks by Mertz and Garcia. The close comes back to formal security rather than gut feel, with the guests describing work from pen-and-paper PDF proofs toward formal verification, shared with Plonky 3 maintainers and posted on e-print.

As heard by us

A careful look at quantum-safe Ethereum signatures, with real cryptographic stakes.

This second Lean Ethereum episode stays on the question of how a quantum-safe Ethereum consensus might actually work. Nico speaks with Benedikt Wagner and Dmitry Korvatovich about LeanSig, a hash-based multi-signature scheme meant to replace BLS in a quantum-secure setting, and…

Read the full review in PlayNext →

Why you'd press play

You want the Lean Ethereum path to a quantum-secure signature scheme, not the slogan.

Read the full recommendation in PlayNext →
Listen to the show on