Personally, I think we’re navigating some rough waters right now. Do you want to run some benchmarks on the post-quantum implementation? Are SPHINCS+ transactions that are not covered by this privacy-enhancing solution also processed in a block at the same time? So that there is little additional computational overhead?
Quantum-resistant signatures are significantly larger than classical ones, which directly impacts transaction size and fees.
- ML-DSA (Dilithium): ~2.5 KB (~40x larger)
- SPHINCS+: 8 KB – 49 KB (~125x - 760x larger)
Grouping inputs that share the same Lock Scripts, allowing multiple inputs to be verified with a single signature stored in the transaction’s Witnesses.
Edit:
- PayJoin requires both sender and receiver wallets to support the protocol.
- PayJoin is used during an actual payment.
- PayJoin involves only two parties (sender and receiver) and makes a payment transaction look normal while breaking the assumption that all inputs belong to the sender.
- read spark.money bitcoin-privacy-tools-comparison