We're working on a post-quantum sig scheme, hash-based, that we hope to submit to NIST. Code name: Gravity. May or may not rely on B2b and The hardest part is to design something simple enough yet fast and stateless. SPHINCS is fast and stateless but incomprehensible. Goldreich is stateless and simpler but inefficient. Looking for a middle ground.

