SHRINCS: 324-byte stateful post-quantum signatures with static backups

Why do we need to hide the iteration of a signature? Is not it visible on the chain anyways?

Is not it possible to distinguish the unbalanced version from XMSS from balanced through the authentication path length?