MAK CapitalCrypto Desk
Archive/2026-10-08Research

Quantum Readiness: Major Chains (Qrisk)

Q-Risk Pack: Every Major Chain's Path to Quantum Resistance

As of Thu 2026-10-08, 16:43 ET. Market caps come from CoinGecko (/simple/price, include_market_cap) and were pulled at 16:38 ET. Chains are sorted by those caps. On-chain stats were pulled 16:30–16:43 ET. Labels used: Fact means verified against a primary source today. Reported means it comes from press, a vendor, or a secondary source. Speculative means it is my inference. Unknown means I could not source it.

Summary

  • Ethereum is the only chain with a dated, L1-wide PQ deadline. The EF Protocol cluster (Sep 7 2026) set a target of a quantum-resistant L1 across execution, consensus and data by Dec 2029, with a reassessment in Jan 2027 (Fact). Four lean-consensus PQ devnets have already run (Fact). No PQ signature is live on mainnet.
  • Zcash is the only chain that has shipped a consensus-level quantum measure on mainnet. NU6.3 "Ironwood" activated 2026-07-28 at height 3,428,143 (Fact). It makes new notes quantum-recoverable, which is not the same as quantum-secure. The Recovery Protocol itself is still unspecified (Fact, ZIP 2005).
  • Bitcoin has specs but no activation path. BIP-360 (P2MR) and BIP-361 (legacy-signature sunset) are merged Drafts (Fact). There is no PQ-signature BIP and no activation client. Exposed supply is 31.2% per Glassnode (Oct 8 2026) and 34.45% per Project Eleven (block 950,000) (Reported).
  • Mid-caps are split. TRON (TIP-899, live on Nile testnet, "year-end" mainnet target, Reported) and Sui (ML-DSA-65 mainnet targeted Q1 2027) have dated plans. Solana has app-level Winternitz vaults and Falcon client prototypes, but its Falcon syscall SIMD was closed (Fact). Monero's FCMP++ adds forward secrecy, not PQ spend authority. Hyperliquid has no public plan.
  • The threat baseline moved left in 2026. Google Quantum AI estimates ECDLP-256 can be broken with ≤1,200 logical qubits on <500k physical qubits (Mar 31 2026, Fact). ECDSA.fail (Sep 2026) cuts point-addition circuits to 793 logical qubits (Fact). Justin Drake's "bunker mode" warning (Oct 7–8 2026) adds an AI-cryptanalysis tail risk (Reported).
  • L2s mostly inherit Ethereum's timeline. Starknet (59) leads, using STARK proofs, native AA, a mainnet Falcon-512 account and BLAKE2s OS hashes. Optimism has a 10-year ECDSA-EOA sunset plan to Jan 2036. Arbitrum has no official plan.

Scoreboard

Ranked by CoinGecko mcap (16:38 ET). Score bands: 🟢 ≥60, 🟡 35–59, 🔴 <35.

#ChainMcap (USD)ScoreBadgeStageNext milestone
1Bitcoin (BTC)$1,641.3B42🟡2: Spec drafts (BIP-360/361), no activationMove a PQ-signature BIP and an activation proposal past Draft. Date unknown
2Ethereum (ETH)$301.2B65🟢3: Dated roadmap + PQ devnetsGlamsterdam mainnet (tentative Dec 2026, Reported), then the Jan 2027 reassessment, then Hegotá with EIP-8141 Frames (expected 2027)
3Solana (SOL)$64.4B37🟡1–2: Research + app-level vaultsSIMD-0579 Keccak-p1600 syscall (open PR). No dated PQ protocol milestone
4TRON (TRX), extra L1$31.6B48🟡3: Testnet (Nile)TIP-899 mainnet SR votes, prioritizing ML-DSA-44. "Year-end 2026" target (Reported)
5Zcash (ZEC)$19.9B68🟢4: Partial mainnet (quantum-recoverable notes)Recovery Protocol spec (undated). Shielded Labs Epoch production PQ crypto by end-2027 (target)
6Hyperliquid (HYPE)$18.8B5🔴0: No public planNone announced
7Monero (XMR)$9.9B31🔴1–2: Research; FCMP++ (forward secrecy) on stressnetFCMP++/Carrot mainnet hard fork. No date
8Sui (SUI)$4.3B54🟡2–3: Dated plan, audits underwayPQ vaults on mainnet in 2026, ML-DSA accounts on testnet by end-2026, mainnet in Q1 2027 (targets)
9Ethereum L2s (group)$1.98B combined ARB+STRK+OP+ZK15–59🟡/🔴Varies (see section)Starknet Phase 2 tooling; OP scheme selection; most others follow L1

L2 group placement basis: the group is ranked by the combined mcap of ARB ($1.171B), STRK ($0.412B), OP ($0.274B) and ZK ($0.124B), which totals ≈$1.98B. Base has no token, so it contributes $0. Using the largest single token (ARB, $1.17B) gives the same rank: below SUI ($4.32B). Within the group, scores are Starknet 59, Optimism 35, zkSync 26, Base 21 and Arbitrum 15.

Extra L1 = TRON. It is #2 by stablecoin supply at $94.22B (DefiLlama, behind Ethereum's $150.77B), had 4,449,621 active accounts and 11.62M transactions on 2026-10-07 (Tronscan), and has an active PQ TIP with a live testnet.

Rubric (0–100). Applied identically to every chain.

Sub-scoreMaxWhat earns points
R: Research depth15Published threat models, papers, scheme comparisons, and core-team engagement
S: Spec / proposal15Formal BIP/EIP/SIMD/TIP/ZIP text. More points for merged, accepted, or scheduled
I: Implementation / testnet15Client code, devnets/testnets running PQ paths, audits
M: Mainnet PQ capability today20What a user can do today on mainnet. Native PQ signatures score highest; app-level vaults and recoverability earn partial credit
G: Migration plan for existing funds20Concrete path for already-exposed keys and legacy funds, such as sunset rules, recovery proofs, or key rotation
C: Governance momentum / dated commitment15Official dated targets, scheduled forks, funding, and absence of blocking disputes

Stages: 0 none · 1 research · 2 spec drafts · 3 testnet/devnet · 4 partial mainnet · 5 full PQ mainnet. Badges in tables: 🟢 done or High likelihood · 🟡 in progress or Med · 🔴 blocked, absent, or Low. Scores are my judgment applied to the sourced facts below (Speculative by nature). The sub-scores are shown so they can be re-weighted.


Bitcoin (BTC)

Snapshot

ItemDetailBadgeLabel
Mcap$1,641.27B (price $81,674)Fact (CoinGecko 16:38 ET)
Signature schemesECDSA secp256k1 (legacy/SegWit v0) and BIP-340 Schnorr (Taproot)🔴Fact
Quantum-exposedP2PK outputs, reused addresses, and Taproot key-path outputs (the tweaked key is visible on-chain). Exposed supply: 6.26M BTC / 31.2% (Glassnode, Oct 8 2026); 6,900,573 BTC / 34.45% (Project Eleven, block 950,000); 4–10M BTC (Chaincode range)🔴Reported
Exchange exposureExchanges hold 1.79M exposed BTC. Binance is 83% exposed and Coinbase 10%🔴Reported (CoinDesk/Glassnode)
PoWSHA-256. Grover gives at most a quadratic speedup, so this is not a direct break🟢Fact
OpsHeight 970,526; hashrate ≈979 EH/s (3-day, mempool.space)Fact

Readiness score: 42 / 100 🟡

RSIMGC
13105374

The deep research and two merged BIP drafts drive the score. It is held down by having no PQ signature spec, no activation path, and only a nonstandard workaround on mainnet.

Completed milestones

DateMilestoneBadgeLabel
2024-12-18BIP-360 number assigned (then P2QRH; authors Hunter Beast, Ethan Heilman, Isabel Foxen Duke)🟢Fact
2025-07-07BIP-360 v0.8.0 drops the key path and moves PQ signatures to future opcodes🟢Fact
2025-09-17BIP-360 v0.10.0 is renamed P2TSH🟢Fact
2026-02-11BIP-360 merged into bitcoin/bips as Draft (#1670), renamed P2MR (v0.11.0)🟢Fact
2026-02-11 / 2026-04-14BIP-361 "Post Quantum Migration and Legacy Signature Sunset" (Lopp et al.) is assigned, then merged as Draft🟢Fact
2026-03-31Google Quantum AI publishes ECDLP resource estimates for secp256k1🟢Fact
2026-06-18 / 2026-07-24BIP-360 v0.12.0 (depth-zero trees made anyone-can-spend) and v0.12.1🟢Fact
2026-07-21Galaxy Bitcoin Quantum Readiness Initiative offers up to $5M in milestone grants🟢Fact
2026-07-23Bitcoin Security Consortium: nine institutions (BlackRock, Fidelity Digital Assets, Coinbase, Strategy, Block, Blockstream, etc.) pledge $15M over 3 years. It takes no protocol positions and is coordinated by Mike Schmidt (Brink)🟢Fact
2026-07-28Independent BIP-360 regtest implementation in Bitcoin Core posted on Delving Bitcoin🟢Reported
2026-08-03Latest BIP-360 edits merged (#2223)🟢Fact
2026-08-26StarkWare QSB (Avihu Levy): first quantum-safe tx mined on mainnet with no soft fork. It is nonstandard, was submitted via MARA Slipstream, and took hours of GPU grinding🟢Fact (StarkWare); cost is Reported

Active proposals

ProposalStatusLikelihoodBadgeReason
BIP-360 P2MR (Pay-to-Merkle-Root)Draft, consensus soft fork, mergedMed to eventual activation🟡It is the most mature output-type proposal, has a Core regtest implementation, and has support from investors such as Ben-Sasson ("should happen, and I believe it will", Reported). But it adds no PQ signature itself and has no activation mechanism or date
BIP-361 Legacy Signature SunsetDraft. Phase A bans sends to vulnerable outputs 160,000 blocks (about 3 yrs) after activation. Phase B restricts ECDSA/Schnorr spends 2 yrs laterLow within 24 mo🔴It requires a not-yet-written PQ signature BIP, and freezing coins is the most contentious idea in Bitcoin governance (Speculative)
SHRINCS / OP_CHECKSHRINCS (Blockstream)Research. The draft repo is not a numbered BIP. It has a 324-byte stateful signature path and a larger stateless fallback, and was demonstrated on Liquid via SimplicityLow–Med🟡It is the leading hash-based candidate for the missing signature opcode, but has no BIP number
ML-DSA/SLH-DSA opcodesNo BIP. A third-party BTQ Technologies testnet v0.3.0 (Mar 2026) has ML-DSA opcodesLow🔴It is a fork-chain experiment, not Core (Reported)

Roadmap

HorizonWhatLabel
Past2024–25: P2QRH evolves into P2TSH. 2026: P2MR merged, BIP-361 merged, consensus funding consortia formedFact
NowP2MR is in Draft with regtest code. QSB is a costly opt-in hack for new coins only. Glassnode and Project Eleven are tracking exposureFact
Next 12–24 moExpect a PQ-signature BIP (SHRINCS-style or SLH-DSA) to be numbered, and activation-mechanism debate. Soft-fork activation within 24 months is unlikelySpeculative
Longer termP2MR plus a PQ opcode soft fork, followed by BIP-361-style sunset debates over Satoshi-era P2PK coinsSpeculative

Risks and open questions

  • About 1.9M BTC is structurally exposed (P2PK, early coins; Glassnode May 2026 put it at 1.92M) and cannot be protected by its owners if the keys are lost. Whether those coins get frozen is unresolved (Reported).
  • Binance's 83% exposure rate means a single exchange's hygiene drives a large share of the operational exposure (Reported).
  • Activation politics: there is no activation client or signaling plan, and the 2017-style dispute risk is untested for a freeze proposal (Speculative).
  • Signature size and block weight: PQ signatures are 10–100x the size of Schnorr. The fee-market impact is unquantified on-chain (Unknown).

Ethereum (ETH)

Snapshot

ItemDetailBadgeLabel
Mcap$301.23B (price $2,466.78)Fact
Execution signaturesECDSA secp256k1 (EOAs). Precompiles: ecrecover, BN254 pairings (used by ZK rollups), and BLS12-381🔴Fact
ConsensusBLS12-381 aggregate signatures🔴Fact
DataKZG commitments (blobs)🔴Fact
Quantum-exposedEvery EOA that has ever sent a transaction. Estimated 50–65% of supply, most defensibly 55–60% (arXiv 2606.14484, Jun 2026). Deloitte's 2021 figure of >65% is the root of most press numbers. EF estimates long-dormant ETH at ≈0.1%🔴Reported
Ops854,739 active validators; 43.7M ETH staked (35.78%) per validatorqueue.comReported (aggregator)

Readiness score: 65 / 100 🟢

RSIMGC
15121141013

The score comes from an official dated target, a named fork sequence, multi-client PQ devnets and the AA rails (EIP-8141). It is held down because no PQ signature is native on mainnet. Smart-contract wallets can verify PQ signatures only at high gas cost.

Completed milestones

DateMilestoneBadgeLabel
2025-10-06pq-devnet-0 (lean consensus, hash-based leanSig/XMSS)🟢Fact (leanEthereum/pm)
2026-01-20pq-devnet-1🟢Fact
2026-02Vitalik's PQ roadmap post (Feb 2026), referenced on pq.ethereum.org🟢Reported
2026-02-27pq-devnet-2🟢Fact
2026-03-26pq-devnet-3🟢Fact
2026-06-27pq.ethereum.org updated. It lists a $20M zkEVM formal-verification effort and the ≈0.1% dormant-ETH estimate🟢Fact
2026-08-19Strawmap update. I*: PQ key registry. J*: minimum-viable PQ (PQ heartbeat, leanDA, leanSPHINCS txs). L* (or K*): PQ attestations. M*: PQ aggregation and PQ blobs🟢Reported
2026-09-07EF Protocol "Current and Emerging Priorities": L1 to be quantum-resistant by Dec 2029, planning for Q-day as early as 2030. The target is non-negotiable until the Jan 2027 reassessment🟢Fact
2026-10-06Glamsterdam activates on Sepolia (13:53 UTC / 09:53 ET)🟢Fact (EF blog)

Active proposals

ProposalStatusLikelihoodBadgeReason
EIP-8141 Frame Transactions (native AA)SFI'd as a Hegotá headliner. Expected in 2027High🟢EF designates it must-ship. It lets accounts swap ECDSA for PQ verification
EIP-7805 FOCILHegotá headlinerHigh🟢Not PQ itself. It is protected because PQ milestones are sequenced behind it
EIP-8365 Disallow new 0x00 validatorsCFI'd for Hegotá (ACDC #188), scope narrowedMed🟡Hygiene step toward withdrawal-credential migration. CFI is not SFI
EIP-8151, EIP-8298 (account-related, Hegotá candidates)Under discussionMed🟡Their scope and final inclusion are not settled (Reported)
EIP-8051 ML-DSA precompile / EIP-8052 Falcon precompileDraftMed🟡Would make PQ verification gas-practical. Not yet scheduled for a fork
Strawmap I*/J*/L*/M* PQ forksPlanning artifacts, not EIPsMed to hit Dec 2029🟡The fork cadence it needs (about 7.2 months) has never been achieved historically (Speculative)

Roadmap

HorizonWhatLabel
Past2018-era research into hash-based signatures and STARKs. 2025–26 lean consensus and four PQ devnetsFact
NowGlamsterdam on testnets (mainnet tentatively Dec 2026; officially TBD). Hegotá scoping. pq-devnet-4 (proposer keys, recursive aggregation) was being specced, current status unverifiedFact / Unknown
Next 12–24 moJan 2027 target reassessment; Hegotá (Frames + FOCIL) in 2027; PQ key registry (I*) spec workReported
Longer termJ* minimum-viable PQ fallback, then L* PQ attestations, then M* PQ aggregation and blobs. Goal: PQ across execution, consensus and data by Dec 2029Fact (target)

Risks and open questions

  • Fork-cadence risk: the Dec 2029 target needs roughly five forks in three years (Speculative).
  • Vitalik warned that botched migrations cause losses. Rushing EOA migration could create phishing and loss events (Reported).
  • PQ signature sizes vs. consensus bandwidth: leanMultisig/leanVM aggregation is unproven at mainnet scale (Speculative).
  • Justin Drake's "bunker mode" (Oct 2026) argues AI could break ECDSA before quantum computers do and advises moving to never-exposed addresses. No practical attack has been shown (Reported).
  • ZK rollups and bridges that rely on BN254/KZG precompiles inherit the L1 schedule (Fact).

Solana (SOL)

Snapshot

ItemDetailBadgeLabel
Mcap$64.36B (price $109.23)Fact
Signature schemesEd25519 for accounts and transactions. Validators sign votes with Ed25519 today. Alpenglow adds BLS vote signatures, a new quantum-vulnerable surface🔴Fact
Quantum-exposedEvery non-PDA address is an Ed25519 public key, so effectively all funded wallets are exposed from creation. PDAs have no private key🔴Fact
Ops671 current + 10 delinquent vote accounts (getVoteAccounts). getAgGenesisCert = null at 16:43 ET, meaning mainnet still runs TowerBFT and Alpenglow is not activeFact

Readiness score: 37 / 100 🟡

RSIMGC
1157743

App-level vaults are live, and two clients have Falcon prototypes. There is no active PQ SIMD beyond a hash syscall, the migration plan is conditional ("if the threat becomes credible"), and there are no dates.

Completed milestones

DateMilestoneBadgeLabel
2024 (live for >2 yrs)Blueshift Solana Winternitz Vault (hash-based one-time signatures, user-level), later cited by Google🟢Reported
2025-12Project Eleven PQ testnet for Solana🟢Reported
2026-02-01SIMD-0461 (Falcon verification syscall) PR opened🟢Fact
2026-04-27solana.com "Quantum readiness": Anza and Firedancer independently chose Falcon and have initial implementations🟢Fact (post) / Reported (implementations)
2026-07-08SIMD-0387 BLS pubkey registration live on mainnet (Alpenglow prerequisite). VAT (SIMD-0357) followed on 2026-07-22🟢Reported (solana.com/upgrades)
2026-07-27SIMD-0563 Keccak-p1600 syscall closed in favor of SIMD-0579🟢Fact
2026-09-01SIMD-0461 Falcon syscall closed without merge🔴Fact

Active proposals

ProposalStatusLikelihoodBadgeReason
SIMD-0579 Keccak-p1600 syscallOpen PR since 2026-07-09Med🟡A cheaper permutation helps hash-based and Falcon (SHAKE) verifiers in programs. It is generic infrastructure with no PQ mandate
Falcon verification syscall (SIMD-0461)Closed 2026-09-01Low in the near term🔴Closed. Blueshift's solana-falcon512 and solana-hawk512 already run as programs without protocol changes
Jump Crypto migration design (PQ key + ZK proof of Ed25519 seed possession)Research postMed long term🟡A credible path for exposed wallets, but it is not a SIMD. Note: Jump cites "SIMD-0416" for the Falcon syscall, but GitHub PR #416 is a SIMD-0387 change. The Falcon syscall was PR #461 (discrepancy)
Alpenglow Votor (SIMD-0326)Live on testnet/devnet. Mainnet date unknownHigh to ship, but it adds BLS🔴It increases the classical-crypto surface in consensus

Roadmap

HorizonWhatLabel
PastWinternitz vaults (user-level), Falcon prototypesReported
NowResearch. Hash-syscall SIMD in review. Alpenglow rolloutFact
Next 12–24 moPer solana.com: PQ for new wallets "if the threat becomes credible," then migration. No datesFact (stated plan)
Longer termFalcon-based accounts and some PQ consensus aggregation (aggregate lattice signatures are still research per Jump)Reported

Risks and open questions

  • Address = public key means no "hash shield." Exposure is close to 100% of non-PDA balances (Fact by construction).
  • BLS in Alpenglow will need its own PQ replacement later (Speculative).
  • The roadmap is conditional on a threat trigger, so lead time depends on how quickly the trigger can be recognized (Speculative).

TRON (TRX), extra L1

Why TRON: #2 chain by stablecoin supply ($94.22B, DefiLlama, pulled today); 4,449,621 active accounts and 11.62M transactions on 2026-10-07 (Tronscan); has an active consensus-level PQ TIP.

Snapshot

ItemDetailBadgeLabel
Mcap$31.61B (price $0.3327)Fact
Signature schemesECDSA secp256k1 for accounts and for the 27 Super Representatives' block signing🔴Fact
Quantum-exposedAny address that has sent a transaction (pubkey recoverable from signature). This includes major USDT hot wallets🔴Fact (mechanism) / exposure % Unknown
Ops5,121 nodes; height 86,938,662; 2.26M USDT transfers on 2026-10-07; TVL $5.58BFact (Tronscan, DefiLlama)
Usage (reported)$2.08T Q2 2026 stablecoin volumeReported (CoinLaw citing TRON Q2 report)

Readiness score: 48 / 100 🟡

RSIMGC
91211079

A detailed TIP and a live testnet drive the score. It is held down because nothing is on mainnet, the mainnet date has already slipped, and the audit plan is undetermined.

Completed milestones

DateMilestoneBadgeLabel
2026-04Justin Sun states a Q3 2026 mainnet target🟡Reported
2026-06-30TIP-899 created (author Federico2014). FN-DSA-512 + ML-DSA-44 for transactions, SR block signing, and the network handshake; TVM precompiles 0x02000016–0x0200001a🟢Fact
2026-07-02PQ enabled on Nile testnet (GreatVoyage-v4.8.2-PQ1, committee proposal 20628)🟢Reported
2026-07-20Devs: prioritize ML-DSA for mainnet, Falcon waits for FIPS 206; third-party audit plan "not determined"🟢Fact (TIP thread)
2026-08-11Phase 2 key-registry V2 design posted🟢Fact (TIP thread)
2026-08-27Sun at Bitcoin Asia: target slips to year-end 2026🟡Reported

Active proposals

ProposalStatusLikelihoodBadgeReason
TIP-899 Phase 1: ALLOW_ML_DSA_44 (#1001)Draft. Needs a 27-SR committee vote; disabled by defaultMed for mainnet by end-2026🟡Strong founder push and a working Nile build. Undetermined audit, plus Nile gaps (no gas-free transfers, no BIP-39 recovery, no Ledger)
TIP-899: ALLOW_FN_DSA_512 (#1000)DraftLow by end-2026🔴Devs said it waits for FIPS 206, which is not final
Phase 2: key registry (rotate ECDSA → PQ)Design V2 (Aug 11)Med within 24 mo🟡Required for existing funds. Design-only
Later phases: emergency SR channel, FORBID_ECDSA_SIGN, ZK recoveryConcepts in TIP discussionLow within 24 mo🔴Unspecified
ML-DSA-65 instead of -44 (shemnon suggestion)CommentLow–Med🟡Security-margin debate is open

Roadmap

HorizonWhatLabel
PastNo PQ work before 2026 foundUnknown
NowNile testnet with both schemes; TIP-899 DraftFact
Next 12–24 moML-DSA-44 mainnet vote (target year-end 2026), then the key registryReported
Longer termECDSA prohibition plus ZK recovery for exposed accountsReported (TIP discussion)

Risks and open questions

  • Throughput: reports say PQ signatures could cut TPS by up to 95% in testing (Reported, Coindoo). This has not been verified independently.
  • Concentrated governance (27 SRs) makes activation fast but also concentrates the decision (Fact on structure).
  • Some wallets may be able to pay but not replace keys under the current design (Reported).
  • No audit commitment yet (Fact as of Jul 20).

Zcash (ZEC)

Snapshot

ItemDetailBadgeLabel
Mcap$19.89B (price $1,171.96)Fact
Signature / proof systemsTransparent: ECDSA secp256k1. Sapling: RedJubjub + Groth16 (BLS12-381). Orchard: RedPallas + Halo 2 (Pasta). Ironwood: quantum-recoverable notes (lead byte 0x03)🟡Fact
Quantum-exposedTransparent pubkeys. Shielded privacy (ECDH note encryption, harvest-now-decrypt-later). Soundness (proof forgery means counterfeiting in shielded pools). Sapling and Orchard funds that are never migrated to Ironwood are unrecoverable under the recovery model🔴Fact (ZIP 2005)
OpsHeight 3,511,013. Zebra is the only full validator supporting NU6.3 (zcashd does not)Fact

Readiness score: 68 / 100 🟢

RSIMGC
14131081211

This is the only chain here with a consensus change on mainnet aimed at the quantum transition, plus a written migration model. It is held down because recoverability is not PQ security, the Recovery Protocol is unspecified, and Tachyon's Ragu stack is unaudited.

Completed milestones

DateMilestoneBadgeLabel
2026-02Polls back quantum recoverability: 90.5% ZCAP, 94.6% coinholders🟢Reported
2026-05-22Tachyon testnet release candidate🟢Reported
2026-05-29 / 06-02 / 06-03Orchard soundness bug (halo2_gadgets missing copy constraint, CVE-2026-54496) found by Taylor Hornby. Emergency soft fork disabled Orchard on Jun 2. NU6.2 re-enabled it with the fix on Jun 3🟢Fact (ZF, GHSA)
2026-07-28 14:07 UTC (10:07 ET)NU6.3 "Ironwood" activates at height 3,428,143. New shielded value goes to the Ironwood pool with quantum-recoverable notes (ZIP 2005); Orchard becomes spend-only🟢Fact
2026-09-15ZIP 259 (NU7 deployment) published: 25s blocks, v4 txs disallowed (Sprout becomes unspendable). No quantum content🟢Fact
2026-10-01Shielded Labs announces Epoch (Haböck, Edwards, Bagad): formally verified PQ crypto, production-ready by end-2027 (target)🟢Fact (forum)

Active proposals

ProposalStatusLikelihoodBadgeReason
ZIP 2005 Ironwood Quantum RecoverabilityStatus: Proposed. Deployed via NU6.3High (already live)🟢Activated on mainnet
Recovery Protocol (spend Ironwood notes after ECC is disabled)Not specified or deployedMed within 24 mo🟡Explicitly future work in ZIP 2005
Three-step plan: recoverability → ML-KEM with Tachyon → fully PQ poolStep 1 done; Step 2 on testnetMed🟡Development is spread across ZODL, Tachyon, Valar, ZF and Shielded Labs. Ragu is unaudited
Shielded Labs EpochPhase 1 researchMed for the end-2027 target🟡Strong team. Scope "may be narrower than Tachyon"
NU7 (ZIP 259)Mainnet height "TBD (to be set on Oct 20)"High to ship; not PQ🟢Relevant only because it ends Sprout

Roadmap

HorizonWhatLabel
PastSprout bug (2018), Orchard bug (2026), quantum-recoverability pollsFact
NowIronwood live. Users need to migrate Sapling/Orchard funds into Ironwood to be recoverableFact
Next 12–24 moNU7 (non-PQ); Recovery Protocol spec; Tachyon with ML-KEM note encryption; Epoch design proposalReported
Longer termFully PQ shielded pool and formally verified PQ proving systemReported (plan)

Risks and open questions

  • Two critical soundness bugs in shielded pools (2018, 2026) show implementation risk is at least as large as quantum risk (Fact).
  • There is now a single full-validator implementation (Zebra) for NU6.3+ (Fact).
  • Migration burden: unmigrated Sapling/Orchard value is unrecoverable in the recovery model, and the share already migrated is Unknown.
  • Harvest-now-decrypt-later: historical shielded transactions remain exposed to future decryption until ML-KEM ships (Fact by design).

Hyperliquid (HYPE)

Snapshot

ItemDetailBadgeLabel
Mcap$18.77B (price $84.37)Fact
Signature schemesHyperCore actions: EIP-712 secp256k1 ECDSA. HyperEVM: ECDSA. HyperBFT validator signatures: undocumented (reverse-engineered docs suggest secp256k1)🔴Fact / Unknown
Quantum-exposedEvery account that has signed an action; bridge validator keys🔴Speculative (mechanism)
Ops35 validators, 27 active, 29 not jailed (Hyperliquid info API)Fact

Readiness score: 5 / 100 🔴

RSIMGC
200300

Completed milestones

DateMilestoneBadgeLabel
2026-06qLABS qVAULT: third-party Falcon (FN-DSA) vault on HyperEVM (early access, then commercial availability). qLABS is a vendor, so treat its claims as marketing🟡Reported
No official Hyperliquid or Hyper Foundation PQ statement found (X search of @HyperliquidX, @chameleon_jeff, @hyperfnd returned 0 results)🔴Fact (search result)

Active proposals

ProposalStatusLikelihoodBadgeReason
None public🔴No HIP or roadmap item found

Roadmap

HorizonWhatLabel
Past / NowECDSA everywhere; one third-party vaultFact / Reported
Next 12–24 moUnknownUnknown
Longer termCould follow the EVM AA patterns via HyperEVMSpeculative

Risks and open questions

  • Closed-source core plus an undocumented consensus signature scheme makes external assessment impossible (Fact).
  • The small validator set (27 active) controls the bridge. Quantum or AI key recovery against those keys would be systemic (Speculative).

Monero (XMR)

Snapshot

ItemDetailBadgeLabel
Mcap$9.90B (price $525.99)Fact
Signature / proof systemsEd25519-family keys; CLSAG ring signatures; Bulletproofs+; ECDH one-time addresses; key images🔴Fact
Quantum-exposedPrivacy (retroactive de-anonymization through ECDH), soundness (inflation via forged proofs), spend authority🔴Fact (MRL issues #151/#159)
PoWRandomX (not ECC-based)🟢Fact
OpsHeight 3,779,811; hashrate ≈6.34 GH/s; hard-fork version 16 (xmrchain.net)Fact

Readiness score: 31 / 100 🔴

RSIMGC
1166053

Completed milestones

DateMilestoneBadgeLabel
2025-11-27jeffro256 PQ "turnstile" gist: a migration path for Carrot-derived enotes only, not legacy RingCT🟢Reported
2026-04 to 2026-06Jamtis-PQ draft (tevador, CSIDH-1024 encryption, about 400-character addresses) and MRL discussion updates🟢Reported
2026-09-25FCMP++ & Carrot beta stressnet v3.0 (v0.19.0.0-beta.3.0) released🟢Fact
2026-10-05Stressnet fork at block 3,102,800🟢Reported

Active proposals

ProposalStatusLikelihoodBadgeReason
FCMP++ + Carrot hard forkStressnet. Integration audit CCS !663. No mainnet dateHigh to ship eventually (date unknown)🟡Gives forward secrecy for privacy. Spend authorization stays Ed25519, so it is not PQ
Jamtis-PQ addressingDraftLow–Med within 24 mo🟡Large addresses; MRL still debating
PQ turnstile (Carrot enotes)GistLow within 24 mo🔴Excludes legacy RingCT outputs
PQ signatures (MRL #159) / PQ encryption (MRL #151)Open research issuesLow🔴No candidate construction chosen

Roadmap

HorizonWhatLabel
PastMRL research issues openedFact
NowFCMP++/Carrot stressnetFact
Next 12–24 moFCMP++ mainnet (no date); Jamtis-PQ decisionSpeculative
Longer termPQ turnstile and PQ spend authorityReported (research)

Risks and open questions

  • Privacy coins face harvest-now-decrypt-later on all historical transactions. Forward secrecy only protects new Carrot outputs (Fact by design).
  • Inflation detection under a quantum adversary is unsolved for legacy outputs (Reported, MRL).
  • The FCMP++ timeline has repeatedly been "when ready" with no date (Fact).

Sui (SUI)

Snapshot

ItemDetailBadgeLabel
Mcap$4.32B (price $1.05)Fact
Signature schemesUsers: Ed25519, secp256k1, secp256r1/passkey, multisig, zkLogin. Validators: BLS12-381 (not re-verified this session)🔴Fact (users) / Unknown (validators)
Quantum-exposedAddresses are hashes, but the public key is exposed on first use. zkLogin relies on a pairing-based SNARK🔴Fact (Sui blog)
Ops127 active validators, epoch 1274 (Sui GraphQL)Fact

Readiness score: 54 / 100 🟡

RSIMGC
1210731111

The score is driven by the chosen NIST schemes, dated targets and an in-place key-rotation path. It is held down because nothing PQ is on mainnet yet.

Completed milestones

DateMilestoneBadgeLabel
2025Mysten-affiliated paper "Post-Quantum Readiness in EdDSA Chains" (eprint 2025/1368): a zk proof of seed possession for EdDSA. Deployment deferred🟢Fact (paper) / Reported (deferral)
2026-07Sui blog: an AI model halved HAWK key strength in about 60h, which informed the scheme choice🟡Reported
about 2026-08-06"Making Sui Quantum Ready" and "From the cryptographer's desk": ML-DSA-65 native accounts and SLH-DSA-SHA2-128s Move vaults. Address aliases let accounts rotate keys without moving funds. ML-DSA-65 is also supported in multisig. Audits underway🟢Fact (blog)

Active proposals

ProposalStatusLikelihoodBadgeReason
SLH-DSA vaults (Move)Targeted for mainnet in 2026Med for 2026🟡Contract-level, so lower protocol risk, but less than 3 months remain
ML-DSA-65 native accountsTestnet by end-2026, mainnet Q1 2027Med–High🟡Single foundation-led governance; audits underway
Address-alias rotation for existing accountsDescribed in the blogMed🟡Mainnet status of aliases not independently verified (Unknown)
PQ validator signatures / zkLogin PQNot announcedLow🔴No public plan

Roadmap

HorizonWhatLabel
PastEdDSA seed-proof researchFact
NowAudits; vault and account implementationsReported
Next 12–24 moVaults on mainnet (2026), ML-DSA on testnet (end-2026), on mainnet (Q1 2027)Fact (targets)
Longer termConsensus and zkLogin migrationUnknown

Risks and open questions

  • Validator BLS and zkLogin are not covered by the announced plan (Fact by omission).
  • ML-DSA-65 signatures (3,309 bytes per FIPS 204) increase transaction size and storage (Fact on size; throughput impact Unknown).

Ethereum L2s (grouped)

Group mcap: combined ARB+STRK+OP+ZK ≈ $1.98B. The largest token is ARB at $1.171B. Base has no token. Either basis ranks the group below SUI. Shared dependency: all five settle to Ethereum L1. Their bridges, blob data (KZG) and any L1 ECDSA/BLS signer inherit Ethereum's Dec 2029 timeline (Fact).

Arbitrum (ARB, $1.171B): score 15 🔴

ItemDetailBadgeLabel
SignaturesECDSA EOAs; ECDSA sequencer and batch poster🔴Fact
Sub-scoresR 5 · S 1 · I 3 · M 4 · G 2 · C 0
Done2026-06-30 community forum technical overview of PQ risk in Arbitrum contracts. Stylus ML-DSA-65 verifier PoC at about 374,000 gas (unaudited)🟡Reported
ResearchOffchain Labs researchers' eprint 2026/1660 "Transient Quantum Resistance" (on Ethereum BLS)🟢Fact (paper)
ProposalsNo AIP or official roadmap found. Likelihood of an official plan within 12 mo: Low–Med🔴Fact (absence) / Speculative
RoadmapNow: PoCs only. Next 12–24 mo: Unknown. Longer term: follow the L1 AA path (Speculative)
RisksNo dated commitment; Stylus contracts need reactivation after 365 days or ArbOS upgrades (Reported)

Base (no token): score 21 🔴

ItemDetailBadgeLabel
SignaturesECDSA EOAs; ECDSA sequencer (OP Stack lineage)🔴Fact
Sub-scoresR 5 · S 3 · I 4 · M 3 · G 3 · C 3
Done2026-07-23 Coinbase blog: Base inherits Ethereum's PQ roadmap and a Base-specific plan is to come. PQ-CoreKMS (custody, not Base) is targeted within a year🟢Fact
Done2026-09-30 Cobalt mainnet: validity transactions, B20, dynamic upgrades, TEE registration. No PQ feature in the official overview🟢Fact
ProposalsEIP-8130 native AA (pluggable verifiers) is documented for Base's "vibenet" dev network. Inclusion in Cobalt mainnet is unverified. Likelihood within 24 mo: Med🟡Reported
Third partyPQ1 hardware wallet (FreedomFactory) USDC transfer on Base on 2026-09-21🟡Reported
RoadmapNext 12–24 mo: concrete Base plan (undated). Longer term: inherit L1Reported
RisksCentralized sequencer key, plus TEE attestation chains that are themselves ECDSA-based (Speculative)

Optimism / OP Stack (OP, $0.274B): score 35 🟡

ItemDetailBadgeLabel
SignaturesECDSA EOAs; ECDSA sequencer and batcher🔴Fact
Sub-scoresR 7 · S 5 · I 3 · M 3 · G 9 · C 8
Done2026-01-14 Karl Floersch, "A Post-Quantum Roadmap for the Superchain": deprecate ECDSA EOA transactions by Jan 2036 (subject to governance) through EIP-7702 delegation to PQ smart accounts; dual ECDSA/PQ period; sequencer and batcher to migrate; scheme undecided🟢Fact
Done2026-02-27 OP 2026 roadmap aligned with Ethereum's strawmap🟢Reported
ProposalsScheme selection and the PQ smart-account standard: not yet specified. Likelihood within 24 mo: Med🟡Speculative
RisksThe 10-year horizon is long relative to Google/EF Q-day planning (2030) (Speculative)

zkSync (ZK, $0.124B): score 26 🔴

ItemDetailBadgeLabel
SignaturesNative AA (accounts can define custom verification); default ECDSA🟡Fact
Sub-scoresR 6 · S 3 · I 6 · M 6 · G 3 · C 2
DoneAirbender STARK/FRI prover (hash-based, PQ-friendly). The final on-chain proof is an FFLONK SNARK over BN254/KZG, which is not PQ🟡Fact (zkSync docs, L2BEAT)
ClaimX post 2026-01-24 says the prover is "100% PQ-proof". True for the inner STARK, not the L1 wrapper🟡Reported
ProposalsNone found for replacing the wrapper. Likelihood within 24 mo: Low–Med🔴Unknown
RisksProof forgery against the BN254 wrapper means invalid state could be finalized on L1 (Fact by construction)

Starknet (STRK, $0.412B): score 59 🟡

ItemDetailBadgeLabel
SignaturesNative AA. Default Stark-curve ECDSA (vulnerable). STARK proofs verified on L1 with hash-based verifiers🟡Fact
Sub-scoresR 13 · S 9 · I 10 · M 10 · G 8 · C 9
Done2026-06-30 StarkWare 3-phase PQ roadmap. Phase 1: BLAKE2s replaces Pedersen. Phase 2: legacy-storage migration tooling. Phase 3: depends on Ethereum (bridge secp syscalls, KZG blobs)🟢Fact
Done2026-07-22 OpenZeppelin Falcon-512 account executes a live mainnet transfer. An S2morrow Falcon account also exists🟢Reported
Donev0.14.3: BLAKE2s for OS program/config hashes on mainnet (migration register updated 2026-08-19). Trie and address-derivation changes not yet live🟢Fact
ProposalsPhase 2 tooling (research). Likelihood within 24 mo: Med. Ben-Sasson has floated Starknet becoming an L1 with a 2027 PQ target🟡Fact / Reported (L1 idea, Speculative outcome)
RisksPhase 3 is gated on Ethereum. Default accounts remain ECDSA until users opt in (Fact)

Cross-chain takeaways

  1. Hash-based is winning at the base layer, lattice at the account layer. ETH lean consensus uses XMSS/leanSig, BTC's leading candidate is SHRINCS/SLH-DSA, and Sui vaults use SLH-DSA. Accounts on Sui, TRON, Solana prototypes and Starknet use ML-DSA or Falcon (Fact). The pending FIPS 206 (Falcon) is a gating item for TRON's FN-DSA and some Solana designs (Fact).
  2. Account abstraction is the migration rail. Chains with native AA or key rotation (Starknet, zkSync, Sui aliases, ETH via EIP-8141/7702, TRON's key registry) can move users without moving funds. Bitcoin and Monero cannot, so they need new output types and turnstiles (Fact by design).
  3. Exposure measurement is diverging. BTC estimates range from 31.2% (Glassnode) to 34.45% (Project Eleven) and 20–50% (Chaincode). ETH estimates of 50–65% trace back to a 2021 Deloitte figure. Treat any single "% exposed" number as methodology-dependent (Reported).
  4. Dated commitments now exist in four places: ETH (Dec 2029), Sui (Q1 2027), TRON (year-end 2026, already slipped once), and OP (Jan 2036). Zcash has a dated end-2027 crypto target from one org. Bitcoin, Solana, Monero, Hyperliquid, Arbitrum and zkSync have none (Fact).
  5. New classical surfaces keep being added. Solana's Alpenglow BLS, zkSync's BN254 wrapper, Ethereum KZG blobs and Sui's zkLogin SNARK all add pairing-based dependencies that will need their own migration (Fact).
  6. Implementation bugs and AI cryptanalysis compete with quantum as the near-term risk. Examples: the Zcash Orchard bug, AI weakening HAWK, and Drake's "bunker mode" warning (Reported).

Timeline of expected milestones

WhenChainMilestoneBadgeLabel
2026-10-20ZECNU7 mainnet activation height to be set (non-PQ; ends Sprout)🟡Fact (ZIP 259 text)
Late Oct 2026ETHGlamsterdam on Hoodi🟡Reported (tentative)
Dec 2026ETHGlamsterdam mainnet (official schedule says TBD)🟡Reported (tentative)
By end-2026SUISLH-DSA vaults on mainnet; ML-DSA-65 accounts on testnet🟡Fact (target)
By end-2026TRXTIP-899 PQ mainnet (ML-DSA-44 first)🟡Reported (target; slipped from Q3)
Jan 2027ETHEF reassessment of the Dec 2029 PQ target🟡Fact
Q1 2027SUIML-DSA-65 accounts on mainnet🟡Fact (target)
2027ETHHegotá: EIP-8141 Frame Transactions + FOCIL🟡Reported (expected)
2027STRKFloated PQ L1 target🔴Speculative
End-2027ZECShielded Labs Epoch production-ready PQ crypto🟡Fact (target)
UndatedBTCPQ-signature BIP; BIP-360 activation; BIP-361 Phase A (+160,000 blocks after activation)🔴Unknown
UndatedXMRFCMP++/Carrot mainnet🟡Unknown
UndatedSOLPQ for new wallets "if the threat becomes credible"🔴Unknown
Dec 2029ETHL1 quantum-resistant across execution, consensus and data🟡Fact (target)
End-2030 / end-2031US federal (context)EO 14412: PQ key establishment / signatures across federal systems🟡Reported (via Sui blog)
Jan 2036OPECDSA EOA transactions deprecated (subject to governance)🟡Fact (target)

WHAT COULD I BE WRONG ABOUT?

  • Scores are judgment calls. Zcash outranks Ethereum only because shipped mainnet changes are weighted at 20+20 points. Weighting dated commitments more heavily would flip them. The sub-scores are shown so they can be re-weighted.
  • Timelines from founders slip. TRON already moved from Q3 to year-end, and Sui's "2026" vault target has under 3 months left. Glamsterdam's December date is tentative, and the official schedule says TBD.
  • Exposure figures are methodology-driven. The Glassnode 31.2%, Project Eleven 34.45% and ETH 55–60% figures all count visible pubkeys, not economically attackable coins. Project Eleven's filtered "attractive" set is only 351,654 BTC (Reported).
  • Threat timing could move either way. Google's <500k-physical-qubit estimate and ECDSA.fail's 793-logical-qubit point-addition circuit are resource estimates, not demonstrations. ECDSA.fail's figure is per point-addition, not a full attack. AI-cryptanalysis warnings (Drake) are unproven.
  • I may have missed non-public or non-English work, especially for Hyperliquid (closed source), Arbitrum (no official plan found) and Solana client repositories.
  • Some items are unverified. These include the Base EIP-8130 mainnet status, the Sui validator signature scheme, the Sui address-alias mainnet status, the pq-devnet-4 status, the HyperBFT signature scheme, and the Nile build and proposal numbers (from press).
  • The extra-L1 choice is debatable. BNB ($97.5B) and XRP ($86.8B) are larger by mcap. TRON was picked on usage (stablecoin settlement) plus active PQ work. Using pure mcap would favor BNB.
Sources / technical notes

Market and on-chain data (pulled 2026-10-08, 16:30–16:43 ET)

Threat baseline and standards

Bitcoin

Ethereum

Solana

TRON

Zcash

Hyperliquid

Monero

Sui

L2s

Technical notes

  • CoinGecko last_updated_at = 1791491818. Box clock at pull: 16:38:39 EDT.
  • Solana getAgGenesisCert returned null at 16:43 ET, meaning mainnet is on TowerBFT.
  • Sui stats came from GraphQL (JSON-RPC is deprecated).
  • The ETH validator count came from an aggregator because beaconcha.in requires an API key.
  • Blockchair confirms Zcash block 3,428,143 at 14:07 UTC (10:07 ET) on 2026-07-28.