About
About the Hardy Index
The Hardy Index is an independent readiness benchmark. It scores how prepared each major blockchain is for the quantum-computing threat, and nothing else.
Why this exists
In March 2026 a Google Quantum AI paper cut the estimated resources needed to break the elliptic-curve cryptography behind most blockchains by roughly a factor of twenty. Since then "which blockchain is quantum-safe?" has stopped being a specialist question. The answers circulating are mostly listicles and project marketing, and several of them are simply out of date. IOTA, for example, is still widely described as quantum-resistant on the strength of a signature scheme it removed in 2021.
A question that people are asking daily deserves a neutral referee: one place that rates every chain against the same published rubric, sources every claim, and says plainly when it is making a judgement call.
Neutrality statement
These are commitments, not aspirations. If we break one, we have failed at the only job.
- We rate; we do not recommend. Nothing on this site is investment advice, and no page tells you what to buy, sell or hold. A high Hardy Score is a statement about cryptography, not about an asset.
- No chain can pay for a rating, a review or a position. There is no paid placement, no sponsored profile and no expedited review. The methodology applies identically to every chain in the index.
- No affiliate links, no advertising and no referral revenue anywhere in the index. The ranking, the methodology and every chain profile are clean. The guides, which are a separate part of the site, carry disclosed affiliate links and labelled sponsorship, and neither can influence a score, a tier or a position. That arrangement is set out in full on how we make money.
- We hold no position that a rating could move. The index is not run to benefit a token, a fund or a protocol.
- The rubric is public before the scores are. You can check our arithmetic against our own published anchors on the methodology page.
- Corrections are logged in public. Every score change, methodology change and mistake appears in the changelog with a reason and a source.
How we work
Each chain is assessed against primary sources: the chain's own documentation and roadmaps, standards published by NIST, public code repositories and improvement proposals, and named research papers. Where we use a secondary source, usually an exposure estimate produced by a third-party analytics firm, it is labelled as secondary in the source list on that chain's profile.
Scores are set editorially in this phase, which means a person reads the sources and writes the note. That is a limitation and we would rather state it than obscure it. The rubric, anchors and derived deployment mapping exist to constrain that judgement as tightly as possible, and the build refuses to publish a dataset whose tiers and scores contradict each other.
What stands in for a review committee here is a set of checks that a judgement has to survive before it reaches the site, and they are worth naming because you can verify each one rather than take our word for it. Every score carries a note and a primary source link, and the build rejects a score without them. A tier and its deployment score are the same claim, so the build fails if an editor moves one without the other. Where a published anchor covers more than one score, the data has to state why that exact value and not its neighbour. Every change is logged in the changelog with a reason, a source and the score either side of it, so a revision cannot be made quietly. None of that is the same as a second reader, and we are not going to claim it is. It does mean the specific ways a single editor's judgement could drift are the ones a machine is checking.
What is in scope
The index rates layer-1 blockchains: networks that run their own consensus and whose own signature scheme secures the balances people hold. That boundary is not arbitrary. The question this index answers is whether the cryptography protecting your funds can be forged by a quantum computer, and that question only has a clean answer where a network controls its own signatures.
Three categories are excluded, each for a specific reason.
- Layer 2s and rollups. A rollup inherits settlement security from the chain beneath it, so its quantum exposure is partly its own and partly its parent's. Rating it on the same scale as a layer 1 would compare two different things. This excludes Starknet, which is an Ethereum layer 2, despite it having genuinely interesting post-quantum work: its STARK proof system is hash-based and therefore not vulnerable to Shor's algorithm, while its account keys use a Stark-curve signature that is. That distinction deserves a profile, but not on this scale.
- Oracles and middleware. These secure data feeds or route messages between chains. They do not hold a ledger of balances under their own signature scheme, so the dimensions in our rubric do not apply. This excludes Chainlink, and it also excludes Quant: Overledger is an interoperability layer rather than a blockchain, and QNT is an ERC-20 token on Ethereum, so its holders carry Ethereum's exposure rather than any of its own.
- Stablecoins and tokens. A token inherits the signature scheme of whatever chain it lives on. Rating it separately would double-count the host chain and imply the token has a cryptographic position of its own, which it does not.
Which chains we cover
Within that boundary, a chain is in scope if it meets any one of three tests. The list is re-checked every time the index is updated.
- Scale. It is one of the twenty-five largest layer 1s by market capitalisation. Market value is not part of the Hardy Score and never will be, for the reasons set out on the methodology page. It is used here and only here: size decides who gets assessed, never how they score.
- Position. It has published a post-quantum position of any kind, at any size: a claim to be quantum-safe, or a roadmap, an improvement proposal or a funded research programme addressing the threat. Testing those against what is actually deployed is a large part of what this index is for, including where we find a claim does not hold.
- Deployment. It has a post-quantum signature scheme running on mainnet, at any size. A small chain that has actually shipped is one of the most informative rows in the index, and is exactly what a ranking by market value would hide.
Two conditions apply to all three. The chain must have a live public mainnet, because the bottom of the readiness spine describes the signatures securing real balances and a network without a mainnet has none. And the deployed scheme must be confirmable against a primary source, or the row is held back rather than guessed at.
A chain that meets none of the three tests is not missing because we judged it unimportant. It is absent because nothing about its quantum position is yet in question. If you believe a chain qualifies and is not here, that is a coverage gap and we would like to know about it.
Chains we have held back
A chain is only published once its signature scheme and its post-quantum status can be confirmed against a primary source. Where a project markets post-quantum protection but we cannot verify what is actually deployed, we hold the row rather than guess in either direction. Publishing an unverified high score would be as damaging as publishing an unfair low one.
- Cellframe. Its documentation lists post-quantum algorithms as available, and its own material describes a post-quantum transaction on mainnet, but we could not confirm from primary documentation which scheme secures ordinary transactions by default or whether post-quantum signing is mandatory.
- QANplatform. It markets a quantum-resistant layer 1 built on CRYSTALS-Dilithium, and its components carry real third-party audits, but there is no public mainnet. That means no deployed scheme to inspect and no live balances to assess. It was rated until 12 August 2026, when the bottom of the readiness spine became Exposed, a rung that describes the signatures securing funds on a live mainnet. A chain with no mainnet has no such signatures, so the row is held back until one is running.
- Quranium. Its mainnet is described as live and natively post-quantum using SPHINCS+, but the developer documentation was not reachable to us at the time of writing, so the claim rests on announcements rather than a specification we could inspect.
- Canton Network. It qualifies on scale and is the only chain inside the twenty-five largest we do not rate. Secondary sources report that Canton signs with Ed25519 by default and supports ECDSA over P-256 and P-384, which would be an ordinary quantum-vulnerable position, but every version of the security documentation stating those schemes served us a navigation shell rather than the text. We will not publish a signature assessment from a search-engine summary of a page we could not read, so the row waits for a specification we can quote.
All four will be added as soon as the deployed scheme can be verified. If you can point us at the primary documentation, that is the fastest route.
Corrections and contact
If a score is wrong, the most useful thing you can send is the primary source that contradicts it. Write to index@hardyindex.com. Corrections are published in the changelog with the source that prompted them, including corrections to our own errors.
Chains are welcome to submit sources and will be assessed on the same rubric as everyone else. Submitting a source does not create an obligation to change a score.
Citing and reusing the index
The index is meant to be cited. Every page has a Markdown mirror at the same URL with a
.md extension, and the site publishes an llms.txt for
machine readers. When quoting a score, please include the Hardy Score, the tier and the "as of"
date, because all three move.
Current methodology version: v1.4.
This is a security-readiness assessment, not investment advice.