---
title: Is Bitcoin Cash quantum-safe?
chain: Bitcoin Cash
ticker: BCH
hardy_score: 66
rank: 7 of 31
tier: "2: Shipping"
url: "https://hardyindex.com/chains/bitcoin-cash"
updated: 2026-08-16
reviewed: 2026-10-02
methodology_version: 1.4
---

# Is Bitcoin Cash quantum-safe?

**Hardy Score 66.0 / 100. Rank 7 of 31. Tier 2: Shipping. As of 2 October 2026.** Sources last verified 2 October 2026; last substantive change 16 August 2026.

Not at the protocol level, but Bitcoin Cash holders can put coins behind a post-quantum signature on mainnet today, which is more than Bitcoin can say. Bitcoin Cash still signs with ECDSA and Schnorr on secp256k1, both broken by Shor's algorithm, and no proposal exists to change that. What changed is the scripting layer. The Layla upgrade activated on mainnet at 12:00 UTC on 15 May 2026, bundling four Cash Improvement Proposals: Loops, Functions, Pay to Script and Bitwise. Together they made Quantumroot practical, a vault design by Jason Dreyzehner that verifies Leighton-Micali One-Time Signatures in Bitcoin Script. LM-OTS is specified in RFC 8554, rests only on SHA-256, and is the one-time signature underlying the LMS scheme that NIST approves in SP 800-208. Wallets including OPTN Labs and Paytaca shipped support. So the post-quantum protection is real, it is on mainnet, and it is reachable by ordinary holders, but it is an opt-in contract rather than an account type, its author states it has not been reviewed by anyone else, and the chain's base signature scheme is untouched.

> This is a security-readiness assessment, not investment advice.

## Summary

The Layla upgrade of 15 May 2026 activated the scripting features that make Quantumroot work, so hash-based post-quantum vaults now run on Bitcoin Cash mainnet as contracts, without any change to the chain's own signature scheme.

## Where we are making a judgement call

Two judgement calls carry this profile. The first is treating a contract-level vault as shipping, which places Bitcoin Cash in Tier 2 on the same reasoning applied to the other application-level case in this index; a reader who thinks only protocol features should count would put it in Tier 3 and take about fifteen points off. The second is the exposure score, which is set on the address model because no Bitcoin Cash measurement exists. Given that this chain carries the same pre-fork pay-to-public-key outputs Bitcoin does, a published measurement at Bitcoin-like levels would move that dimension sharply downward, and it is the number we would most like somebody to produce.

## Score breakdown

| # | Dimension | Score | Weight | Contribution |
|---:|---|---:|---:|---:|
| 1 | Signature scheme | 5/10 | 30% | 15.0 |
| 2 | Deployment stage | 8/10 | 25% | 20.0 |
| 3 | NIST alignment | 7/10 | 15% | 10.5 |
| 4 | Migration path | 8/10 | 15% | 12.0 |
| 5 | Exposure | 6/10 | 10% | 6.0 |
| 6 | Verification | 5/10 | 5% | 2.5 |
| | **Hardy Score** | | | **66.0** |

### 1. Signature scheme: 5/10

Anchor band 4 to 6: A post-quantum signature is available on mainnet only as an opt-in, application-level or experimental primitive.

Quantumroot verifies Leighton-Micali One-Time Signatures inside Bitcoin Script, so the post-quantum primitive protecting a vault is real and runs on mainnet. It is an application-level contract rather than a protocol signature scheme: Bitcoin Cash itself still signs transactions with ECDSA and Schnorr on secp256k1, and no post-quantum account type exists.

Placement in the band: Above the 4 given to a comparable application-level vault elsewhere in this index, because the enabling consensus changes shipped in a mainnet upgrade and production wallets carry it, rather than it being a single experimental program. Not a 6, because no share of supply behind Quantumroot has been measured and the author states the template is unreviewed.

Source: https://blog.bitjson.com/quantumroot/

### 2. Deployment stage: 8/10

Anchor band 8: Tier 2: Shipping.

Tier 2: Shipping. A post-quantum signing primitive is live on mainnet and reachable by holders through supported wallets. As with the other contract-level cases in this index, this is a generous reading and the caveat below sets out why a reader might score it lower.

Source: https://thequantuminsider.com/2026/05/26/bitcoin-quantumroot-vaults-go-live-on-cashvm-upgrade-unlocks-turing-complete-defi-on-l1-with-cashtokens/

### 3. NIST alignment: 7/10

Anchor band 6 to 8: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.

Quantumroot names its scheme precisely: LM-OTS as specified in RFC 8554, which NIST SP 800-208 recommends. The construction rests only on SHA-256 rather than on lattice assumptions. What runs is the one-time signature on its own, not the stateful LMS or HSS scheme that SP 800-208 actually approves.

Placement in the band: A 7 rather than an 8 because the approved artefact in SP 800-208 is LMS, and Quantumroot deploys its LM-OTS component standalone. Above a 6 because the scheme is named to the RFC and the parameter choice, and it is deployed rather than merely referenced.

Source: https://blog.bitjson.com/quantumroot/

### 4. Migration path: 8/10

Anchor band 6 to 8: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.

The mechanism is not merely designed but built, live and carried by wallets: a holder can move coins into a Quantumroot vault today, and sweeps out of quantum-ready addresses are cheaper than the equivalent P2PKH spend. Nothing at the protocol level accompanies it. No plan, dated or otherwise, has been published for Bitcoin Cash's own ECDSA and Schnorr signatures.

Placement in the band: At the top of the band rather than a 6 or a 7, because a working, wallet-supported route beats the identified-but-unbuilt mechanism this band describes at its floor. It cannot reach the band above, which is for chains migrating the accounts themselves: moving coins into a vault contract protects the coins moved and leaves the signature scheme exactly where it was.

Source: https://blog.bitjson.com/quantumroot/

### 5. Exposure: 6/10

Anchor band 6 to 8: Addresses are key hashes and exposure is limited to spent outputs, keeping a meaningful share of supply unexposed.

Bitcoin Cash uses the same pay-to-public-key-hash address model as Bitcoin, so a public key is revealed on spend rather than on receipt and a never-spent address exposes only a hash. Exposure therefore concentrates in reused addresses and in the pre-fork pay-to-public-key outputs that Bitcoin Cash inherited with the shared chain history to August 2017.

Placement in the band: At the floor of the band rather than a 7 or an 8, because the inherited pre-fork outputs are exposed on this chain exactly as they are on Bitcoin, and because no Bitcoin Cash specific measurement of exposed supply has been published. This score reflects the address model, which is what the evidence supports, and the caveat below says what would change it.

Source: https://blog.bitjson.com/quantumroot/

### 6. Verification: 5/10

Anchor band 3 to 5: Some independent verification exists, but the headline quantum-safety claim itself is not verified.

The consensus changes that made Quantumroot practical went through the Cash Improvement Proposal process in public and shipped in a node release. The vault template itself is open source but explicitly unreviewed: its author writes that it "has not yet been reviewed by anyone else" and that he is erring on the side of publishing too early.

Placement in the band: At the top of the band rather than a 3 or a 4, because the enabling upgrade had genuine public scrutiny and a named node release behind it. It cannot enter the band above, because the component carrying the post-quantum claim is the one part of this that carries a self-declared absence of review.

Source: https://blog.bitjson.com/quantumroot/

## Nearest chains in the ranking

The chains Bitcoin Cash sits among, out of 31 rated. The last column is the gap in Hardy points from Bitcoin Cash.

| Rank | Chain | Tier | Hardy | vs BCH |
|---:|---|---|---:|---:|
| 3 | [Abelian](https://hardyindex.com/chains/abelian) | 1: Native | 84.5 | +18.5 |
| 4 | [NEAR Protocol](https://hardyindex.com/chains/near) | 2: Shipping | 81.5 | +15.5 |
| 5 | [Algorand](https://hardyindex.com/chains/algorand) | 2: Shipping | 77.5 | +11.5 |
| 6 | [Nervos CKB](https://hardyindex.com/chains/nervos-ckb) | 2: Shipping | 75.5 | +9.5 |
| 7 | **Bitcoin Cash** | 2: Shipping | 66.0 | this chain |
| 8 | [Solana](https://hardyindex.com/chains/solana) | 2: Shipping | 54.5 | -11.5 |
| 9 | [XRP Ledger](https://hardyindex.com/chains/xrp-ledger) | 3: Committed | 46.5 | -19.5 |
| 10 | [Sui](https://hardyindex.com/chains/sui) | 3: Committed | 45.5 | -20.5 |
| 11 | [Hedera](https://hardyindex.com/chains/hedera) | 3: Committed | 42.0 | -24.0 |

## Signature scheme

- **On mainnet today:** ECDSA and Schnorr on secp256k1
- **Post-quantum scheme:** LM-OTS (Leighton-Micali One-Time Signatures) verified in Bitcoin Script by the Quantumroot vault template, opt-in at the contract level
- **NIST standard:** None adopted at protocol level. LM-OTS is specified in RFC 8554 and underlies the LMS scheme approved in NIST SP 800-208.
- **Readiness tier:** Tier 2: Shipping. Post-quantum signature features are live on mainnet and a migration for existing holders is underway.

## Roadmap

- **1 July 2025** (shipped): Quantumroot is published as a post-quantum vault design for Bitcoin Cash, using LM-OTS per RFC 8554 and relying only on SHA-256.
  Source: https://blog.bitjson.com/quantumroot/
- **20 November 2025** (shipped): Post-quantum vaults go live on Chipnet, the Bitcoin Cash preview network that runs six months ahead of mainnet.
  Source: https://blog.bitjson.com/quantumroot-on-chipnet/
- **15 May 2026** (shipped): The Layla upgrade activates on mainnet at 12:00 UTC, bundling the Loops, Functions, Pay to Script and Bitwise CHIPs that Quantumroot depends on.
  Source: https://thequantuminsider.com/2026/05/26/bitcoin-quantumroot-vaults-go-live-on-cashvm-upgrade-unlocks-turing-complete-defi-on-l1-with-cashtokens/
- **No date published** (proposed): No Cash Improvement Proposal addresses Bitcoin Cash's own ECDSA and Schnorr signatures, and no sunset or protocol-level post-quantum account type has been proposed.
  Source: https://blog.bitjson.com/bitcoin-cash-upgrade-2026/

## Exposure

Bitcoin Cash inherits both halves of Bitcoin's exposure story, because it inherits Bitcoin's chain history up to the split in August 2017. Every original pay-to-public-key output mined before that date exists on this chain too, with its public key published on-chain, and every address reused before or since has revealed its key on first spend. What Bitcoin Cash does not inherit is the measurement: the Deloitte, Galaxy Digital and Glassnode analyses that quantify Bitcoin's exposed supply were done on Bitcoin, and nobody has published the equivalent for Bitcoin Cash. The score above therefore reflects the address model rather than a count, which is a limitation this rubric states openly. Quantumroot changes the forward-looking picture rather than the historical one: coins moved into a vault stop being protected by an elliptic-curve key, and coins that were exposed before remain exposed for good.

## Frequently asked questions

### Is Bitcoin Cash quantum-safe?

Not at the protocol level, but Bitcoin Cash holders can put coins behind a post-quantum signature on mainnet today, which is more than Bitcoin can say. Bitcoin Cash still signs with ECDSA and Schnorr on secp256k1, both broken by Shor's algorithm, and no proposal exists to change that. What changed is the scripting layer. The Layla upgrade activated on mainnet at 12:00 UTC on 15 May 2026, bundling four Cash Improvement Proposals: Loops, Functions, Pay to Script and Bitwise. Together they made Quantumroot practical, a vault design by Jason Dreyzehner that verifies Leighton-Micali One-Time Signatures in Bitcoin Script. LM-OTS is specified in RFC 8554, rests only on SHA-256, and is the one-time signature underlying the LMS scheme that NIST approves in SP 800-208. Wallets including OPTN Labs and Paytaca shipped support. So the post-quantum protection is real, it is on mainnet, and it is reachable by ordinary holders, but it is an opt-in contract rather than an account type, its author states it has not been reviewed by anyone else, and the chain's base signature scheme is untouched.

### Is Bitcoin Cash quantum-safe?

Not at the protocol level. Bitcoin Cash signs transactions with ECDSA and Schnorr on secp256k1, both broken by Shor's algorithm, and no proposal exists to change that. Holders can, however, move coins into a Quantumroot vault on mainnet today, which protects them with a hash-based one-time signature instead. That protection is opt-in and applies only to coins actually moved.

### What is Quantumroot?

Quantumroot is a vault design by Jason Dreyzehner that verifies Leighton-Micali One-Time Signatures inside Bitcoin Script. LM-OTS is specified in RFC 8554, rests only on SHA-256 rather than on any new cryptographic assumption, and is the one-time signature underlying the LMS scheme NIST approves in SP 800-208. It became practical on Bitcoin Cash mainnet when the Layla upgrade activated the Loops, Functions, Pay to Script and Bitwise features on 15 May 2026.

### Why does Bitcoin Cash score higher than Bitcoin?

Because this index ranks preparation, and on that measure the two chains are now in different positions. Bitcoin has two Draft BIPs, no activation path and a measured exposure of several million coins. Bitcoin Cash has a hash-based post-quantum signing primitive working on mainnet and reachable through production wallets. Neither has changed its own signature scheme, and Bitcoin Cash's advantage rests on its scripting layer rather than on its cryptography.

### Has Quantumroot been audited?

No. Its author states plainly that the wallet template "has not yet been reviewed by anyone else" and that he is erring on the side of publishing too early. The consensus changes it depends on went through the public Cash Improvement Proposal process and shipped in a node release, so the platform underneath it has had scrutiny that the vault template itself has not. This is the main reason the verification dimension scores where it does.

### Does moving coins into a Quantumroot vault fix past exposure?

No. If a public key has already appeared on-chain, it is recorded permanently and an attacker with a future quantum computer can work from the copy they took today. Moving the coins protects them from being spent by someone who breaks that key later, because the vault requires the hash-based signature instead, but it cannot un-publish the key. The coins that cannot be helped are the ones whose owners never act.

## What this rating means if you hold Bitcoin Cash

Plain-language guidance from the same publication, with no product recommendation attached.

- [Is my crypto safe from quantum computers?](https://hardyindex.com/guides/is-my-crypto-safe-from-quantum-computers.md)
- [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers.md)
- [All guides](https://hardyindex.com/guides.md)

Nothing on this profile is sponsored and nothing on it is an affiliate link. See https://hardyindex.com/how-we-make-money.md.

## What we have published about Bitcoin Cash

- [Bitcoin Cash entered the index above Bitcoin, and the gap needs explaining](https://hardyindex.com/news/bitcoin-cash-quantumroot-vaults-mainnet-coverage.md): Neither chain changed how it signs. The difference sits in the scripting layer, and one weak dimension keeps the gap wider than it may stay. Published 25 August 2026.

## Sources

1. [Quantumroot: Quantum-Secure Vaults for Bitcoin Cash](https://blog.bitjson.com/quantumroot/): Jason Dreyzehner (bitjson) (primary, checked 16 August 2026)
2. [Post-quantum vaults are live on Bitcoin Cash's Chipnet](https://blog.bitjson.com/quantumroot-on-chipnet/): Jason Dreyzehner (bitjson) (primary, checked 16 August 2026)
3. [Bitcoin Cash Upgrade 2026](https://blog.bitjson.com/bitcoin-cash-upgrade-2026/): Jason Dreyzehner (bitjson) (primary, checked 16 August 2026)
4. [SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes](https://csrc.nist.gov/pubs/sp/800/208/final): NIST (primary, checked 16 August 2026)
5. [Bitcoin Quantumroot Vaults Go Live on CashVM](https://thequantuminsider.com/2026/05/26/bitcoin-quantumroot-vaults-go-live-on-cashvm-upgrade-unlocks-turing-complete-defi-on-l1-with-cashtokens/): The Quantum Insider (secondary, checked 16 August 2026)

## How to cite this rating

A rating is only true as of the day it was reviewed, so both forms carry the review date and the methodology version. If you are quoting the score, quote those too.

The Hardy Index (2026). Bitcoin Cash: quantum readiness assessment. Hardy Score 66.0 of 100, Tier 2: Shipping. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/bitcoin-cash

```bibtex
@misc{hardyindex_bitcoin_cash_2026,
  author       = {{The Hardy Index}},
  title        = {Bitcoin Cash: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/bitcoin-cash}},
  note         = {Hardy Score 66.0 of 100, Tier 2: Shipping. Methodology v1.4},
  urldate      = {2026-10-02}
}
```

---

Methodology: https://hardyindex.com/methodology (v1.4).
Cite as: The Hardy Index, "Bitcoin Cash", https://hardyindex.com/chains/bitcoin-cash, as of 2 October 2026.
