1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Cronos runs the Ethereum Virtual Machine on the Cosmos SDK via Ethermint, so accounts are secured by ECDSA on secp256k1 in the Ethereum style, with the Cosmos SDK's own secp256k1 for native accounts and Ed25519 for validator identities. Nothing post-quantum protects funds at either layer.
source
2 Deployment stage 1/10, weighted 25%
Band 1: Tier 5: Exposed.
Tier 5: Exposed. The signatures securing mainnet balances are quantum-vulnerable and we found no roadmap, improvement proposal, research programme or testnet implementation from Cronos Labs or Crypto.com. See the caveat below on what that finding does and does not establish.
source
3 NIST alignment 0/10, weighted 15%
Band 0 to 2: No named post-quantum scheme, or a proprietary scheme with no public cryptanalysis.
No post-quantum scheme has been named or selected at protocol level, so there is nothing to assess against a NIST standard.
source
Placement in the band The floor of the band rather than a 1 or a 2, because no candidate scheme has been named at all. A chain that had named an algorithm and then declined to adopt it would sit above this.
4 Migration path 1/10, weighted 15%
Band 0 to 2: No agreed migration path, or the proposals on the table would strand or freeze holder funds.
No migration plan, mechanism or published position was found. Cosmos SDK chains can in principle add a signature algorithm through a coordinated upgrade, which is a lighter governance burden than a Bitcoin-style soft fork, but nothing has been proposed to put through it and no account-migration route for existing holders has been described.
source
Placement in the band A 1 rather than a 0, because the Cosmos SDK upgrade path is a real mechanism a proposal could use, which chains at the true floor of this band lack. It cannot reach a 3 or above, because that requires the problem to be acknowledged publicly and Cronos has not acknowledged it.
5 Exposure 2/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
Ethereum-style addresses are hashes of public keys, so a funded address that has never signed keeps its key private, and Cosmos-style bech32 addresses on this chain are likewise derived by hashing. In practice an EVM chain used for trading and DeFi sees essentially every account of consequence sign repeatedly, so the key protecting almost all live value is already on-chain.
source
Placement in the band At the top of the band rather than a 1 or a 0, because the hashed address does protect a never-signed account in principle, which chains that publish the key at creation cannot offer. It stays in this band because on a chain of this type nearly every account with a meaningful balance has signed, and no measured share of unexposed supply has been published.
6 Verification 5/10, weighted 5%
Band 3 to 5: Some independent verification exists, but the headline quantum-safety claim itself is not verified.
The node implementation is open source and the chain's architecture is documented, so the current cryptographic position is checkable. There is no post-quantum claim to verify, and no published position to hold against future statements.
source
Placement in the band At the top of the band rather than a 4 or a 3, because the implementation is public and the schemes follow documented Ethereum and Cosmos standards. It cannot reach the band above, which credits verification of a post-quantum claim, and Cronos has made none.