1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Mainnet accounts use ECDSA on secp256k1 and validators use BLS, both broken by Shor's algorithm. leanXMSS validator signatures run in weekly interoperability devnets but nothing post-quantum protects funds or consensus on mainnet.
source
2 Deployment stage 5/10, weighted 25%
Band 5: Tier 3: Committed.
Tier 3: Committed. A dedicated Ethereum Foundation team, public research at pq.ethereum.org, weekly devnets with more than ten client teams, and structured fork milestones targeting approximately 2029 constitute a funded roadmap with active research and no mainnet deployment.
source
3 NIST alignment 7/10, weighted 15%
Band 6 to 8: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.
The roadmap references ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), and the schemes chosen for consensus are hash-based, the same family NIST approves in SP 800-208 and FIPS 205. The specific constructions, leanXMSS and leanSPHINCS, are Ethereum-tailored variants rather than the standardised parameter sets.
source
Placement in the band Not an 8: leanXMSS and leanSPHINCS are Ethereum-tailored variants rather than the standardised parameter sets, so the constructions actually chosen would not themselves be covered by a NIST standard.
4 Migration path 7/10, weighted 15%
Band 6 to 8: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.
Account abstraction gives Ethereum a genuinely credible per-user migration route: signature agility lets individual accounts adopt a post-quantum scheme without a protocol-wide change or a contentious fork. The deductions are for timing, with core infrastructure targeted around 2029, and for the unsolved problem of externally owned accounts whose keys are already exposed.
source
Placement in the band Not an 8: the mechanism is credible but the schedule is not, with core infrastructure targeted around 2029, and externally owned accounts whose keys are already exposed have no route at all.
5 Exposure 2/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
Ethereum addresses are hashes of public keys, so a funded account that has never sent a transaction keeps its key private. In practice nearly every economically meaningful externally owned account has signed at least once and therefore published its key, so effectively all active supply is harvestable today.
source
Placement in the band At the top of the band rather than a 0 or a 1, because the hashed-address model genuinely protects never-signed accounts, a structural advantage over the account-model chains alongside it here, even though almost no meaningful balance still enjoys it.
6 Verification 9/10, weighted 5%
Band 9 to 10: Open source, independently audited, with the claim checkable on-chain or in public research.
Everything is open: a named Ethereum Foundation team, public research at pq.ethereum.org, weekly interoperability devnets with more than ten independent client teams, and open-source implementations. Ethereum Foundation researchers were also co-authors on the March 2026 Google Quantum AI resource-estimate paper that reset the threat timeline.
source
Placement in the band Not a 10: what is open and checkable is the research programme, not a deployed post-quantum component. Nothing post-quantum runs on mainnet for an auditor to examine.