---
title: Is Internet Computer quantum-safe?
chain: Internet Computer
ticker: ICP
hardy_score: 14.5
rank: 23 of 31
tier: "5: Exposed"
url: "https://hardyindex.com/chains/internet-computer"
updated: 2026-08-17
reviewed: 2026-10-02
methodology_version: 1.4
---

# Is Internet Computer quantum-safe?

**Hardy Score 14.5 / 100. Rank 23 of 31. Tier 5: Exposed. As of 2 October 2026.** Sources last verified 2 October 2026; last substantive change 17 August 2026.

No, and the Internet Computer's exposure is unusually structural because its distinguishing feature is built on the cryptography at risk. Chain-key cryptography uses BLS for what the documentation calls ICP's internal operations: consensus, response certification, cross-subnet messaging and randomness generation. On top of that, chain-key signatures let canisters hold and use keys for external schemes, currently threshold ECDSA over secp256k1 and threshold Schnorr in bip340secp256k1 and ed25519 variants. Every one of those is broken by Shor's algorithm. So is the subnet key that lets any client verify a response without trusting a node, which is the property the whole design is sold on. DFINITY's chief scientist has said publicly that ICP was built with crypto agility, that the situation is being monitored, that replacement algorithms would be proposed to the NNS at the appropriate time, and that the network's public key would have to change. That is a real answer from someone with authority, and it is not a proposal, a programme or a date, which is why this profile sits where it does.

> This is a security-readiness assessment, not investment advice.

## Summary

Every layer of the chain-key architecture rests on elliptic curves, from the BLS signatures that certify state to the threshold ECDSA and Schnorr keys canisters sign with, and DFINITY has published no post-quantum programme addressing any of it.

## Where we are making a judgement call

Two things should be said plainly. First, our finding is that we could not locate a formal post-quantum proposal, specification or research programme, not that DFINITY has done no work. A chief scientist citing crypto agility is a real statement from a real cryptographer, and the methodology's Tier 4 floor asks for a formal improvement proposal or a public research programme, which a forum answer is not. The rung records the absence of that artefact and nothing about DFINITY's competence. Second, ICP is a serious cryptography organisation, and this profile would change quickly on the publication of an NNS proposal or a research programme. The primary source is the fastest way to correct it.

## Score breakdown

| # | Dimension | Score | Weight | Contribution |
|---:|---|---:|---:|---:|
| 1 | Signature scheme | 0/10 | 30% | 0.0 |
| 2 | Deployment stage | 1/10 | 25% | 2.5 |
| 3 | NIST alignment | 0/10 | 15% | 0.0 |
| 4 | Migration path | 3/10 | 15% | 4.5 |
| 5 | Exposure | 5/10 | 10% | 5.0 |
| 6 | Verification | 5/10 | 5% | 2.5 |
| | **Hardy Score** | | | **14.5** |

### 1. Signature scheme: 0/10

Anchor band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Nothing post-quantum protects funds or state. The documentation names BLS for consensus, response certification, cross-subnet messaging and randomness, and threshold ECDSA over secp256k1 plus threshold Schnorr over bip340secp256k1 and ed25519 for chain-key signatures. User identities sign with Ed25519 or ECDSA. Every scheme in use falls to Shor's algorithm.

Source: https://docs.internetcomputer.org/concepts/chain-key-cryptography/

### 2. Deployment stage: 1/10

Anchor band 1: Tier 5: Exposed.

Tier 5: Exposed. The signatures securing mainnet are quantum-vulnerable throughout, and the only published position is a forum answer rather than a formal proposal or a research programme. See the caveat below on what that finding does and does not establish.

Source: https://forum.dfinity.org/t/what-is-icps-post-quantum-migration-plan-for-threshold-bls-and-bls-based-randomness/75099

### 3. NIST alignment: 0/10

Anchor band 0 to 2: No named post-quantum scheme, or a proprietary scheme with no public cryptanalysis.

No post-quantum scheme has been named or selected for any layer of the protocol, so there is nothing to assess against a NIST standard. The chain-key documentation names its curves precisely and none of them is post-quantum.

Placement in the band: The floor of the band rather than a 1 or a 2, because no candidate has been named at all. Naming a scheme and declining to adopt it would sit higher than this; ICP has not reached the point of naming one.

Source: https://csrc.nist.gov/pubs/fips/204/final

### 4. Migration path: 3/10

Anchor band 3 to 5: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.

The problem is acknowledged by someone with authority and no mechanism exists. DFINITY's chief scientist has cited crypto agility and said replacement algorithms would be proposed to the NNS at the appropriate time, while also noting that the Internet Computer's public key would need to change. That last point is the hard part: clients verify responses against a root key they hold, so rotating it reaches beyond the network into everything that has ever embedded it.

Placement in the band: At the floor of the band rather than a 4 or a 5, because acknowledgement is all there is. No mechanism has been designed, no NNS proposal has been raised, and the one structural obstacle that has been named publicly, changing the root key, has had no solution offered for it.

Source: https://forum.dfinity.org/t/what-is-icps-post-quantum-migration-plan-for-threshold-bls-and-bls-based-randomness/75099

### 5. Exposure: 5/10

Anchor band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.

Ledger accounts are identifiers derived by hashing, and a self-authenticating principal is itself a hash of a public key, so an account that has never transacted does not publish the key protecting it. Signing reveals it. Separately and unavoidably, the subnet public keys are published by design, because verifying a certified response without trusting a node is the entire point of the architecture.

Placement in the band: At the top of the band rather than a 4 or a 3, because the hashed principal genuinely protects a never-used account, which is more than chains at the floor of this band offer. It cannot rise into the band above, because the subnet keys that certify all state are public by construction and cannot be withheld without breaking the design.

Source: https://docs.internetcomputer.org/concepts/chain-key-cryptography/

### 6. Verification: 5/10

Anchor band 3 to 5: Some independent verification exists, but the headline quantum-safety claim itself is not verified.

The cryptography is documented to the curve and the variant, the implementation is open source, and the chain-key design has been described in public research. That makes the current position checkable. There is no post-quantum claim to verify, and no published position beyond a forum answer to hold against future statements.

Placement in the band: At the top of the band rather than a 4 or a 3, because the schemes in use are named precisely enough to be audited by a reader. It cannot reach the band above, which credits verification of a post-quantum claim, and ICP has made none.

Source: https://docs.internetcomputer.org/concepts/chain-key-cryptography/

## Nearest chains in the ranking

The chains ICP sits among, out of 31 rated. The last column is the gap in Hardy points from ICP.

| Rank | Chain | Tier | Hardy | vs ICP |
|---:|---|---|---:|---:|
| 19 | [BNB Chain](https://hardyindex.com/chains/bnb-chain) | 4: Debating | 22.5 | +8.0 |
| 20 | [Monero](https://hardyindex.com/chains/monero) | 4: Debating | 21.0 | +6.5 |
| 21 | [IOTA](https://hardyindex.com/chains/iota) | 5: Exposed | 18.5 | +4.0 |
| 22 | [Bitcoin](https://hardyindex.com/chains/bitcoin) | 4: Debating | 17.0 | +2.5 |
| 23 | **Internet Computer** | 5: Exposed | 14.5 | this chain |
| 24 | [TON](https://hardyindex.com/chains/toncoin) | 5: Exposed | 13.0 | -1.5 |
| 25 | [Litecoin](https://hardyindex.com/chains/litecoin) | 5: Exposed | 12.5 | -2.0 |
| 26 | [Bittensor](https://hardyindex.com/chains/bittensor) | 5: Exposed | 11.0 | -3.5 |
| 27 | [Dogecoin](https://hardyindex.com/chains/dogecoin) | 5: Exposed | 11.0 | -3.5 |

## Signature scheme

- **On mainnet today:** BLS for consensus, certification and randomness; threshold ECDSA over secp256k1 and threshold Schnorr over bip340secp256k1 and ed25519 for chain-key signatures; Ed25519 or ECDSA for user identities
- **Post-quantum scheme:** None. No post-quantum scheme has been named for any layer of the protocol.
- **NIST standard:** None adopted and none named as a candidate.
- **Readiness tier:** Tier 5: Exposed. The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme addressing them could be found.

## Roadmap

- **December 2024** (proposed): DFINITY's chief scientist states publicly that ICP was designed with crypto agility, that the situation is being monitored, that replacement algorithms would be proposed to the NNS at the appropriate time, and that the Internet Computer's public key would need to change.
  Source: https://forum.dfinity.org/t/what-is-icps-post-quantum-migration-plan-for-threshold-bls-and-bls-based-randomness/75099
- **14 August 2026** (proposed): A detailed public request for ICP's concrete post-quantum migration plan for threshold BLS and BLS-based randomness draws no substantive answer.
  Source: https://forum.dfinity.org/t/what-is-icps-post-quantum-migration-plan-for-threshold-bls-and-bls-based-randomness/75099
- **No date published** (proposed): No NNS proposal, formal specification, research programme or timeline addressing post-quantum migration was found.
  Source: https://docs.internetcomputer.org/concepts/chain-key-cryptography/

## Exposure

ICP's exposure divides into the ordinary kind and a kind particular to its architecture. The ordinary kind is mild: account identifiers and self-authenticating principals are hashes, so a key is revealed by signing rather than by existing, and an account that has never transacted publishes nothing usable. The particular kind is not mild and cannot be reduced by user behaviour. Chain-key cryptography works by having every subnet hold a threshold BLS key whose public half is known to everyone, so that any client can verify a certified response against it without trusting the node that served it. That public key is the product. It is published deliberately, it is embedded in clients and wallets, and an adversary recording it today needs nothing further from the network. Breaking it would not drain an individual account; it would let an attacker forge certified state, which is a worse failure and one that no holder can opt out of.

## Frequently asked questions

### Is Internet Computer quantum-safe?

No, and the Internet Computer's exposure is unusually structural because its distinguishing feature is built on the cryptography at risk. Chain-key cryptography uses BLS for what the documentation calls ICP's internal operations: consensus, response certification, cross-subnet messaging and randomness generation. On top of that, chain-key signatures let canisters hold and use keys for external schemes, currently threshold ECDSA over secp256k1 and threshold Schnorr in bip340secp256k1 and ed25519 variants. Every one of those is broken by Shor's algorithm. So is the subnet key that lets any client verify a response without trusting a node, which is the property the whole design is sold on. DFINITY's chief scientist has said publicly that ICP was built with crypto agility, that the situation is being monitored, that replacement algorithms would be proposed to the NNS at the appropriate time, and that the network's public key would have to change. That is a real answer from someone with authority, and it is not a proposal, a programme or a date, which is why this profile sits where it does.

### Is the Internet Computer quantum-safe?

No. Every signature scheme in use falls to Shor's algorithm: BLS for consensus, certification and randomness, threshold ECDSA over secp256k1 and threshold Schnorr for chain-key signatures, and Ed25519 or ECDSA for user identities. No post-quantum scheme has been named for any layer, and no migration proposal has been put to the NNS.

### What is chain-key cryptography and why does it matter here?

Chain-key cryptography is what lets any client verify a response from the Internet Computer against a single public key, without trusting the node that answered. Each subnet holds a threshold BLS key and the network derives canister keys from a small number of master keys. It is ICP's distinguishing feature, and it means the cryptography at risk is not an implementation detail at the edge of the system but the mechanism the whole design rests on.

### Has DFINITY said anything about post-quantum migration?

Yes, but not in a form this methodology can score as a plan. DFINITY's chief scientist has said publicly that ICP was designed with crypto agility, that the situation is being monitored, that replacement algorithms would be proposed to the NNS at the appropriate time, and that the network's public key would need to change. A renewed and detailed request for a concrete plan in August 2026 drew no substantive reply.

### Why is ICP rated Exposed rather than Debating?

Because the Debating rung asks for post-quantum work on the chain's own signatures documented in a formal improvement proposal or a public research programme, and that bar exists specifically so a forum post does not clear it. ICP's published position is a forum answer. The same reading is applied to every chain in this index, and it is about the artefact rather than about the organisation behind it.

### Would breaking ICP's cryptography just mean stolen tokens?

It would be worse than that. Breaking a subnet's threshold BLS key would let an attacker forge certified responses, meaning clients could be told anything about the state of the network and would verify it as genuine. That is a different and larger failure than an individual account being drained, and unlike key exposure at the account level, no user action reduces it.

## What this rating means if you hold ICP

Plain-language guidance from the same publication, with no product recommendation attached.

- [Is my crypto safe from quantum computers?](https://hardyindex.com/guides/is-my-crypto-safe-from-quantum-computers.md)
- [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers.md)
- [All guides](https://hardyindex.com/guides.md)

Nothing on this profile is sponsored and nothing on it is an affiliate link. See https://hardyindex.com/how-we-make-money.md.

## What we have published about Internet Computer

- [Four layer 1s enter the index, and one is held back for want of a readable source](https://hardyindex.com/news/four-layer-1s-added-under-the-coverage-rule.md): We ran the inclusion rule against live market sizes instead of memory, and it produced four new rows. Published 30 August 2026.

## Sources

1. [Chain-key cryptography](https://docs.internetcomputer.org/concepts/chain-key-cryptography/): Internet Computer developer documentation (primary, checked 17 August 2026)
2. [What is ICP's post-quantum migration plan for threshold BLS and BLS-based randomness?](https://forum.dfinity.org/t/what-is-icps-post-quantum-migration-plan-for-threshold-bls-and-bls-based-randomness/75099): Internet Computer Developer Forum (primary, checked 17 August 2026)
3. [FIPS 204: Module-Lattice-Based Digital Signature Standard](https://csrc.nist.gov/pubs/fips/204/final): NIST (primary, checked 17 August 2026)

## How to cite this rating

A rating is only true as of the day it was reviewed, so both forms carry the review date and the methodology version. If you are quoting the score, quote those too.

The Hardy Index (2026). Internet Computer: quantum readiness assessment. Hardy Score 14.5 of 100, Tier 5: Exposed. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/internet-computer

```bibtex
@misc{hardyindex_internet_computer_2026,
  author       = {{The Hardy Index}},
  title        = {Internet Computer: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/internet-computer}},
  note         = {Hardy Score 14.5 of 100, Tier 5: Exposed. Methodology v1.4},
  urldate      = {2026-10-02}
}
```

---

Methodology: https://hardyindex.com/methodology (v1.4).
Cite as: The Hardy Index, "Internet Computer", https://hardyindex.com/chains/internet-computer, as of 2 October 2026.
