1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
IOTA layer-1 transactions are signed with Ed25519, which replaced the quantum-resistant Winternitz one-time signature scheme in the Chrysalis upgrade. No post-quantum signature protects IOTA tokens on mainnet.
source
2 Deployment stage 1/10, weighted 25%
Band 1: Tier 5: Exposed.
Tier 5: Exposed. IOTA has shipped real post-quantum algorithms, but in IOTA Identity, which secures credentials rather than tokens. For the Ed25519 signatures that actually protect layer-1 balances we found no improvement proposal and no research programme: a search of the iotaledger TIP and node repositories returns no quantum-related issue at all.
source
3 NIST alignment 4/10, weighted 15%
Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.
IOTA Identity v1.7 supports genuinely NIST-standardised schemes: ML-DSA at security levels 44, 65 and 87, SLH-DSA at 128, 192 and 256 bits, and Falcon at 512 and 1024, along with hybrid EdDSA combinations. The algorithm choices are sound; they are deployed in the credential layer rather than in consensus.
source
Placement in the band A 4 rather than a 5: the schemes are genuinely NIST-standardised and specifically named, which is well above a passing reference to candidates. It is held down because they sit in the credential layer rather than anywhere near consensus, so nothing standardised protects tokens.
4 Migration path 2/10, weighted 15%
Band 0 to 2: No agreed migration path, or the proposals on the table would strand or freeze holder funds.
No published layer-1 migration plan or date was found. IOTA has demonstrated it can change its signature scheme network-wide, having done exactly that in Chrysalis, so the capability is proven even though the plan is absent.
source
Placement in the band At the top of the band rather than a 0 or a 1: IOTA has changed its signature scheme network-wide before, in Chrysalis, so the capability is proven. It cannot reach 3 because no layer-1 plan or date exists for the problem to be acknowledged against.
5 Exposure 4/10, weighted 10%
Band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.
Post-Chrysalis IOTA addresses are derived from a hash of the Ed25519 public key rather than being the key itself, so unspent, never-signed holdings are not yet harvestable. Any address that has signed has published its key.
source
Placement in the band A 4 rather than a 3: the hashed-address model means never-signed holdings are not yet harvestable, which is better than the account-model chains sharing this band. Not a 5, because no measurement of IOTA's exposed share was found.
6 Verification 6/10, weighted 5%
Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.
IOTA's protocol and identity libraries are open source and the signature change is documented in a public Tangle Improvement Proposal, so the facts are checkable. The deduction is for the gap between the documented reality and the widely circulated claim that IOTA is quantum-resistant, which IOTA has not prominently corrected.
source
Placement in the band The floor of the band: the libraries are open source and the signature change is documented in a public improvement proposal, so the facts are checkable. It cannot go higher while the widely circulated quantum-resistance claim stands uncorrected by IOTA itself.