Hardy Index Quantum readiness benchmark

Chain profile

IOTA

IOTA Exposed

Widely described as quantum-resistant on the strength of a scheme it removed in 2021; IOTA's layer 1 has signed with Ed25519 since Chrysalis and post-quantum support exists only in IOTA Identity.

Is IOTA quantum-safe?

No, despite a reputation that says otherwise. IOTA originally used Winternitz one-time signatures, a hash-based scheme that is genuinely quantum-resistant, and that is the source of the claim still repeated across the internet today. The Chrysalis upgrade replaced Winternitz with Ed25519, an elliptic-curve scheme that Shor's algorithm breaks, in exchange for reusable addresses and a much better developer experience. IOTA does have real post-quantum cryptography today, but it lives in IOTA Identity, where version 1.7 supports ML-DSA, SLH-DSA and Falcon, plus hybrid combinations with EdDSA, for issuing and verifying verifiable credentials. That protects credentials, not tokens: it is not the signature scheme securing layer-1 transactions. We found no proposal, research programme or dated plan addressing post-quantum signatures at layer 1, which is why IOTA sits in Tier 5 rather than Tier 1.

Where we are making a judgement call IOTA is the clearest case in this index of a reputation outliving the fact. Its quantum-resistance claim was accurate before 2021 and is repeatedly restated in current articles, listicles and AI answers. We rate the signature scheme that protects IOTA tokens on mainnet today, which is Ed25519. The Tier 5 placement is the harder call, and it is a close one. IOTA is not indifferent to post-quantum cryptography: the Foundation has shipped ML-DSA, SLH-DSA and Falcon in IOTA Identity, which is more deployed post-quantum engineering than several chains placed above it. The tier asks a narrower question, whether there is a proposal or research programme addressing the chain's own vulnerable signatures, and for IOTA there is none we could find. A reader who counts the Foundation's demonstrated post-quantum capability as evidence of intent toward layer 1 would reasonably place IOTA in Tier 4.

At a glance

On mainnet today

Ed25519 (EdDSA over Curve25519 with SHA-512) for layer-1 transactions

Post-quantum scheme

ML-DSA, SLH-DSA and Falcon in IOTA Identity v1.7 for verifiable credentials, including hybrid EdDSA combinations. None at layer 1.

NIST standard

FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) in the identity layer only

Readiness tier

Tier 5: Exposed. The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme addressing them could be found.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
IOTA Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 1 25% 2.5
3 NIST alignment 4 15% 6.0
4 Migration path 2 15% 3.0
5 Exposure 4 10% 4.0
6 Verification 6 5% 3.0
Hardy Score 18.5

1 Signature scheme 0/10, weighted 30%

Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

IOTA layer-1 transactions are signed with Ed25519, which replaced the quantum-resistant Winternitz one-time signature scheme in the Chrysalis upgrade. No post-quantum signature protects IOTA tokens on mainnet. source

2 Deployment stage 1/10, weighted 25%

Band 1: Tier 5: Exposed.

Tier 5: Exposed. IOTA has shipped real post-quantum algorithms, but in IOTA Identity, which secures credentials rather than tokens. For the Ed25519 signatures that actually protect layer-1 balances we found no improvement proposal and no research programme: a search of the iotaledger TIP and node repositories returns no quantum-related issue at all. source

3 NIST alignment 4/10, weighted 15%

Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.

IOTA Identity v1.7 supports genuinely NIST-standardised schemes: ML-DSA at security levels 44, 65 and 87, SLH-DSA at 128, 192 and 256 bits, and Falcon at 512 and 1024, along with hybrid EdDSA combinations. The algorithm choices are sound; they are deployed in the credential layer rather than in consensus. source

Placement in the band A 4 rather than a 5: the schemes are genuinely NIST-standardised and specifically named, which is well above a passing reference to candidates. It is held down because they sit in the credential layer rather than anywhere near consensus, so nothing standardised protects tokens.

4 Migration path 2/10, weighted 15%

Band 0 to 2: No agreed migration path, or the proposals on the table would strand or freeze holder funds.

No published layer-1 migration plan or date was found. IOTA has demonstrated it can change its signature scheme network-wide, having done exactly that in Chrysalis, so the capability is proven even though the plan is absent. source

Placement in the band At the top of the band rather than a 0 or a 1: IOTA has changed its signature scheme network-wide before, in Chrysalis, so the capability is proven. It cannot reach 3 because no layer-1 plan or date exists for the problem to be acknowledged against.

5 Exposure 4/10, weighted 10%

Band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.

Post-Chrysalis IOTA addresses are derived from a hash of the Ed25519 public key rather than being the key itself, so unspent, never-signed holdings are not yet harvestable. Any address that has signed has published its key. source

Placement in the band A 4 rather than a 3: the hashed-address model means never-signed holdings are not yet harvestable, which is better than the account-model chains sharing this band. Not a 5, because no measurement of IOTA's exposed share was found.

6 Verification 6/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

IOTA's protocol and identity libraries are open source and the signature change is documented in a public Tangle Improvement Proposal, so the facts are checkable. The deduction is for the gap between the documented reality and the widely circulated claim that IOTA is quantum-resistant, which IOTA has not prominently corrected. source

Placement in the band The floor of the band: the libraries are open source and the signature change is documented in a public improvement proposal, so the facts are checkable. It cannot go higher while the widely circulated quantum-resistance claim stands uncorrected by IOTA itself.

The deployment dimension is not a separate judgement. It is Tier 5 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. IOTA is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains IOTA sits among, out of 31 rated. The last column is the gap in Hardy points from IOTA.

Chains ranked immediately around IOTA, with tier, Hardy Score and the gap to IOTA
Rank Chain Tier Hardy vs IOTA
17 Cardano 3: Committed 37.5 +19.0
18 Tron 4: Debating 34.5 +16.0
19 BNB Chain 4: Debating 22.5 +4.0
20 Monero 4: Debating 21.0 +2.5
21 IOTA this chain 5: Exposed 18.5
22 Bitcoin 4: Debating 17.0 -1.5
23 Internet Computer 5: Exposed 14.5 -4.0
24 TON 5: Exposed 13.0 -5.5
25 Litecoin 5: Exposed 12.5 -6.0

Roadmap

  1. 2017 shipped

    IOTA launches using Winternitz one-time signatures over the ternary Kerl hash, a hash-based scheme resistant to Shor's algorithm but limited to one safe signature per address. source

  2. 2021 shipped

    The Chrysalis upgrade replaces Winternitz one-time signatures with Ed25519, adopting reusable addresses and standard tooling and removing IOTA's quantum resistance at layer 1. source

  3. IOTA Identity v1.7 shipped

    IOTA Identity adds ML-DSA, SLH-DSA and Falcon, plus hybrid EdDSA combinations, for issuing and verifying post-quantum verifiable credentials. source

  4. No date published proposed

    No published plan or date for restoring post-quantum signatures to IOTA's layer-1 transaction signing was found at the time of writing. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Post-Chrysalis IOTA addresses are Blake2b hashes of Ed25519 public keys, so a funded address that has never signed does not have its key on-chain and is not harvestable today. Once an address signs, the key is published. IOTA's earlier Winternitz addresses had the opposite property in a stricter form: signing even once from a Winternitz address published enough key material that signing a second time was unsafe, which is the usability problem Chrysalis was designed to solve.

What this rating means for you

If you hold IOTA

IOTA runs quantum-vulnerable signatures with no published post-quantum plan that we could find. Nothing here is urgent today, and there is also nothing scheduled to change it.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show IOTA's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/iota"><img src="https://hardyindex.com/badge/iota.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/iota.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is IOTA quantum-safe?

No, not since 2021. IOTA's layer-1 transactions are signed with Ed25519, which a sufficiently large quantum computer would break. IOTA was quantum-resistant before the Chrysalis upgrade, when it used Winternitz one-time signatures, and that earlier fact is the source of the claim still widely repeated today.

Why did IOTA give up its quantum-resistant signatures?

Usability. Winternitz one-time signatures are safe for exactly one signature per address; from the second signature onward, enough key material has been exposed that the funds on that address are considered insecure. Chrysalis replaced the scheme with Ed25519 to get reusable addresses, standard cryptographic tooling and a conventional developer experience.

Does IOTA have any post-quantum cryptography today?

Yes, but not where tokens live. IOTA Identity v1.7 supports ML-DSA, SLH-DSA and Falcon, plus hybrid combinations with EdDSA, for issuing and verifying verifiable credentials and presentations. That is a genuine post-quantum capability in the identity layer. It does not protect IOTA balances, which are still secured by Ed25519.

Is IOTA planning to bring back post-quantum signatures at layer 1?

IOTA has stated an intention to adopt future quantum-resistant standards, but at the time of writing we could not find a published roadmap, a named scheme, an improvement proposal or a research programme for layer-1 transaction signing. A stated intention on its own no longer clears the Debating floor, which asks for a proposal or a research programme aimed at the chain's own signatures. That absence, rather than the absence of intent, is what places IOTA in Tier 5: Exposed.

Sources

  1. TIP-0009: Ed25519 Signature Scheme IOTA Foundation (Tangle Improvement Proposals) · primary · checked 11 August 2026
  2. Post-Quantum Cryptography: IOTA Identity IOTA Foundation · primary · checked 11 August 2026
  3. FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) NIST · primary · checked 11 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). IOTA: quantum readiness assessment. Hardy Score 18.5 of 100, Tier 5: Exposed. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/iota

BibTeX
@misc{hardyindex_iota_2026,
  author       = {{The Hardy Index}},
  title        = {IOTA: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/iota}},
  note         = {Hardy Score 18.5 of 100, Tier 5: Exposed. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/iota.md.

This is a security-readiness assessment, not investment advice.