Hardy Index Quantum readiness benchmark

Chain profile

Mochimo

MCM Native

Mochimo has signed every mainnet transaction with hash-based WOTS+ since launching in June 2018, and its node source contains no elliptic-curve signature implementation at all.

Is Mochimo quantum-safe?

Yes, on the signature question that this index measures. Mochimo launched in June 2018 with WOTS+, the Winternitz one-time signature scheme, as its signing algorithm, and it has never carried a classical alternative. We verified this in the node source rather than taking it from project material: src/wots.h and src/wots.c implement WOTS+ with a 32-byte parameter n and Winternitz parameter w of 16, citing RFC 8391, the specification that defines XMSS and the WOTS+ construction inside it. They are the only signature implementation in the repository. There is no ECDSA, secp256k1, Ed25519 or Schnorr source anywhere in the tree, which means post-quantum signing is not an opt-in mode on Mochimo but the only way a transaction can be made. WOTS+ security rests on hash functions rather than the discrete logarithm problem, so Shor's algorithm does not apply to it. The qualifier is on standards rather than on security: Mochimo uses WOTS+ standalone, and the NIST-approved hash-based schemes are the fuller constructions built on top of it.

Where we are making a judgement call Two things about this row are worth stating plainly. First, our signature and deployment scores rest on our own reading of the node source rather than on a specification we could check them against, because Mochimo's wiki documentation was unreachable while we were writing. Reading the code is the stronger evidence for what is deployed, but it means the account tag mechanism described here is inferred from protocol source and test files rather than from a published spec. Second, we found no named third-party audit of the WOTS+ implementation. Mochimo scores highly here because of what it deployed and when, not because its implementation has been independently reviewed to the standard a large chain would face.

At a glance

On mainnet today

WOTS+ (Winternitz one-time signature), hash-based, with PARAMSN 32 and WOTSW 16 per RFC 8391

Post-quantum scheme

WOTS+ itself. Mochimo has been post-quantum since genesis rather than adding a scheme later.

NIST standard

None directly. RFC 8391 defines WOTS+ and underpins NIST SP 800-208, but SP 800-208 approves XMSS and LMS rather than standalone WOTS+.

Readiness tier

Tier 1: Native. Post-quantum secure at mainnet today, with quantum-resistant signatures built in from genesis.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Mochimo Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 10 30% 30.0
2 Deployment stage 10 25% 25.0
3 NIST alignment 7 15% 10.5
4 Migration path 8 15% 12.0
5 Exposure 9 10% 9.0
6 Verification 7 5% 3.5
Hardy Score 90.0

1 Signature scheme 10/10, weighted 30%

Band 10: A post-quantum signature is the mandatory scheme for all accounts on mainnet.

WOTS+ is the mandatory scheme for every account on Mochimo mainnet, verified in the node source rather than from project claims. src/wots.h defines PARAMSN 32 and WOTSW 16 with a verbatim reference to RFC 8391, and the repository contains no ECDSA, secp256k1, Ed25519 or Schnorr implementation, so there is no classical path a transaction could take. source

2 Deployment stage 10/10, weighted 25%

Band 10: Tier 1: Native.

Tier 1: Native. Hash-based signatures have protected every unit of supply since the mainnet launched in June 2018, so there is no migration to run and no legacy cohort left behind. source

3 NIST alignment 7/10, weighted 15%

Band 6 to 8: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.

This is the one place Mochimo's position is weaker than it first looks, and the distinction is worth stating precisely. Mochimo implements WOTS+ exactly as RFC 8391 specifies it, and that same document underpins NIST SP 800-208. But SP 800-208 approves the fuller constructions, XMSS and LMS with their multi-tree variants, not the bare WOTS+ one-time signature used on its own. Mochimo is therefore using a standardised primitive in a way the standard does not itself cover, which is a long way from bespoke unreviewed cryptography and still short of a chain running an approved scheme. source

Placement in the band A 7 rather than an 8 or a 6: Mochimo implements a standardised primitive, RFC 8391 WOTS+, but uses it bare where SP 800-208 approves only the fuller XMSS and LMS constructions. That is well clear of bespoke cryptography and still short of running an approved scheme.

4 Migration path 8/10, weighted 15%

Band 6 to 8: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.

There is no classical legacy to migrate, which removes the hardest problem facing every chain in this index that did not launch post-quantum. What replaces it is an operational one: WOTS+ keys are one-time, so a key that signs twice leaks enough material to forge, and that is a classical weakness rather than a quantum one. Mochimo addresses this at the protocol level with account tags, resolved to public keys and validated in the node source, which lets an account identity persist across the key rotation the scheme requires. source

Placement in the band The top of the band because there is no classical legacy to migrate at all. It is not a 9 because the one-time key constraint imposes a permanent operational migration on every holder, which account tags manage rather than remove.

5 Exposure 9/10, weighted 10%

Band 9 to 10: No quantum-vulnerable public keys are exposed on-chain, or the exposed keys protect nothing.

No Mochimo public key is a quantum liability, because WOTS+ security rests on the preimage and collision resistance of hash functions rather than on the discrete logarithm problem. A published WOTS+ public key gives a quantum adversary nothing Shor's algorithm can use, so the harvest-now-decrypt-later question that drives this dimension for every classical chain does not arise. source

Placement in the band Not a perfect ten: the one-time constraint means key reuse rather than key exposure is the failure mode a holder must avoid, so the dimension is clean on quantum grounds but not on operational ones.

6 Verification 7/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

The claim is checkable in the strongest way available: the signature implementation is open source, the mainnet has run since 2018, and the absence of any classical signature code can be confirmed by reading the repository, which is how we scored the signature dimension. source

Placement in the band A 7 rather than an 8: the code is open and the absence of classical signature code is directly checkable, which is strong public review, but no named third-party audit was found and the project's own wiki was unreachable at the time of writing.

The deployment dimension is not a separate judgement. It is Tier 1 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Mochimo is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Mochimo sits among, out of 31 rated. The last column is the gap in Hardy points from Mochimo.

Chains ranked immediately around Mochimo, with tier, Hardy Score and the gap to Mochimo
Rank Chain Tier Hardy vs MCM
1 Quantum Resistant Ledger 1: Native 92.0 +2.0
2 Mochimo this chain 1: Native 90.0
3 Abelian 1: Native 84.5 -5.5
4 NEAR Protocol 2: Shipping 81.5 -8.5
5 Algorand 2: Shipping 77.5 -12.5
6 Nervos CKB 2: Shipping 75.5 -14.5
7 Bitcoin Cash 2: Shipping 66.0 -24.0
8 Solana 2: Shipping 54.5 -35.5
9 XRP Ledger 3: Committed 46.5 -43.5

Roadmap

  1. 25 June 2018 shipped

    Mochimo mainnet launches with WOTS+ hash-based signatures as the only signing algorithm, making it one of the earliest live post-quantum layer 1s. source

  2. 11 December 2018 shipped

    RFC 8391, which specifies the WOTS+ construction Mochimo implements, moves from draft to published RFC. The node source records the change in its header comments. source

  3. October 2020 shipped

    NIST publishes SP 800-208, approving the XMSS and LMS hash-based constructions. Mochimo's standalone WOTS+ is not itself covered, which is what holds its NIST alignment below the top band. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Mochimo has no harvest-now-decrypt-later exposure in the sense this index usually means. That risk exists because a classical public key sitting on a chain today can be turned into a private key by a quantum computer later, and it applies wherever security rests on the discrete logarithm problem. WOTS+ does not: its security reduces to the hash function, and a published WOTS+ public key is not a route to the private key for any adversary, quantum or classical. The failure mode a Mochimo holder has to avoid is a different one, and it is not quantum at all. A Winternitz key is one-time, so signing twice with the same key leaks enough of the private material for anyone to forge a third signature. That is why the protocol carries account tags: an identity that persists while the key underneath it rotates.

What this rating means for you

If you hold Mochimo

Mochimo already runs post-quantum signatures for every account on mainnet, so there is no migration for you to make here. The habits that still matter are address hygiene and keeping your own keys.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Mochimo's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/mochimo"><img src="https://hardyindex.com/badge/mochimo.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/mochimo.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Mochimo quantum-safe?

On the measure this index applies, yes. Every Mochimo transaction is signed with WOTS+, a hash-based scheme whose security rests on hash functions rather than elliptic curves, so Shor's algorithm does not break it. We confirmed this by reading the node source: WOTS+ is the only signature implementation in the repository and there is no classical alternative for a transaction to use.

How do you know Mochimo actually uses WOTS+ rather than just claiming to?

We checked the source rather than the marketing. The files src/wots.h and src/wots.c in the official repository implement WOTS+ with a 32-byte hash parameter and a Winternitz parameter of 16, citing RFC 8391 in their header comments. Just as importantly, we searched the whole repository for ECDSA, secp256k1, Ed25519 and Schnorr implementations and found none, which is what makes post-quantum signing mandatory rather than optional here.

Why does Mochimo score 7 on NIST alignment rather than 9 or 10?

Because standalone WOTS+ is not itself an approved scheme. NIST SP 800-208 approves XMSS and LMS, the fuller constructions that use WOTS+ as their one-time signature component. Mochimo implements that component faithfully to RFC 8391 but uses it on its own, so it is applying a standardised primitive in a way the standard does not cover. That is much stronger than unreviewed bespoke cryptography and still short of running an approved scheme, which is what the 7 records.

What is the catch with one-time signatures?

A Winternitz key can safely sign once. Signing twice with the same key reveals enough of the private material that anyone, with no quantum computer required, could forge a further signature. This is a classical constraint rather than a quantum one, and it is why hash-based chains need a way to keep an account identity stable while the underlying key rotates. Mochimo does this with account tags at the protocol level.

Sources

  1. Mochimo node source: src/wots.h Mochimo · primary · checked 13 August 2026
  2. Mochimo node repository Mochimo · primary · checked 13 August 2026
  3. RFC 8391: XMSS, eXtended Merkle Signature Scheme IETF · primary · checked 13 August 2026
  4. NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes NIST · primary · checked 13 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Mochimo: quantum readiness assessment. Hardy Score 90.0 of 100, Tier 1: Native. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/mochimo

BibTeX
@misc{hardyindex_mochimo_2026,
  author       = {{The Hardy Index}},
  title        = {Mochimo: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/mochimo}},
  note         = {Hardy Score 90.0 of 100, Tier 1: Native. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/mochimo.md.

This is a security-readiness assessment, not investment advice.