Hardy Index Quantum readiness benchmark

Chain profile

Monero

XMR Debating

Monero funded and completed a post-quantum research programme in 2020 and has published candidate schemes since, but no post-quantum work is deployed and a quantum adversary would break its privacy retroactively as well as its funds.

Is Monero quantum-safe?

No. Monero signs with Ed25519 and builds its ring signatures, stealth addresses and range proofs on the same elliptic curve, so a sufficiently large quantum computer breaks all of them. Monero's position is unusual in this index because it has two things to lose rather than one. A quantum adversary could extract private keys and spend outputs, which is the risk every chain here faces, and could also identify the true input inside a historical ring signature and unmask the sender, which is a risk specific to a privacy chain and which applies retroactively to transactions already recorded. Monero acknowledged this early: the community crowdfunded a dedicated post-quantum research programme that ran from June to October 2020 and published a Monero Research Lab position paper on the vulnerabilities and the candidate replacements. That work identified lattice-based options such as MatRiCT and Raptor linkable ring signatures, and research since has explored a post-quantum addressing scheme. None of it is deployed, none of it is scheduled, and no scheme has been selected.

Where we are making a judgement call Monero's tier records that no post-quantum scheme is selected or scheduled, not that the problem is being ignored. Monero funded and completed dedicated research on this in 2020, earlier than most chains in this index, and its researchers have been candid about the vulnerabilities in public. The gap is between analysis and deployment. Readers who weigh early, honest research more heavily than we do would place Monero at the top of Tier 4 rather than in the middle of it, and that is a reasonable disagreement.

At a glance

On mainnet today

Ed25519 for signing; CLSAG linkable ring signatures, stealth addresses and Bulletproofs, all over the same curve

Post-quantum scheme

None deployed. Lattice-based candidates including MatRiCT and Raptor linkable ring signatures have been analysed in Monero's own research.

NIST standard

None committed. NIST has standardised no linkable ring signature or confidential transaction scheme, so no standardised replacement exists for Monero's design.

Readiness tier

Tier 4: Debating. Post-quantum work on the chain’s own signatures is documented by people with authority over it, in a formal improvement proposal or a public research programme, but no scheme is agreed and no timeline is published.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Monero Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 2 25% 5.0
3 NIST alignment 3 15% 4.5
4 Migration path 4 15% 6.0
5 Exposure 1 10% 1.0
6 Verification 9 5% 4.5
Hardy Score 21.0

1 Signature scheme 0/10, weighted 30%

Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Monero mainnet signs with Ed25519 and its CLSAG ring signatures, stealth addresses and Bulletproofs all rest on the same elliptic curve. No post-quantum signature is available on mainnet in any form, opt-in or otherwise. source

2 Deployment stage 2/10, weighted 25%

Band 2: Tier 4: Debating.

Tier 4: Debating. The threat is acknowledged in Monero's own funded research and candidate schemes have been named and analysed, but no scheme has been selected, no timeline is published and nothing post-quantum is running on mainnet. source

3 NIST alignment 3/10, weighted 15%

Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.

No NIST scheme has been selected or committed to. The candidates Monero's research names are drawn from the lattice, hash, multivariate and supersingular isogeny families, and the specific protocols discussed, MatRiCT and Raptor linkable ring signatures, are academic constructions rather than NIST standards. A privacy chain needs linkable ring signatures and confidential transactions, and NIST has standardised neither, so a standardised drop-in does not exist for Monero in the way it does for a transparent chain. source

Placement in the band The floor of the band rather than a 4 or a 5: the constructions Monero's research names are academic rather than standardised, and NIST has standardised neither linkable ring signatures nor confidential transactions, so no standardised drop-in exists for a privacy chain at all.

4 Migration path 4/10, weighted 15%

Band 3 to 5: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.

Migration is acknowledged as a problem with no agreed mechanism. Monero's advantage is governance: it has a long record of shipping consensus-breaking hard forks on a regular cadence, so it can enact a protocol change once one is agreed, which several larger chains cannot. The offsetting problem is that replacing ring signatures, stealth addresses and range proofs together is a far larger change than swapping a signature scheme, and the candidates carry substantial size and verification costs. source

Placement in the band A 4 rather than a 3: Monero's record of shipping consensus-breaking hard forks on a regular cadence means it could enact a change once one is agreed, which several larger chains could not. It cannot reach 5 because no mechanism is agreed and the change required is far larger than a signature swap.

5 Exposure 1/10, weighted 10%

Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

Structurally the worst position in the index. Monero publishes a one-time output public key on-chain for every output, so there is no equivalent of an unspent address whose key has never been revealed. Monero's own research describes an adversary using publicly available on-chain information to extract private keys. Exposure here also carries a second cost no other chain in this index has: the same break would identify true inputs inside historical ring signatures and unmask senders retroactively. source

Placement in the band Not a 0, because breaking Monero still requires an adversary to do work against the ring signature and stealth address construction rather than simply reading a balance. Not a 2, because a one-time output public key is published for every output, so no unspent-and-unrevealed category exists at all.

6 Verification 9/10, weighted 5%

Band 9 to 10: Open source, independently audited, with the claim checkable on-chain or in public research.

Monero makes no post-quantum claim, and its published research says plainly that its primitives are vulnerable. The protocol is open source, the 2020 study was community-funded through the Monero CCS and published in full with a technical position paper and a non-technical summary, and the research lab's discussion of post-quantum strategy is public and ongoing. There is no marketing claim here to verify, which is itself the finding. source

Placement in the band Not a 10: the openness is complete and the research was funded and published in full, but what is verifiable here is the absence of a claim rather than the presence of a working post-quantum component.

The deployment dimension is not a separate judgement. It is Tier 4 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Monero is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Monero sits among, out of 31 rated. The last column is the gap in Hardy points from Monero.

Chains ranked immediately around Monero, with tier, Hardy Score and the gap to Monero
Rank Chain Tier Hardy vs XMR
16 Ethereum 3: Committed 40.0 +19.0
17 Cardano 3: Committed 37.5 +16.5
18 Tron 4: Debating 34.5 +13.5
19 BNB Chain 4: Debating 22.5 +1.5
20 Monero this chain 4: Debating 21.0
21 IOTA 5: Exposed 18.5 -2.5
22 Bitcoin 4: Debating 17.0 -4.0
23 Internet Computer 5: Exposed 14.5 -6.5
24 TON 5: Exposed 13.0 -8.0

Roadmap

  1. June 2020 shipped

    Monero's community crowdfunding system funds a dedicated post-quantum research programme at 576 XMR across 58 contributors, led by Insight's head of research with a researcher in residence. source

  2. October 2020 shipped

    The programme completes, publishing a Monero Research Lab position paper on quantum vulnerabilities and candidate mitigations, a semi-technical summary and public outreach material. source

  3. No selection or date proposed

    Post-quantum strategy remains an open research discussion in the Monero Research Lab. No scheme has been selected, no implementation is scheduled and no activation timeline exists. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Monero inverts the usual exposure question. On a transparent chain the interesting number is what share of supply sits in addresses whose public key has already been revealed, and the answer is usually a fraction. Monero publishes a one-time output public key on-chain for every single output, so the fraction is effectively all of it and there is no hygiene a holder can practise to avoid it. The second cost is the one that matters more to Monero's users. Because ring signatures and their linkability tags rest on the same curve, a quantum adversary would not only be able to spend, but could go back through the recorded chain and determine which ring member was the true input, unmasking senders in transactions that were private when they were made. Privacy, unlike custody, cannot be restored by moving funds to a new scheme later.

What this rating means for you

If you hold Monero

Monero has acknowledged the threat without agreeing a plan, so nothing is going to change for holders in the near term. That makes address hygiene the part worth attending to.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Monero's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/monero"><img src="https://hardyindex.com/badge/monero.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/monero.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Monero quantum-safe?

No. Monero signs with Ed25519 and its ring signatures, stealth addresses and range proofs are all built on the same elliptic curve, every one of which a sufficiently large quantum computer breaks. No post-quantum scheme is deployed on Monero mainnet and none has been selected.

Would a quantum computer break Monero's privacy as well as its funds?

Yes, and that is the part specific to Monero. Monero's own research describes an adversary extracting the private transaction key from the linkability tag, which would identify the true input inside a ring signature and unmask the sender. Because the chain is a permanent record, that break would apply retroactively to transactions that were private at the time they were made. Funds can be moved to a new scheme later; privacy already spent cannot be recovered.

Has Monero done anything about the quantum threat?

Yes, earlier than most. In 2020 the Monero community crowdfunded a dedicated post-quantum research programme through its community crowdfunding system, at 576 XMR from 58 contributors. It ran from June to October 2020 and delivered a Monero Research Lab position paper on the vulnerabilities and candidate replacements, plus a semi-technical summary. What it did not deliver, and was not scoped to deliver, was a deployment plan.

Why does Monero score low on NIST alignment when it has done real research?

Because NIST has not standardised anything Monero could adopt directly. The NIST post-quantum standards cover signatures and key encapsulation, not linkable ring signatures or confidential transactions, which are what Monero's privacy model actually requires. The candidates its researchers name, such as MatRiCT and Raptor, are academic constructions rather than standards. A transparent chain can plan to adopt ML-DSA; Monero has no equivalent shelf to reach for.

Sources

  1. CCS: Research post-quantum strategies for Monero Monero Community Crowdfunding System · primary · checked 13 August 2026
  2. Post-quantum Monero: semi-technical summary Insight Decentralized Consensus Lab · primary · checked 13 August 2026
  3. Discussion: post-quantum security and ethical considerations over elliptic curve cryptography Monero Research Lab · primary · checked 13 August 2026
  4. Zero to Monero, second edition Monero · primary · checked 13 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Monero: quantum readiness assessment. Hardy Score 21.0 of 100, Tier 4: Debating. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/monero

BibTeX
@misc{hardyindex_monero_2026,
  author       = {{The Hardy Index}},
  title        = {Monero: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/monero}},
  note         = {Hardy Score 21.0 of 100, Tier 4: Debating. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/monero.md.

This is a security-readiness assessment, not investment advice.