1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Monero mainnet signs with Ed25519 and its CLSAG ring signatures, stealth addresses and Bulletproofs all rest on the same elliptic curve. No post-quantum signature is available on mainnet in any form, opt-in or otherwise.
source
2 Deployment stage 2/10, weighted 25%
Band 2: Tier 4: Debating.
Tier 4: Debating. The threat is acknowledged in Monero's own funded research and candidate schemes have been named and analysed, but no scheme has been selected, no timeline is published and nothing post-quantum is running on mainnet.
source
3 NIST alignment 3/10, weighted 15%
Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.
No NIST scheme has been selected or committed to. The candidates Monero's research names are drawn from the lattice, hash, multivariate and supersingular isogeny families, and the specific protocols discussed, MatRiCT and Raptor linkable ring signatures, are academic constructions rather than NIST standards. A privacy chain needs linkable ring signatures and confidential transactions, and NIST has standardised neither, so a standardised drop-in does not exist for Monero in the way it does for a transparent chain.
source
Placement in the band The floor of the band rather than a 4 or a 5: the constructions Monero's research names are academic rather than standardised, and NIST has standardised neither linkable ring signatures nor confidential transactions, so no standardised drop-in exists for a privacy chain at all.
4 Migration path 4/10, weighted 15%
Band 3 to 5: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.
Migration is acknowledged as a problem with no agreed mechanism. Monero's advantage is governance: it has a long record of shipping consensus-breaking hard forks on a regular cadence, so it can enact a protocol change once one is agreed, which several larger chains cannot. The offsetting problem is that replacing ring signatures, stealth addresses and range proofs together is a far larger change than swapping a signature scheme, and the candidates carry substantial size and verification costs.
source
Placement in the band A 4 rather than a 3: Monero's record of shipping consensus-breaking hard forks on a regular cadence means it could enact a change once one is agreed, which several larger chains could not. It cannot reach 5 because no mechanism is agreed and the change required is far larger than a signature swap.
5 Exposure 1/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
Structurally the worst position in the index. Monero publishes a one-time output public key on-chain for every output, so there is no equivalent of an unspent address whose key has never been revealed. Monero's own research describes an adversary using publicly available on-chain information to extract private keys. Exposure here also carries a second cost no other chain in this index has: the same break would identify true inputs inside historical ring signatures and unmask senders retroactively.
source
Placement in the band Not a 0, because breaking Monero still requires an adversary to do work against the ring signature and stealth address construction rather than simply reading a balance. Not a 2, because a one-time output public key is published for every output, so no unspent-and-unrevealed category exists at all.
6 Verification 9/10, weighted 5%
Band 9 to 10: Open source, independently audited, with the claim checkable on-chain or in public research.
Monero makes no post-quantum claim, and its published research says plainly that its primitives are vulnerable. The protocol is open source, the 2020 study was community-funded through the Monero CCS and published in full with a technical position paper and a non-technical summary, and the research lab's discussion of post-quantum strategy is public and ongoing. There is no marketing claim here to verify, which is itself the finding.
source
Placement in the band Not a 10: the openness is complete and the research was funded and published in full, but what is verifiable here is the absence of a claim rather than the presence of a working post-quantum component.