---
title: Is Monero quantum-safe?
chain: Monero
ticker: XMR
hardy_score: 21
rank: 20 of 31
tier: "4: Debating"
url: "https://hardyindex.com/chains/monero"
updated: 2026-08-15
reviewed: 2026-10-02
methodology_version: 1.4
---

# Is Monero quantum-safe?

**Hardy Score 21.0 / 100. Rank 20 of 31. Tier 4: Debating. As of 2 October 2026.** Sources last verified 2 October 2026; last substantive change 15 August 2026.

No. Monero signs with Ed25519 and builds its ring signatures, stealth addresses and range proofs on the same elliptic curve, so a sufficiently large quantum computer breaks all of them. Monero's position is unusual in this index because it has two things to lose rather than one. A quantum adversary could extract private keys and spend outputs, which is the risk every chain here faces, and could also identify the true input inside a historical ring signature and unmask the sender, which is a risk specific to a privacy chain and which applies retroactively to transactions already recorded. Monero acknowledged this early: the community crowdfunded a dedicated post-quantum research programme that ran from June to October 2020 and published a Monero Research Lab position paper on the vulnerabilities and the candidate replacements. That work identified lattice-based options such as MatRiCT and Raptor linkable ring signatures, and research since has explored a post-quantum addressing scheme. None of it is deployed, none of it is scheduled, and no scheme has been selected.

> This is a security-readiness assessment, not investment advice.

## Summary

Monero funded and completed a post-quantum research programme in 2020 and has published candidate schemes since, but no post-quantum work is deployed and a quantum adversary would break its privacy retroactively as well as its funds.

## Where we are making a judgement call

Monero's tier records that no post-quantum scheme is selected or scheduled, not that the problem is being ignored. Monero funded and completed dedicated research on this in 2020, earlier than most chains in this index, and its researchers have been candid about the vulnerabilities in public. The gap is between analysis and deployment. Readers who weigh early, honest research more heavily than we do would place Monero at the top of Tier 4 rather than in the middle of it, and that is a reasonable disagreement.

## Score breakdown

| # | Dimension | Score | Weight | Contribution |
|---:|---|---:|---:|---:|
| 1 | Signature scheme | 0/10 | 30% | 0.0 |
| 2 | Deployment stage | 2/10 | 25% | 5.0 |
| 3 | NIST alignment | 3/10 | 15% | 4.5 |
| 4 | Migration path | 4/10 | 15% | 6.0 |
| 5 | Exposure | 1/10 | 10% | 1.0 |
| 6 | Verification | 9/10 | 5% | 4.5 |
| | **Hardy Score** | | | **21.0** |

### 1. Signature scheme: 0/10

Anchor band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Monero mainnet signs with Ed25519 and its CLSAG ring signatures, stealth addresses and Bulletproofs all rest on the same elliptic curve. No post-quantum signature is available on mainnet in any form, opt-in or otherwise.

Source: https://github.com/insight-decentralized-consensus-lab/post-quantum-monero/blob/master/writeups/semitechnical_summary.MD

### 2. Deployment stage: 2/10

Anchor band 2: Tier 4: Debating.

Tier 4: Debating. The threat is acknowledged in Monero's own funded research and candidate schemes have been named and analysed, but no scheme has been selected, no timeline is published and nothing post-quantum is running on mainnet.

Source: https://ccs.getmonero.org/proposals/research-post-quantum-monero.html

### 3. NIST alignment: 3/10

Anchor band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.

No NIST scheme has been selected or committed to. The candidates Monero's research names are drawn from the lattice, hash, multivariate and supersingular isogeny families, and the specific protocols discussed, MatRiCT and Raptor linkable ring signatures, are academic constructions rather than NIST standards. A privacy chain needs linkable ring signatures and confidential transactions, and NIST has standardised neither, so a standardised drop-in does not exist for Monero in the way it does for a transparent chain.

Placement in the band: The floor of the band rather than a 4 or a 5: the constructions Monero's research names are academic rather than standardised, and NIST has standardised neither linkable ring signatures nor confidential transactions, so no standardised drop-in exists for a privacy chain at all.

Source: https://github.com/insight-decentralized-consensus-lab/post-quantum-monero/blob/master/writeups/semitechnical_summary.MD

### 4. Migration path: 4/10

Anchor band 3 to 5: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.

Migration is acknowledged as a problem with no agreed mechanism. Monero's advantage is governance: it has a long record of shipping consensus-breaking hard forks on a regular cadence, so it can enact a protocol change once one is agreed, which several larger chains cannot. The offsetting problem is that replacing ring signatures, stealth addresses and range proofs together is a far larger change than swapping a signature scheme, and the candidates carry substantial size and verification costs.

Placement in the band: A 4 rather than a 3: Monero's record of shipping consensus-breaking hard forks on a regular cadence means it could enact a change once one is agreed, which several larger chains could not. It cannot reach 5 because no mechanism is agreed and the change required is far larger than a signature swap.

Source: https://github.com/monero-project/research-lab/issues/131

### 5. Exposure: 1/10

Anchor band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

Structurally the worst position in the index. Monero publishes a one-time output public key on-chain for every output, so there is no equivalent of an unspent address whose key has never been revealed. Monero's own research describes an adversary using publicly available on-chain information to extract private keys. Exposure here also carries a second cost no other chain in this index has: the same break would identify true inputs inside historical ring signatures and unmask senders retroactively.

Placement in the band: Not a 0, because breaking Monero still requires an adversary to do work against the ring signature and stealth address construction rather than simply reading a balance. Not a 2, because a one-time output public key is published for every output, so no unspent-and-unrevealed category exists at all.

Source: https://github.com/insight-decentralized-consensus-lab/post-quantum-monero/blob/master/writeups/semitechnical_summary.MD

### 6. Verification: 9/10

Anchor band 9 to 10: Open source, independently audited, with the claim checkable on-chain or in public research.

Monero makes no post-quantum claim, and its published research says plainly that its primitives are vulnerable. The protocol is open source, the 2020 study was community-funded through the Monero CCS and published in full with a technical position paper and a non-technical summary, and the research lab's discussion of post-quantum strategy is public and ongoing. There is no marketing claim here to verify, which is itself the finding.

Placement in the band: Not a 10: the openness is complete and the research was funded and published in full, but what is verifiable here is the absence of a claim rather than the presence of a working post-quantum component.

Source: https://ccs.getmonero.org/proposals/research-post-quantum-monero.html

## Nearest chains in the ranking

The chains Monero sits among, out of 31 rated. The last column is the gap in Hardy points from Monero.

| Rank | Chain | Tier | Hardy | vs XMR |
|---:|---|---|---:|---:|
| 16 | [Ethereum](https://hardyindex.com/chains/ethereum) | 3: Committed | 40.0 | +19.0 |
| 17 | [Cardano](https://hardyindex.com/chains/cardano) | 3: Committed | 37.5 | +16.5 |
| 18 | [Tron](https://hardyindex.com/chains/tron) | 4: Debating | 34.5 | +13.5 |
| 19 | [BNB Chain](https://hardyindex.com/chains/bnb-chain) | 4: Debating | 22.5 | +1.5 |
| 20 | **Monero** | 4: Debating | 21.0 | this chain |
| 21 | [IOTA](https://hardyindex.com/chains/iota) | 5: Exposed | 18.5 | -2.5 |
| 22 | [Bitcoin](https://hardyindex.com/chains/bitcoin) | 4: Debating | 17.0 | -4.0 |
| 23 | [Internet Computer](https://hardyindex.com/chains/internet-computer) | 5: Exposed | 14.5 | -6.5 |
| 24 | [TON](https://hardyindex.com/chains/toncoin) | 5: Exposed | 13.0 | -8.0 |

## Signature scheme

- **On mainnet today:** Ed25519 for signing; CLSAG linkable ring signatures, stealth addresses and Bulletproofs, all over the same curve
- **Post-quantum scheme:** None deployed. Lattice-based candidates including MatRiCT and Raptor linkable ring signatures have been analysed in Monero's own research.
- **NIST standard:** None committed. NIST has standardised no linkable ring signature or confidential transaction scheme, so no standardised replacement exists for Monero's design.
- **Readiness tier:** Tier 4: Debating. Post-quantum work on the chain’s own signatures is documented by people with authority over it, in a formal improvement proposal or a public research programme, but no scheme is agreed and no timeline is published.

## Roadmap

- **June 2020** (shipped): Monero's community crowdfunding system funds a dedicated post-quantum research programme at 576 XMR across 58 contributors, led by Insight's head of research with a researcher in residence.
  Source: https://ccs.getmonero.org/proposals/research-post-quantum-monero.html
- **October 2020** (shipped): The programme completes, publishing a Monero Research Lab position paper on quantum vulnerabilities and candidate mitigations, a semi-technical summary and public outreach material.
  Source: https://github.com/insight-decentralized-consensus-lab/post-quantum-monero/blob/master/writeups/semitechnical_summary.MD
- **No selection or date** (proposed): Post-quantum strategy remains an open research discussion in the Monero Research Lab. No scheme has been selected, no implementation is scheduled and no activation timeline exists.
  Source: https://github.com/monero-project/research-lab/issues/131

## Exposure

Monero inverts the usual exposure question. On a transparent chain the interesting number is what share of supply sits in addresses whose public key has already been revealed, and the answer is usually a fraction. Monero publishes a one-time output public key on-chain for every single output, so the fraction is effectively all of it and there is no hygiene a holder can practise to avoid it. The second cost is the one that matters more to Monero's users. Because ring signatures and their linkability tags rest on the same curve, a quantum adversary would not only be able to spend, but could go back through the recorded chain and determine which ring member was the true input, unmasking senders in transactions that were private when they were made. Privacy, unlike custody, cannot be restored by moving funds to a new scheme later.

## Frequently asked questions

### Is Monero quantum-safe?

No. Monero signs with Ed25519 and builds its ring signatures, stealth addresses and range proofs on the same elliptic curve, so a sufficiently large quantum computer breaks all of them. Monero's position is unusual in this index because it has two things to lose rather than one. A quantum adversary could extract private keys and spend outputs, which is the risk every chain here faces, and could also identify the true input inside a historical ring signature and unmask the sender, which is a risk specific to a privacy chain and which applies retroactively to transactions already recorded. Monero acknowledged this early: the community crowdfunded a dedicated post-quantum research programme that ran from June to October 2020 and published a Monero Research Lab position paper on the vulnerabilities and the candidate replacements. That work identified lattice-based options such as MatRiCT and Raptor linkable ring signatures, and research since has explored a post-quantum addressing scheme. None of it is deployed, none of it is scheduled, and no scheme has been selected.

### Is Monero quantum-safe?

No. Monero signs with Ed25519 and its ring signatures, stealth addresses and range proofs are all built on the same elliptic curve, every one of which a sufficiently large quantum computer breaks. No post-quantum scheme is deployed on Monero mainnet and none has been selected.

### Would a quantum computer break Monero's privacy as well as its funds?

Yes, and that is the part specific to Monero. Monero's own research describes an adversary extracting the private transaction key from the linkability tag, which would identify the true input inside a ring signature and unmask the sender. Because the chain is a permanent record, that break would apply retroactively to transactions that were private at the time they were made. Funds can be moved to a new scheme later; privacy already spent cannot be recovered.

### Has Monero done anything about the quantum threat?

Yes, earlier than most. In 2020 the Monero community crowdfunded a dedicated post-quantum research programme through its community crowdfunding system, at 576 XMR from 58 contributors. It ran from June to October 2020 and delivered a Monero Research Lab position paper on the vulnerabilities and candidate replacements, plus a semi-technical summary. What it did not deliver, and was not scoped to deliver, was a deployment plan.

### Why does Monero score low on NIST alignment when it has done real research?

Because NIST has not standardised anything Monero could adopt directly. The NIST post-quantum standards cover signatures and key encapsulation, not linkable ring signatures or confidential transactions, which are what Monero's privacy model actually requires. The candidates its researchers name, such as MatRiCT and Raptor, are academic constructions rather than standards. A transparent chain can plan to adopt ML-DSA; Monero has no equivalent shelf to reach for.

## What this rating means if you hold Monero

Plain-language guidance from the same publication, with no product recommendation attached.

- [Is my crypto safe from quantum computers?](https://hardyindex.com/guides/is-my-crypto-safe-from-quantum-computers.md)
- [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers.md)
- [All guides](https://hardyindex.com/guides.md)

Nothing on this profile is sponsored and nothing on it is an affiliate link. See https://hardyindex.com/how-we-make-money.md.

## What we have published about Monero

- [A stale chain count was corrected, and news posts came under the claims guard on 19 August 2026](https://hardyindex.com/news/stale-chain-count-corrected-and-news-posts-brought-under-the-claims-guard.md): A post published on 19 August 2026 carried a count that had been true six days earlier, and nothing was checking it. Published 13 September 2026.
- [Monero and Mochimo joined the index on 13 August 2026](https://hardyindex.com/news/monero-and-mochimo-join-the-index.md): Two rows added on 13 August for opposite reasons: one was the biggest gap we had left, the other signs with no elliptic curve at all. Published 19 August 2026.

## Sources

1. [CCS: Research post-quantum strategies for Monero](https://ccs.getmonero.org/proposals/research-post-quantum-monero.html): Monero Community Crowdfunding System (primary, checked 13 August 2026)
2. [Post-quantum Monero: semi-technical summary](https://github.com/insight-decentralized-consensus-lab/post-quantum-monero/blob/master/writeups/semitechnical_summary.MD): Insight Decentralized Consensus Lab (primary, checked 13 August 2026)
3. [Discussion: post-quantum security and ethical considerations over elliptic curve cryptography](https://github.com/monero-project/research-lab/issues/131): Monero Research Lab (primary, checked 13 August 2026)
4. [Zero to Monero, second edition](https://www.getmonero.org/library/Zero-to-Monero-2-0-0.pdf): Monero (primary, checked 13 August 2026)

## How to cite this rating

A rating is only true as of the day it was reviewed, so both forms carry the review date and the methodology version. If you are quoting the score, quote those too.

The Hardy Index (2026). Monero: quantum readiness assessment. Hardy Score 21.0 of 100, Tier 4: Debating. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/monero

```bibtex
@misc{hardyindex_monero_2026,
  author       = {{The Hardy Index}},
  title        = {Monero: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/monero}},
  note         = {Hardy Score 21.0 of 100, Tier 4: Debating. Methodology v1.4},
  urldate      = {2026-10-02}
}
```

---

Methodology: https://hardyindex.com/methodology (v1.4).
Cite as: The Hardy Index, "Monero", https://hardyindex.com/chains/monero, as of 2 October 2026.
