Hardy Index Quantum readiness benchmark

Chain profile

Nervos CKB

CKB Shipping

An audited SPHINCS+ lock script is deployed on CKB mainnet, so users can hold funds under a NIST-standardised post-quantum signature today without a hard fork.

Is Nervos CKB quantum-safe?

Partly, and by user choice rather than by default. Nervos CKB does not hardcode a signature algorithm into its consensus rules. Signature verification runs as a Lock Script on a RISC-V virtual machine, so a post-quantum scheme can be added without changing the protocol. The CKB team used that property to build a SPHINCS+ lock script, audited by ScaleBit, and began deploying it on mainnet in 2025 alongside a wallet that uses it. A CKB holder can therefore move funds to a quantum-resistant address today, permissionlessly and without a fork. What CKB has not done is make that the default: ordinary CKB addresses still use secp256k1, which a sufficiently large quantum computer would break, and the large majority of supply still sits under those classical locks.

Where we are making a judgement call CKB sits in Tier 2 on the strength of an opt-in lock script rather than a protocol-level default. We treat a scheme that protects real mainnet funds today as shipped, even when adoption is small, because that is the literal test the tier sets. Readers who weight default protection more heavily than availability should read this placement as generous.

At a glance

On mainnet today

secp256k1 by default; SPHINCS+ available via an on-chain lock script

Post-quantum scheme

SPHINCS+ (SLH-DSA), twelve selectable parameter sets

NIST standard

FIPS 205 (SLH-DSA), finalised August 2024

Readiness tier

Tier 2: Shipping. Post-quantum signature features are live on mainnet and a migration for existing holders is underway.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Nervos Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 6 30% 18.0
2 Deployment stage 8 25% 20.0
3 NIST alignment 10 15% 15.0
4 Migration path 9 15% 13.5
5 Exposure 5 10% 5.0
6 Verification 8 5% 4.0
Hardy Score 75.5

1 Signature scheme 6/10, weighted 30%

Band 4 to 6: A post-quantum signature is available on mainnet only as an opt-in, application-level or experimental primitive.

SPHINCS+ is available on mainnet as an audited, production-ready lock script supporting twelve parameter sets, and a desktop wallet ships with it. It is opt-in rather than the default, and normal CKB addresses remain secp256k1. source

Placement in the band The top of the band rather than a 4 or a 5: the lock script is audited, production-ready and shipped in a desktop wallet, which is well past experimental. It cannot reach 7 because it is opt-in at the application layer and normal CKB addresses remain secp256k1.

2 Deployment stage 8/10, weighted 25%

Band 8: Tier 2: Shipping.

Tier 2: Shipping. A post-quantum signature scheme protects real funds on CKB mainnet today and users can migrate to it now, which is the defining test for this tier. source

3 NIST alignment 10/10, weighted 15%

Band 9 to 10: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).

SPHINCS+ was standardised by NIST as SLH-DSA in FIPS 205 in August 2024. CKB is using a finalised standard rather than a candidate, which of the chains in this index only NEAR also does for a scheme live on mainnet. source

Placement in the band A 10 rather than a 9: SLH-DSA is final in FIPS 205 and the scheme is live on mainnet, so this is a finalised standard actually in use rather than one named for future adoption.

4 Migration path 9/10, weighted 15%

Band 9 to 10: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.

CKB's migration is among the cleanest in the index. A user creates an address referencing the new lock script's code hash and transfers assets to it. No hard fork is required, the network does not need to coordinate, old addresses keep working, and the upgrade can proceed gradually and permissionlessly. source

Placement in the band Not a 10: holders can migrate today with no fork and no coordination, which is what puts this at the top of the band, but migration is manual and per-holder rather than something the protocol performs, and most supply has not moved.

5 Exposure 5/10, weighted 10%

Band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.

CKB uses a cell model in which addresses commit to a lock script hash, so a public key is not revealed until an output is spent. That limits exposure compared with account-model chains where the address is the public key, but the majority of supply still sits under secp256k1 locks and every spent cell has revealed its key. source

Placement in the band The top of the band rather than a 3 or a 4: the cell model reveals a key only when an output is spent, so never-spent holdings stay unharvestable. It cannot reach 6 because most supply still sits under secp256k1 locks and every spent cell has published its key.

6 Verification 8/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

The quantum-resistant lock script is open source and completed a security audit by ScaleBit. The claim is checkable on-chain and in the public repository rather than resting on marketing. source

Placement in the band The top of the band: the lock script completed a named third-party audit by ScaleBit, which is what the upper half of this band asks for. It stops short of 9 because the audit covers an opt-in script rather than a protocol-wide deployment.

The deployment dimension is not a separate judgement. It is Tier 2 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Nervos CKB is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Nervos sits among, out of 31 rated. The last column is the gap in Hardy points from Nervos.

Chains ranked immediately around Nervos CKB, with tier, Hardy Score and the gap to Nervos CKB
Rank Chain Tier Hardy vs CKB
2 Mochimo 1: Native 90.0 +14.5
3 Abelian 1: Native 84.5 +9.0
4 NEAR Protocol 2: Shipping 81.5 +6.0
5 Algorand 2: Shipping 77.5 +2.0
6 Nervos CKB this chain 2: Shipping 75.5
7 Bitcoin Cash 2: Shipping 66.0 -9.5
8 Solana 2: Shipping 54.5 -21.0
9 XRP Ledger 3: Committed 46.5 -29.0
10 Sui 3: Committed 45.5 -30.0

Roadmap

  1. 2023 shipped

    CKB team and Cryptape researchers implement a production-ready quantum-resistant lock script using SPHINCS+. source

  2. August 2024 shipped

    NIST approves SPHINCS+ as SLH-DSA under FIPS 205, giving the deployed scheme a finalised standard. source

  3. 2025 shipped

    The CKB team begins deploying the SPHINCS+ lock script on CKB mainnet, after a security audit by ScaleBit. source

  4. February 2026 shipped

    The Quantum Purse desktop wallet ships, giving non-technical holders a route to SPHINCS+-locked funds. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

CKB's cell model means an address commits to the hash of a lock script rather than to a public key directly, so a key is only revealed when a cell is spent. Unspent, never-spent holdings under secp256k1 are therefore not yet harvestable. This is materially better than account-model chains where every account's public key is on-chain from the first transaction, but it is the same structural position as Bitcoin: reuse and spending progressively expose the network, and the protection erodes rather than holds.

What this rating means for you

If you hold Nervos

Nervos has post-quantum signatures live on mainnet, but they are not the default, so holders have to opt in. That makes this one of the few chains where you can act today rather than wait.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Nervos CKB's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/nervos-ckb"><img src="https://hardyindex.com/badge/nervos-ckb.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/nervos-ckb.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Nervos CKB quantum-safe?

It can be, if a holder chooses it. CKB has an audited SPHINCS+ lock script deployed on mainnet, so funds moved to a SPHINCS+ address are protected by a NIST-standardised post-quantum signature today. Funds left in ordinary CKB addresses use secp256k1 and remain quantum-vulnerable.

Why does CKB not need a hard fork to add post-quantum signatures?

Because CKB does not hardcode a signature algorithm in its consensus rules. Signature verification is implemented as a Lock Script running on a RISC-V virtual machine, so a new cryptographic scheme is deployed as a script on-chain rather than as a protocol change. Users adopt it by creating addresses that reference the new script's code hash.

Has the SPHINCS+ lock script been audited?

Yes. The Nervos documentation states the quantum-resistant lock script completed a security audit conducted by ScaleBit, and the implementation is open source in the nervosnetwork/quantum-resistant-lock-script repository, so the audit claim and the code can both be checked independently.

How much CKB is actually protected by SPHINCS+?

A small share. Deployment began in 2025 and the wallet supporting it shipped in 2026, so the overwhelming majority of CKB supply still sits under secp256k1 locks. Availability is not adoption, and this index scores CKB's signature dimension at 6 rather than higher for exactly that reason.

Sources

  1. Native Quantum Resistance Nervos CKB documentation · primary · checked 11 August 2026
  2. quantum-resistant-lock-script Nervos Network (GitHub) · primary · checked 11 August 2026
  3. FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) NIST · primary · checked 11 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Nervos CKB: quantum readiness assessment. Hardy Score 75.5 of 100, Tier 2: Shipping. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/nervos-ckb

BibTeX
@misc{hardyindex_nervos_ckb_2026,
  author       = {{The Hardy Index}},
  title        = {Nervos CKB: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/nervos-ckb}},
  note         = {Hardy Score 75.5 of 100, Tier 2: Shipping. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/nervos-ckb.md.

This is a security-readiness assessment, not investment advice.