Committed in August 2026 to two finalised NIST schemes, with a migration path that lets existing accounts move to quantum-safe keys without changing their addresses.
Is Sui quantum-safe?
Not yet, but Sui has one of the better-designed transitions in this index. Sui accounts sign with Ed25519 today, which a sufficiently large quantum computer would break. In August 2026 Sui committed to adding two post-quantum schemes that are already finalised NIST standards: ML-DSA-65 under FIPS 204 as a native protocol signature scheme for everyday accounts, and SLH-DSA-SHA2-128s under FIPS 205 for smart contract vaults. The detail that matters most for holders is that the new keys are derived from the recovery phrase people already hold, so accounts can move to quantum-safe keys without changing their addresses. Quantum-safe vaults are targeted for mainnet during 2026, native ML-DSA-65 accounts for testnet by the end of 2026, and native account authentication on mainnet in the first quarter of 2027.
At a glance
On mainnet today
Ed25519 for accounts, with multi-scheme support
Post-quantum scheme
ML-DSA-65 for native accounts; SLH-DSA-SHA2-128s for smart contract vaults
NIST standard
FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), both finalised August 2024
Readiness tier
Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.
Score breakdown
Each dimension scored 0 to 10. The weight beside it is its share of the
total score.
Sui accounts are signed with Ed25519 today and nothing post-quantum protects live funds on mainnet. The post-quantum schemes are committed and dated but not yet deployed.
source
2 Deployment stage 5/10, weighted 25%
Tier 3: Committed. Two named standards, a phased schedule with public dates running to the first quarter of 2027, and active engineering, with nothing post-quantum live on mainnet yet.
source
3 NIST alignment 9/10, weighted 15%
Both selected schemes are final NIST standards rather than candidates: ML-DSA-65 under FIPS 204 for accounts and SLH-DSA-SHA2-128s under FIPS 205 for contract vaults. Committing to two finalised standards is stronger than naming a scheme still awaiting publication.
source
4 Migration path 9/10, weighted 15%
The strongest migration design among the committed chains. Post-quantum keys are derived from the recovery phrase holders already have, so accounts can move to quantum-safe authentication without changing addresses. That removes the coordination problem that makes migration hard elsewhere.
source
5 Exposure 2/10, weighted 10%
Sui uses an account model in which the public key is published when an account first transacts, so effectively all economically active supply has an exposed key today and is harvestable against a future quantum computer.
source
6 Verification 8/10, weighted 5%
The commitment was published by Sui under its own name with named schemes and dated milestones, and the protocol is open source, so each milestone is checkable against the calendar as it passes.
source
The deployment dimension is not a separate judgement. It is Tier 3
expressed as a number. See the tier mapping.
How it compares
All 23 rated chains on the 0 to 100 scale.
Sui is marked. Select any point to open that profile.
Sui commits to adding ML-DSA-65 and SLH-DSA-SHA2-128s, with post-quantum keys derived from existing recovery phrases so addresses do not change.
source
During 2026planned
Quantum-safe smart contract vaults using SLH-DSA targeted for mainnet.
source
Native post-quantum account authentication on mainnet.
source
Exposure
Exposure measures how much of the chain's value already sits behind a public key that an
attacker can record today and break later. This is the part of the threat that a future
upgrade cannot undo.
Sui is an account-model chain, so a public key becomes visible on-chain once an account transacts. In practice that means effectively all economically active SUI sits behind an exposed Ed25519 key today and can be recorded now for a future quantum attack. Sui's structural advantage is not in exposure but in recovery: because keys are derived deterministically from a seed phrase, a holder can adopt a post-quantum key without abandoning their address, which is the step most chains have not solved.
What this rating means for you
If you hold Sui
Sui has a funded roadmap but no post-quantum signature protecting funds on mainnet yet. Until it ships, your exposure is the ordinary one, and the steps that reduce it cost nothing.
Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it
is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating.
How we make money.
Questions
Is Sui quantum-safe?
Not yet. Sui accounts use Ed25519, which a sufficiently large quantum computer would break. Sui committed in August 2026 to adding two finalised NIST post-quantum schemes, with native quantum-safe accounts targeted for mainnet in the first quarter of 2027.
Will Sui holders have to change their address?
No, according to Sui's published plan. The post-quantum keys are derived from the same recovery phrase holders already have, which lets an account move to quantum-safe authentication while keeping its existing address. That is unusual and is the main reason Sui scores 9 on migration in this index.
Which post-quantum schemes is Sui adopting?
Two, for two different jobs. ML-DSA-65, standardised as FIPS 204, becomes a native protocol signature scheme for everyday accounts. SLH-DSA-SHA2-128s, standardised as FIPS 205, is used for smart contract vaults. Both are final NIST standards rather than candidates awaiting publication.
Why does Sui still score below 50 if its plan is strong?
Because the signature dimension carries 30 per cent of the score and measures what protects funds on mainnet today, which for Sui is still Ed25519. A plan, however well designed, cannot earn those points until it ships. Sui's score reflects a strong roadmap attached to an entirely classical present.
This is a security-readiness assessment, not investment advice.
Cookies. We use Google Analytics to count how many people read a page. That is
the only thing this site measures: no advertising, no profiling, no third-party marketing tags.
Until you choose, nothing is stored on your device.
What we would set, in full.