Hardy Index Quantum readiness benchmark

Chain profile

Sui

SUI Committed

Committed in August 2026 to two finalised NIST schemes, with a migration path that lets existing accounts move to quantum-safe keys without changing their addresses.

Is Sui quantum-safe?

Not yet, but Sui has one of the better-designed transitions in this index. Sui accounts sign with Ed25519 today, which a sufficiently large quantum computer would break. In August 2026 Sui committed to adding two post-quantum schemes that are already finalised NIST standards: ML-DSA-65 under FIPS 204 as a native protocol signature scheme for everyday accounts, and SLH-DSA-SHA2-128s under FIPS 205 for smart contract vaults. The detail that matters most for holders is that the new keys are derived from the recovery phrase people already hold, so accounts can move to quantum-safe keys without changing their addresses. Quantum-safe vaults are targeted for mainnet during 2026, native ML-DSA-65 accounts for testnet by the end of 2026, and native account authentication on mainnet in the first quarter of 2027.

At a glance

On mainnet today

Ed25519 for accounts, with multi-scheme support

Post-quantum scheme

ML-DSA-65 for native accounts; SLH-DSA-SHA2-128s for smart contract vaults

NIST standard

FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), both finalised August 2024

Readiness tier

Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Sui Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 5 25% 12.5
3 NIST alignment 9 15% 13.5
4 Migration path 9 15% 13.5
5 Exposure 2 10% 2.0
6 Verification 8 5% 4.0
Hardy Score 45.5

1 Signature scheme 0/10, weighted 30%

Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Sui accounts are signed with Ed25519 today and nothing post-quantum protects live funds on mainnet. The post-quantum schemes are committed and dated but not yet deployed. source

2 Deployment stage 5/10, weighted 25%

Band 5: Tier 3: Committed.

Tier 3: Committed. Two named standards, a phased schedule with public dates running to the first quarter of 2027, and active engineering, with nothing post-quantum live on mainnet yet. source

3 NIST alignment 9/10, weighted 15%

Band 9 to 10: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).

Both selected schemes are final NIST standards rather than candidates: ML-DSA-65 under FIPS 204 for accounts and SLH-DSA-SHA2-128s under FIPS 205 for contract vaults. Committing to two finalised standards is stronger than naming a scheme still awaiting publication. source

Placement in the band Not a 10: both schemes are final standards, which is what puts Sui at the top of this dimension, but neither is deployed, so what is committed to is a standard rather than a standard in use.

4 Migration path 9/10, weighted 15%

Band 9 to 10: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.

The strongest migration design among the committed chains. Post-quantum keys are derived from the recovery phrase holders already have, so accounts can move to quantum-safe authentication without changing addresses. That removes the coordination problem that makes migration hard elsewhere. source

Placement in the band Not a 10: deriving post-quantum keys from the recovery phrase holders already have removes the coordination problem, but holders cannot migrate today, so the plan is executable rather than executed.

5 Exposure 2/10, weighted 10%

Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

Sui uses an account model in which the public key is published when an account first transacts, so effectively all economically active supply has an exposed key today and is harvestable against a future quantum computer. source

Placement in the band At the top of the band rather than a 0 or a 1: the key is published on first transaction rather than at account creation, so never-used accounts retain protection, though almost no active supply does.

6 Verification 8/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

The commitment was published by Sui under its own name with named schemes and dated milestones, and the protocol is open source, so each milestone is checkable against the calendar as it passes. source

Placement in the band The top of the band: named schemes and dated milestones published under Sui's own name, against open source, make each milestone checkable as it passes. It stops short of 9 because there is no deployed component to audit.

The deployment dimension is not a separate judgement. It is Tier 3 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Sui is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Sui sits among, out of 31 rated. The last column is the gap in Hardy points from Sui.

Chains ranked immediately around Sui, with tier, Hardy Score and the gap to Sui
Rank Chain Tier Hardy vs SUI
6 Nervos CKB 2: Shipping 75.5 +30.0
7 Bitcoin Cash 2: Shipping 66.0 +20.5
8 Solana 2: Shipping 54.5 +9.0
9 XRP Ledger 3: Committed 46.5 +1.0
10 Sui this chain 3: Committed 45.5
11 Hedera 3: Committed 42.0 -3.5
12 Stellar 3: Committed 41.0 -4.5
13 Zcash 3: Committed 41.0 -4.5
14 Aptos 3: Committed 40.5 -5.0

Roadmap

  1. 6 August 2026 shipped

    Sui commits to adding ML-DSA-65 and SLH-DSA-SHA2-128s, with post-quantum keys derived from existing recovery phrases so addresses do not change. source

  2. During 2026 planned

    Quantum-safe smart contract vaults using SLH-DSA targeted for mainnet. source

  3. End of 2026 planned

    Native ML-DSA-65 accounts on testnet. source

  4. Q1 2027 planned

    Native post-quantum account authentication on mainnet. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Sui is an account-model chain, so a public key becomes visible on-chain once an account transacts. In practice that means effectively all economically active SUI sits behind an exposed Ed25519 key today and can be recorded now for a future quantum attack. Sui's structural advantage is not in exposure but in recovery: because keys are derived deterministically from a seed phrase, a holder can adopt a post-quantum key without abandoning their address, which is the step most chains have not solved.

What this rating means for you

If you hold Sui

Sui has a funded roadmap but no post-quantum signature protecting funds on mainnet yet. Until it ships, your exposure is the ordinary one, and the steps that reduce it cost nothing.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

Embed this rating

Paste this anywhere to show Sui's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/sui"><img src="https://hardyindex.com/badge/sui.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/sui.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Sui quantum-safe?

Not yet. Sui accounts use Ed25519, which a sufficiently large quantum computer would break. Sui committed in August 2026 to adding two finalised NIST post-quantum schemes, with native quantum-safe accounts targeted for mainnet in the first quarter of 2027.

Will Sui holders have to change their address?

No, according to Sui's published plan. The post-quantum keys are derived from the same recovery phrase holders already have, which lets an account move to quantum-safe authentication while keeping its existing address. That is unusual and is the main reason Sui scores 9 on migration in this index.

Which post-quantum schemes is Sui adopting?

Two, for two different jobs. ML-DSA-65, standardised as FIPS 204, becomes a native protocol signature scheme for everyday accounts. SLH-DSA-SHA2-128s, standardised as FIPS 205, is used for smart contract vaults. Both are final NIST standards rather than candidates awaiting publication.

Why does Sui still score below 50 if its plan is strong?

Because the signature dimension carries 30 per cent of the score and measures what protects funds on mainnet today, which for Sui is still Ed25519. A plan, however well designed, cannot earn those points until it ships. Sui's score reflects a strong roadmap attached to an entirely classical present.

Sources

  1. Making Sui Quantum Ready Sui Foundation · primary · checked 12 August 2026
  2. Sui reference implementation Mysten Labs (GitHub) · primary · checked 12 August 2026
  3. FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) NIST · primary · checked 12 August 2026
  4. FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) NIST · primary · checked 12 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Sui: quantum readiness assessment. Hardy Score 45.5 of 100, Tier 3: Committed. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/sui

BibTeX
@misc{hardyindex_sui_2026,
  author       = {{The Hardy Index}},
  title        = {Sui: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/sui}},
  note         = {Hardy Score 45.5 of 100, Tier 3: Committed. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/sui.md.

This is a security-readiness assessment, not investment advice.