Hardy Index Quantum readiness benchmark

Chain profile

Tron

TRX Debating

Mainnet signs with ECDSA on secp256k1, but Falcon-512 is activated on the public Nile testnet under a formal improvement proposal that names its parameter sets and wire formats.

Is Tron quantum-safe?

No. Tron accounts on mainnet are secured by ECDSA on the secp256k1 curve, the same scheme Bitcoin and Ethereum use, and a sufficiently large quantum computer would break it. Tron has moved well past an announcement, though. TIP-899, Post-Quantum Signature Support, is a full wire-format specification in Tron's own improvement-proposal repository, covering transactions, block production, node handshakes and the TVM, and it names two parameter sets: FN-DSA-512 (Falcon-512) and ML-DSA-44. Falcon-512 is activated on the public Nile testnet, which any reader can check directly: the chain parameter getAllowFnDsa512 reads 1 on Nile, and the parameter does not exist on mainnet at all. That is a testnet implementation, not protection for TRX or TRC-20 balances, and no mainnet date has been published, which is why Tron sits in Tier 4 rather than Tier 3.

Where we are making a judgement call This profile moved a long way, and on evidence that did not exist when Tron was first rated. The earlier entry recorded an announced intention and deliberately declined to credit it, saying the score would move if Tron published a specification, a named parameter set or a testnet implementation. All three now exist. Readers should still weigh that none of this protects a single TRX today: Falcon-512 runs on a test network with test coins, and Tron's mainnet carries no post-quantum parameter at all.

At a glance

On mainnet today

ECDSA on secp256k1

Post-quantum scheme

FN-DSA-512 (Falcon-512) activated on the Nile testnet; ML-DSA-44 specified and staged but not activated. Neither is present on mainnet.

NIST standard

FIPS 204 (ML-DSA), finalised August 2024. FN-DSA is specified in the FIPS 206 draft, which is not final.

Readiness tier

Tier 4: Debating. Post-quantum work on the chain’s own signatures is documented by people with authority over it, in a formal improvement proposal or a public research programme, but no scheme is agreed and no timeline is published.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Tron Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 2 30% 6.0
2 Deployment stage 2 25% 5.0
3 NIST alignment 7 15% 10.5
4 Migration path 5 15% 7.5
5 Exposure 2 10% 2.0
6 Verification 7 5% 3.5
Hardy Score 34.5

1 Signature scheme 2/10, weighted 30%

Band 1 to 3: Classical signatures only on mainnet, with a post-quantum implementation live and usable by the public on a persistent test network.

Tron mainnet signs with ECDSA on secp256k1 and nothing post-quantum protects TRX or TRC-20 balances. Falcon-512 is live on the public Nile testnet, where the chain parameter getAllowFnDsa512 reads 1, while that parameter is absent from mainnet entirely. source

Placement in the band Not a 3: only one of the two schemes TIP-899 specifies is actually usable. ML-DSA-44 is staged on Nile at 0 and has never been activated, so the testnet implementation is half-delivered against its own specification.

2 Deployment stage 2/10, weighted 25%

Band 2: Tier 4: Debating.

Tier 4: Debating. TIP-899 is a formal proposal in Tron's own improvement process, authored from tron.network, and Falcon-512 is running on a persistent public testnet, which clears the Debating floor comfortably. It is not Tier 3 because the proposal is Draft, no scheme is agreed for mainnet and no timeline is published. source

3 NIST alignment 7/10, weighted 15%

Band 6 to 8: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.

TIP-899 names two specific parameter sets rather than a direction: ML-DSA-44 from the finalised FIPS 204, and FN-DSA-512 from the FIPS 206 draft. Specifying standardised parameter sets down to their canonical wire encodings is a committed selection, not a candidate reference. source

Placement in the band Not a 9: the scheme Tron actually switched on, Falcon-512, rests on FIPS 206, which NIST has not finalised. A 9 would need the deployed choice to sit under a final standard.

4 Migration path 5/10, weighted 15%

Band 3 to 5: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.

TIP-899 lets a single account carry a mix of ECDSA and post-quantum signers under Tron's existing permission weights, which is a genuine route off a vulnerable key for a holder who acts. source

Placement in the band Not a 6: a mechanism is not a plan. The 6 to 8 band asks for a published migration plan, and TIP-899 proposes no sunset for ECDSA, attaches no dates, and says nothing about accounts whose keys are already public.

5 Exposure 2/10, weighted 10%

Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

Tron addresses are derived from a hash of the public key, so a funded account that has never sent a transaction keeps its key private. Given Tron's transaction volumes, effectively all economically meaningful accounts have transacted and published their keys. source

Placement in the band Not a 3: the hashed-address protection is real, but it only covers accounts that have never signed, and on a network built for high-frequency stablecoin transfers those hold a negligible share of value.

6 Verification 7/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

The specification is public and has been under open discussion in the TIP repository since June 2026, java-tron is open source, and the Nile activation is checkable on-chain by anyone who queries the chain parameters. source

Placement in the band Not an 8: no third-party audit of Tron's post-quantum implementation was found. Open code and an open specification are public review, which the band credits, but they are not the named audit the top of it asks for.

The deployment dimension is not a separate judgement. It is Tier 4 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Tron is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Tron sits among, out of 31 rated. The last column is the gap in Hardy points from Tron.

Chains ranked immediately around Tron, with tier, Hardy Score and the gap to Tron
Rank Chain Tier Hardy vs TRX
14 Aptos 3: Committed 40.5 +6.0
15 Polkadot 3: Committed 40.5 +6.0
16 Ethereum 3: Committed 40.0 +5.5
17 Cardano 3: Committed 37.5 +3.0
18 Tron this chain 4: Debating 34.5
19 BNB Chain 4: Debating 22.5 -12.0
20 Monero 4: Debating 21.0 -13.5
21 IOTA 5: Exposed 18.5 -16.0
22 Bitcoin 4: Debating 17.0 -17.5

Roadmap

  1. 30 June 2026 shipped

    TIP-899, Post-Quantum Signature Support, is opened in the Tron Improvement Proposals repository with status Draft. It specifies Falcon-512 and ML-DSA-44 across transactions, block production, node relay handshakes and the TVM, with five new precompiles and canonical wire encodings. source

  2. July 2026 shipped

    Falcon-512 is activated on the public Nile testnet by on-chain governance proposal. The chain parameter getAllowFnDsa512 reads 1 on Nile, and ML-DSA-44 is staged alongside it at 0. source

  3. No date published proposed

    ML-DSA-44 activation on Nile, and any mainnet deployment. Neither parameter exists on Tron mainnet and no date has been published for either. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Tron derives addresses from a hash of the public key, in the same manner as Ethereum, so an account that has been funded but has never signed a transaction has not published its key. That protection is theoretical for most of the network. Tron carries very high transaction volumes, particularly in stablecoin transfers, so the accounts holding meaningful value have almost all signed repeatedly and published their keys. Those keys can be recorded today against a future quantum computer. TIP-899 does not change this: post-quantum addresses on Tron use the same derivation and the same 21-byte address space, so the exposure question is about which keys are already public, not about the address format.

What this rating means for you

If you hold Tron

Tron has acknowledged the threat without agreeing a plan, so nothing is going to change for holders in the near term. That makes address hygiene the part worth attending to.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Tron's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/tron"><img src="https://hardyindex.com/badge/tron.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/tron.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Tron quantum-safe?

No. Tron mainnet signs with ECDSA on the secp256k1 curve, which a sufficiently large quantum computer would break. Post-quantum signatures exist on Tron's Nile test network, but nothing post-quantum protects TRX or TRC-20 balances on mainnet.

What is TIP-899?

TIP-899, Post-Quantum Signature Support, is a Draft proposal in Tron's own improvement-proposal repository, opened on 30 June 2026. It specifies how Falcon-512 and ML-DSA-44 signatures work across transactions, block production, node handshakes and the TVM, down to canonical wire encodings and address derivation. It is a specification rather than a schedule: it carries no mainnet date.

How can I check whether Tron's post-quantum signatures are live?

Query the chain parameters on each network. On the Nile testnet, getAllowFnDsa512 reads 1, meaning Falcon-512 transactions are accepted, and getAllowMlDsa44 reads 0. On Tron mainnet neither parameter exists at all. That is the clearest available evidence of where the work has and has not reached.

Why is Tron still in Tier 4 if it has a specification and a testnet?

Because Tier 3 requires a funded roadmap with public dates, and TIP-899 carries none. The tier measures published commitment to a schedule, not engineering progress. Tron's signature and NIST alignment scores rose sharply on the testnet evidence, which is the score doing its job while the tier holds.

Does Tron's stablecoin volume change its quantum exposure?

It worsens it in practice. Address derivation on Tron hashes the public key, so an account that has never signed keeps its key private. High transfer volumes mean the accounts holding value have signed many times and published their keys, so the theoretical protection of a hashed address does not apply to most of the network's value.

Sources

  1. TIP-899: Post-Quantum Signature Support Tron Protocol (GitHub) · primary · checked 15 August 2026
  2. Nile testnet chain parameters Nile testnet node API · primary · checked 15 August 2026
  3. Tron mainnet chain parameters TronGrid node API · primary · checked 15 August 2026
  4. Trying TRON Post-Quantum (PQ) Signatures on the Testnet TRON Core Devs · primary · checked 15 August 2026
  5. java-tron, the Tron protocol implementation Tron Protocol (GitHub) · primary · checked 15 August 2026
  6. FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) NIST · primary · checked 15 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Tron: quantum readiness assessment. Hardy Score 34.5 of 100, Tier 4: Debating. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/tron

BibTeX
@misc{hardyindex_tron_2026,
  author       = {{The Hardy Index}},
  title        = {Tron: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/tron}},
  note         = {Hardy Score 34.5 of 100, Tier 4: Debating. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/tron.md.

This is a security-readiness assessment, not investment advice.