Hardy Index Quantum readiness benchmark

Changelog

Changelog

Every score change, methodology revision and correction, newest first. A benchmark that cannot show what it changed and why is an opinion with a number attached.

  1. Correction

    Correction: a post published this morning announced coverage to 25 chains while the index held 31, and no guard read news posts at all

    The post announcing Monero and Mochimo said, in its headline and its answer block, that they took coverage to 25 chains. That was true on 13 August. The post published on the 19th, by which time the index held 31. It had been drafted from a six-day-old changelog entry, in the present tense, and it merged.

    Two things had to be missing at once for that to reach a reader, and both were.

    The claims guard added yesterday reads src/content/chains and nothing else. No sentence in any published post had ever been checked against the dataset. That is now fixed: the scanner reads the news collection too, and a claim in a post is registered exactly as a claim in a profile is.

    The second gap was subtler and is the more useful lesson. "Taking coverage to 25 chains" is index-scoped and quantitative, but it is not comparative. It ranks nothing and names no other chain, so both halves of the pattern that catches "the only chain in this index" slide straight off it. A whole class of claim, the size of the index, was invisible to a guard built to protect claims about the index. Counts are now matched separately and held to a stricter rule than comparisons: write the live figure as the {{chains}} token, which reads the dataset at build time and cannot go stale, or register the number as historical with the date it was true and say that date in the sentence. A number registered as historical whose sentence does not carry its year fails the build, because the date is the only thing that stops a reader taking it as current.

    Turning the guard on the news collection immediately found something worse than a stale number. The QRL post, live since 12 August, opened by saying every other chain in this index is having a conversation about migration. Mochimo and Abelian launched post-quantum too and never needed one. It is the same error corrected on the profiles yesterday, of the same shape, on the same chain, surviving in a post because posts were not being read. The sentence now names all three chains that launched post-quantum, and it is checked against the tier data rather than trusted, so the claim re-verifies itself whenever a chain enters or leaves Tier 1. Three other comparative sentences in older posts were found at the same time and are now registered with predicates: Algorand's placement, IOTA's statement about elliptic-curve reliance, and Monero's about the gap it filled.

    The Monero and Mochimo post itself has been rewritten as what it always was, a record of a change made on 13 August rather than news of one made today. The event is in the past tense, the post opens by saying when it was published and what it records, the historical count carries its date, and the current figure comes from the live token beside it. Its ratings were never wrong: those are read from the index on every build. Only the narrative around them had aged.

    All four rules were tested by breaking them. The sentence exactly as it published, a historical count with its date removed, a new unregistered comparison in a post, and a falsified predicate each produce a red build.

    Monero Mochimo Quantum Resistant Ledger source ↗

  2. Correction

    Correction: the Zcash roadmap was sourced to a page that stopped being readable, and the recovery path it described has been live since July

    A CoinDesk article from 8 May 2026 was carrying four load-bearing citations on the Zcash profile: the deployment and migration dimensions, and two of the three roadmap entries. Some time on 18 August that URL began returning a 429 to automated clients, which failed the source check on every build. The fix is not an allowlist entry. It is the one the source file already recommends: repoint at sources that can be read.

    Going to the primaries corrected the record in a direction the profile did not anticipate. ZIP 2005, whose title is Ironwood Quantum Recoverability rather than Orchard quantum recoverability, is not pending. ZIP 258 specifies that it activates with the NU6.3 network upgrade at block 3,428,143, and the chain passed that block on 28 July 2026. The deployment note said a ZIP "is deploying" a recovery path and the verification band said the construction was "not yet deployed". Both were three weeks out of date. The profile understated Zcash rather than overstating it, which is the less common direction and no more acceptable.

    Two claims are withdrawn rather than repointed, because no primary source carries them. The May 2026 roadmap entry said Zcash had set out a plan for quantum-recoverable wallets within a month and full post-quantum protection on a twelve to eighteen month horizon. The 2027 entry said a full post-quantum protocol migration was targeted for that year. Both came from the CoinDesk headline. Neither the ZIPs, the Zcash Foundation's NU7 polling results nor anything else we could read states a date for the full migration, so the profile now says we could not confirm one.

    The roadmap that replaces them carries two dated, sourced facts: the February 2026 NU7 polling result, where quantum recoverability drew 90.5 per cent support among ZCAP participants and 94.6 per cent among coinholders, and the July 2026 activation of ZIP 2005 at NU6.3.

    One substantive fact was missing altogether and has been added. The recovery path covers only funds moved into the Ironwood pool. ZIP 2005 states that anything left in the Sprout, Sapling or Orchard pools would be inaccessible once those protocols were disabled. A holder reading the old profile would have taken the protection as automatic.

    No score changed. Zcash remains Tier 3 with deployment at 5, migration at 8 and verification at 8. That placement now deserves a re-read in both directions, and the reasons are recorded here rather than settled quietly. Tier 3 is defined as a funded roadmap with public dates, and the only public date Zcash had has just been withdrawn as unverifiable, which points down. Against that, the chain has shipped a working mitigation on mainnet, which most of the tier has not, and which points up. The spine measures dated promises and post-quantum signatures, and Zcash has delivered something that is neither.

    Zcash source ↗

  3. Correction

    Correction: four claims comparing a chain to the rest of the index were false, and nothing was checking them

    A full audit of the platform found four live statements that compare one chain to the whole index and had stopped being true. Two of them had profiles contradicting each other in public.

    QRL's summary said it was "the only chain in the index where a post-quantum signature is mandatory for every account on mainnet", and its first question answered that it was "the only chain in this index with no quantum-vulnerable signature scheme available on mainnet at all". Mochimo is the same case and has been since the same month: both launched in June 2018, both score 10 on the signature dimension, and Mochimo's own row states that its node source contains no elliptic-curve signature implementation. The claims were wrong on the index's two highest-ranked rows at once. QRL's summary now describes QRL without the comparison, and the question names both chains.

    Mochimo made the mirror-image error. Its migration note said having no classical legacy "removes the hardest problem every other chain in this index faces", which is not true of QRL or Abelian, the other two chains that launched post-quantum. It now refers to every chain that did not launch post-quantum.

    Nervos CKB said that using a finalised NIST standard live on mainnet was something "no other chain in this index does". That was true when written and stopped being true when NEAR was added on 16 August with ML-DSA-65 under FIPS 204. The sentence now names NEAR.

    Solana's placement was described as "the most generous placement in the index" and "the most contestable call in this index". Bitcoin Cash was placed in Tier 2 on the same contract-level reasoning two days earlier, so both are now hedged. Nervos CKB's "the cleanest migration in the index" is hedged for the same reason, against Sui, XRP Ledger and NEAR, which all score the same 9.

    No score changed in any of this. Every correction is to prose that compared chains, not to a rating.

    The reason all four survived is that nothing checked them. From today every sentence in the dataset that is both scoped to the index and comparative has to be registered, and the build fails on any that is not. Thirty are registered. Eleven carry a predicate evaluated against the live data on every build, so they re-verify themselves: QRL and Mochimo being the only two chains scoring 10 on signature is now arithmetic rather than memory. Seventeen are judgements no predicate can express, and each is pinned to the number of chains in the index when a person last read it, so changing the size of the index fails them and forces the re-read that did not happen last week. Two trip the pattern while asserting no ranking, and say so.

    The register is at src/lib/claims.ts and the guard at scripts/check-claims.mjs. Both were tested by breaking them: an unregistered claim, an edited sentence, a falsified predicate and a change in the number of chains each produce a red build.

    Quantum Resistant Ledger Mochimo Nervos CKB Solana source ↗

  4. Correction

    Correction: the MemeCore consensus detail was sourced to a page we could not read

    MemeCore was published hours earlier today citing a press release for its consensus design. That URL refuses automated clients with a 403, which the source checker reports as a bot policy rather than link rot, and the distinction hid a real problem: we had never actually read the page. The claims taken from it came from a search-engine summary.

    Most of what that summary said held up against a syndication of the same release that can be read: the 9 September 2025 launch date, the EVM-compatible layer 1 description, the Proof of Meme combination of Proof of Authority and delegated Proof of Stake, the ten-block validator rotation and the seven million token self-stake. Two details did not appear in the readable version at all. The profile said the top seven validators are elected in real time and that the set refreshes roughly every seventy seconds. Both are now withdrawn, and the citation points at the version we can read.

    No score changed. The migration dimension still scores 1 and the reasoning still turns on a small and identifiable set of parties being able to agree a scheme change, which the ten-block rotation and the self-stake floor support on their own. But the argument was previously resting partly on a number we could not verify, and a rating that names a figure should be able to show where the figure came from.

    The general lesson is being recorded rather than quietly fixed. A 403 in the source checker is reported as a bot policy, which is accurate and which made it easy to treat an unreadable page as an acceptable citation. It is acceptable for a source whose content was verified when it was written down. It is not acceptable for one that never was.

    MemeCore source ↗

  5. Coverage

    The coverage rule run properly: four chains added, one held back, and several candidates correctly absent

    The inclusion rule published on 13 August was applied against live market capitalisations rather than against a list of chains that came to mind. That is a different exercise and it produced a different answer.

    Filtering out stablecoins, tokens, oracles and layer 2s per the scope boundary, five of the twenty-five largest layer 1s were unrated. Four are now in: Internet Computer at 14.5, Bittensor at 11.0, Cronos at 8.5 and MemeCore at 8.5. All four are Exposed. None has published a post-quantum roadmap, improvement proposal or research programme addressing its own signatures, and in each case the absence is the finding rather than a gap in our reading.

    Internet Computer is the one worth reading. Its distinguishing feature is the cryptography at risk: chain-key signatures rest on BLS for consensus and certification and on threshold ECDSA and Schnorr for canister keys, and the subnet public key that lets any client verify a certified response is published by design and cannot be withheld. DFINITY's chief scientist has said in public that the network was built with crypto agility and that replacement algorithms would go to the NNS at the appropriate time. That is a real statement from a real cryptographer and it is not a proposal, a programme or a date, which is what the Debating rung asks for. The same reading placed Cosmos Hub and Kaspa outside the index entirely.

    Canton Network is held back rather than rated, and it is the only chain inside the twenty-five largest we do not cover. Secondary sources report Ed25519 by default with ECDSA over P-256 and P-384 supported, which would be an unremarkable quantum-vulnerable position, but every version of the security documentation stating those schemes served a navigation shell rather than the text. Publishing a signature assessment from a search-engine summary of a page we could not read would break the rule that every data point carries a primary source, and the rule is worth more than the row.

    Several chains considered for this pass are absent because the rule says they should be, not because they were overlooked: Cosmos Hub, Kaspa, Ethereum Classic, Mina, Filecoin, Sei, Injective and Celestia all sit outside the top twenty-five layer 1s by size and none has a published post-quantum position we could find. The about page already says that a chain meeting none of the three tests is absent because nothing about its quantum position is yet in question, and that is the case here. Anyone who thinks otherwise should send the source.

    Internet Computer Bittensor Cronos MemeCore source ↗

  6. Methodology

    Methodology v1.4: two things published beside the score, neither of them in it

    Two artefacts join the profile in v1.4. Neither changes a single score, and that is the design rather than a limitation of the first pass.

    The first is the say-do record. A chain can announce post-quantum work indefinitely without shipping any, and announcing is cheaper than shipping. Where we can compile one, a profile now carries the chain's dated public commitments over a stated window, each with a source and a status, and a counted line: how many shipped, how many shipped in part, how many did not. The obvious move was to turn that into a shipped-to-announced ratio and deduct from the score, which is what at least one competing index does. We declined for three reasons. The score's claim is that a reader can reproduce it from six published dimension scores and six published weights, and an input derived from a corpus only we hold cannot be reproduced by anyone without our corpus. A weight on how much a chain has said is a weight on press-release volume, which would mark down a chain that publishes an honest roadmap and slips it against a chain that published nothing. And the ratio divides by zero on exactly the chains the measure is aimed at.

    So it is counted, not scored, and the entries are printed rather than compressed into a coefficient. A count can be checked against the list underneath it. Three commitments is the floor: below that the record is an anecdote that this layout would lend the authority of a register.

    The second is exposure as a quantity. The exposure dimension is a 0 to 10 score and, as the published limits already said, it is scored on address structure as much as on measurement, which left a reader without the figure they actually want. Where a credible measurement exists the profile now prints it, with the amount, the share where the source states one, who measured it and when. Where sources disagree we print all of them. Bitcoin is the case the rule was written for: published estimates run from about 4 million BTC to about 7 million, and that spread is where each analyst draws the line between exposed and unexposed. A measurement is evidence behind the exposure score rather than an input alongside it, so the dimension is still scored against the published anchors.

    Both fields are optional in the dataset and both render nothing when absent, because inventing a measurement from a block explorer or padding a ledger to reach the floor would be a worse failure than an absent section.

    source ↗

  7. Coverage

    NEAR Protocol enters at Tier 2 and 81.5, the highest score in the index for a chain not built post-quantum from genesis

    NEAR joins the index in fourth place, behind only the three chains that were post-quantum from their first block.

    The nearcore 2.13.0 release notes state that it "stabilized the FIPS 204 ML-DSA-65 post-quantum signature scheme as a third transaction-signature and access-key scheme alongside ed25519 and secp256k1". Protocol version 86 carrying it was voted in on mainnet from 20 July 2026. That is a NIST-standardised post-quantum signature working as a first-class account credential on a live mainnet, which no other retrofitting chain in this index has.

    NEAR's account model is what makes this possible. Accounts are human-readable identifiers controlled by rotatable access keys rather than addresses derived from a keypair, so rotating to ML-DSA-65 is a single on-chain transaction that changes neither the account name nor the balance. The migration dimension scores 9 on that basis, which is the highest in the index outside the native chains.

    One detail deserves more attention than it has had. NEAR stores an ML-DSA-65 key as a 32-byte SHA3-256 hash rather than as the 1952-byte key, so a rotated account publishes a hash and not a public key. On a chain where every account's access keys are readable on-chain from creation, that turns rotation into a fix for exposure as well as for signature strength.

    What keeps NEAR out of Tier 1 is that all of this is optional. Ed25519 and secp256k1 remain valid, no sunset for them has been proposed or dated, and no target has been published for how much of the account set should hold a post-quantum key by when. Effectively every account on the network still has a quantum-vulnerable public key in plain sight until its owner acts, which is why the exposure dimension scores 2 despite the rotation path being open.

    NEAR Protocol source ↗

  8. Coverage

    Bitcoin Cash enters at Tier 2 and 66.0, forty-nine points above Bitcoin

    Bitcoin Cash joins the index above Bitcoin, and the gap is large enough that it needs explaining rather than just reporting.

    Neither chain has changed its own signature scheme. Both still sign with ECDSA and Schnorr on secp256k1. The difference is entirely in the scripting layer. The Layla upgrade activated on Bitcoin Cash mainnet at 12:00 UTC on 15 May 2026, bundling the Loops, Functions, Pay to Script and Bitwise improvement proposals. Those features made Quantumroot practical: a vault design that verifies Leighton-Micali One-Time Signatures inside Bitcoin Script, resting only on SHA-256. LM-OTS is specified in RFC 8554 and is the one-time signature underlying the LMS scheme NIST approves in SP 800-208. Wallets including OPTN Labs and Paytaca shipped support.

    So a Bitcoin Cash holder can put coins behind a post-quantum signature on mainnet today. A Bitcoin holder cannot. This index ranks preparation, and on that measure the two chains are no longer in the same position.

    Bitcoin Cash is placed in Tier 2 on the same reasoning already applied to the other contract-level case in this index, where an application-level quantum-resistant vault protecting real funds on mainnet counts as shipping. That is the most generous reading available and the profile says so: a reader who thinks only protocol features should count would put this chain in Tier 3 and take about fifteen points off.

    The exposure dimension is the weak point and we would rather flag it than bury it. Bitcoin Cash inherits Bitcoin's chain history to August 2017, which means it inherits every pre-fork pay-to-public-key output with its key already published. Nobody has measured exposed supply on Bitcoin Cash, so the dimension is scored on the address model at the floor of its band, which is the limitation this rubric already publishes. Bitcoin scores 1 there on the strength of measurements running from 4 million to 7 million coins. If somebody produces the equivalent count for Bitcoin Cash at similar levels, that dimension falls sharply and this gap narrows. It is the number we would most like to see published.

    Bitcoin Cash source ↗

  9. Methodology

    Methodology v1.3: placement inside a band has to be stated

    This page claimed the Hardy Score is arithmetic rather than opinion. That was true of the total given six dimension scores, and it was never true one level down. An anchor reading "7 to 9" leaves a three-point choice, worth nine points of the total on the signature dimension, and until now nothing in the data had to say why it landed where it did. The strongest objection any chain could raise was that we had given it the bottom of our own band without justifying it.

    From v1.3 every score sitting inside an anchor that covers more than one value carries a stated reason naming the value we did not choose and the fact that decided between them, printed on the profile under "placement in the band" and in the Markdown mirror. That covers 105 of the 150 dimension cells in the index; the other 45 are the 25 deployment scores, whose anchors are generated from the tier list and cover one value each, and 20 signature scores sitting at a flat 0 or 10.

    The rule is enforced twice, by the collection schema and by a standalone check that runs before the site is built, and both call the same function, so neither can drift from the other.

    The check is deliberately mechanical: it verifies that a comparison was made, not that it was a good one. It requires the text to name another score in the band, as a digit or a word, or to use one of a short list of placement phrases, and that list is now published on the methodology page rather than kept as an in-house style note. A lint rule that shapes what a reader sees should not be invisible to them.

    No score changed in this work. Where writing a justification would have changed our mind about a value, that is a separate entry with its own reasoning.

    source ↗

  10. Methodology

    Methodology v1.2: the Debating floor gets a substance test

    Tier 4 read "the threat is acknowledged and proposals exist", which set no bar for who was proposing or where. A single forum post cleared it, which made the fourth rung the one genuinely gameable seam in the spine.

    Debating now asks for post-quantum work on the chain's own signatures, documented by people with authority over it, in a formal improvement proposal or a public research programme. Tier 5 is scoped to match, so its "no plan, proposal or research programme" test is explicitly about the signatures securing mainnet funds rather than about post-quantum work anywhere in a project.

    One chain moves: IOTA, whose post-quantum engineering lives in its identity layer rather than at layer 1. Separately, the signature dimension's 1 to 3 anchor promised credit for "a post-quantum implementation running on a public testnet or devnet", while the dataset consistently scored short-lived devnets and one-off benchmarks at 0. The anchor now says what the scoring actually does: the band needs an implementation live and usable by the public on a persistent test network, and devnet experiments sit at 0. No score changed as a result of that correction, because the data already followed the stricter reading.

    The published formula, the tier-to-score mapping and the share of weight carried by the signature and deployment dimensions are now generated from the weights themselves rather than typed out, so a future change to a weight cannot leave the methodology page describing arithmetic the site no longer performs.

    source ↗

  11. Score change

    IOTA moves from Debating to Exposed

    IOTA held Tier 4 on a stated intention to adopt future quantum-resistant standards. The v1.2 Debating floor asks for more than intent: a proposal in the chain's own improvement process, or a public research programme, aimed at the signatures that protect mainnet funds.

    A search of the iotaledger improvement-proposal and node repositories returns no quantum-related issue at all, and IOTA's layer 1 has signed with Ed25519 since Chrysalis replaced Winternitz one-time signatures in 2021. The post-quantum work IOTA has shipped is real but sits in IOTA Identity, where ML-DSA, SLH-DSA and Falcon secure verifiable credentials rather than tokens.

    Only the deployment dimension moves, from 2 to 1, because the tier is the only thing that changed. The profile carries the reasoning as a declared judgement call: this is a close placement, and a reader who counts the Foundation's demonstrated post-quantum capability as evidence of intent toward layer 1 would reasonably leave IOTA in Debating.

    IOTA source ↗

  12. Score change

    Tron: Falcon-512 is live on Nile, and the profile was two months behind it

    Tron's entry recorded an announced intention to adopt NIST post-quantum signatures and deliberately declined to credit it, stating that the score would move if Tron published a specification, a named parameter set or a testnet implementation. All three exist and predate that entry.

    TIP-899, Post-Quantum Signature Support, was opened in Tron's own improvement-proposal repository on 30 June 2026 with status Draft, specifying Falcon-512 and ML-DSA-44 across transactions, block production, node relay handshakes and the TVM, down to canonical wire encodings and address derivation. Falcon-512 was then activated on the public Nile testnet by governance proposal, which any reader can verify against the chain parameters: getAllowFnDsa512 reads 1 on Nile and the parameter is absent from mainnet entirely.

    Four dimensions move. Signature goes from 0 to 2, into the band for a post-quantum implementation live on a persistent public test network, held at 2 rather than 3 because ML-DSA-44 is staged on Nile at 0 and has not been activated. NIST alignment goes from 4 to 7, since named standardised parameter sets specified to the byte are a committed selection rather than a candidate reference. Migration goes from 2 to 5, because TIP-899's permission-weight coexistence is a real route off a vulnerable key, though a mechanism is not a plan and no sunset or date is proposed. Verification goes from 5 to 7 on the open specification, open source client and on-chain checkability.

    The tier does not move: Tier 3 asks for a funded roadmap with public dates, and TIP-899 carries none.

    This correction is the index working as intended on one axis and failing on another. The score rose sharply on evidence while the tier held, which is what separate axes are for. It should not have taken until now to notice.

    Tron source ↗

  13. Coverage

    Monero and Mochimo added, taking the index to 25 chains

    Both rows follow directly from the coverage rule published the same day.

    Monero enters on the scale test as the tenth largest layer 1 and was the most conspicuous gap in the index. It is placed in Tier 4: Debating, because it funded and completed dedicated post-quantum research in 2020 and has named candidate schemes since, but has selected nothing and scheduled nothing. Its exposure score is the lowest given to any chain here, because a one-time output public key is published on-chain for every output and a quantum break would also unmask senders in historical ring signatures retroactively.

    Mochimo enters on the deployment test at Tier 1: Native. Its WOTS+ signing was verified in the node source rather than accepted from project material, and the repository contains no elliptic-curve signature implementation of any kind, which is what makes post-quantum signing mandatory rather than optional. Its NIST alignment is held at 7 because NIST SP 800-208 approves XMSS and LMS rather than the standalone WOTS+ construction Mochimo uses.

    Monero Mochimo source ↗

  14. Coverage

    The coverage inclusion rule is published

    Until now the about page said only that the index covers the largest chains, the most advanced post-quantum deployments and the chains most often named as quantum-safe. That described our practice without being testable, so 'why is this chain not rated?' had no principled answer.

    Coverage is now a published rule: a layer 1 is in scope if it is one of the twenty-five largest by market capitalisation, or it has published a post-quantum position of any kind at any size, or it runs a post-quantum signature scheme on mainnet at any size. A live public mainnet and a primary-source-verifiable scheme are required in all three cases.

    Market value decides who gets assessed and never how they score, which is the distinction the methodology page draws.

    source ↗

  15. Correction

    Bitcoin and Cardano exposure citations repointed to primary sources

    No score changed. Bitcoin's exposure dimension cited a Forbes article for a figure Deloitte produced, and now cites Deloitte's own analysis directly.

    Cardano's exposure dimension cited Input Output's Cardano Vision 2026 announcement for claims about the address model, stake key visibility and the share of ADA that has moved, none of which that article makes. It now cites CIP-19, which defines a Shelley address as a payment credential plus a delegation credential, each a blake2b-224 hash of an Ed25519 verification key.

    The unmeasured claim about how much ADA has moved has been removed rather than resourced, and the profile now states plainly that no published measurement of Cardano's exposed share could be found.

    Bitcoin Cardano source ↗

  16. Correction

    Cardano's D3.1 deliverable named as its source names it

    Cardano's profile described deliverable D3.1 as publishing a migration strategy as a Cardano Improvement Proposal. Input Output's own wording is a SIP. The profile and roadmap now use the term the source uses. No score changed.

    Cardano source ↗

  17. Score change

    Algorand: signature 8 to 9

    Native Falcon-1024 accounts shipped as a first-class protocol-level account type in the go-algorand 5.0.0 stable consensus release, moving signature to the top of the 7-9 band while Ed25519 remains the default. Detected from release v5.0.0-stable and verified against the linked source before merge.

    Algorand source ↗

  18. Methodology

    Methodology v1.1: the bottom of the spine becomes Exposed

    The fifth rung of the readiness spine was Unverified, which described a chain marketing itself as quantum-safe without a confirmed deployment. That left no rung for a chain with quantum-vulnerable signatures and no published position at all, so five such chains sat in Debating carrying a label more generous than their evidence.

    The fifth rung is now Exposed: quantum-vulnerable signatures on mainnet today, and no public post-quantum plan, proposal or research programme. Unverified becomes a flag rather than a rung, applied to a chain whose marketing claim cannot be confirmed but whose evidence still supports a published row.

    The deployment-score mapping is unchanged, so this re-labels the floor rather than re-weighting the rubric.

  19. Score change

    Five chains re-tiered from Debating to Exposed

    Avalanche, Dogecoin, Hyperliquid, Litecoin and TON were placed in Tier 4: Debating only because the spine had nowhere lower, and each carried a caveat saying so. Under the v1.1 spine they move to Tier 5: Exposed, which is what the evidence supports: quantum-vulnerable signatures securing funds on mainnet today, and no post-quantum plan, proposal or research programme that we could find.

    Their deployment dimension falls from 2 to 1, which lowers each Hardy Score by 2.5 points. No other dimension changed and no other chain moved.

    Bitcoin, BNB Chain, IOTA and Tron remain in Debating, because each has acknowledged the threat and has proposals, research or a stated intention on the public record.

    Avalanche Dogecoin Hyperliquid Litecoin TON

  20. Coverage

    QANplatform held back pending a public mainnet

    QANplatform was rated at the foot of the index while the bottom rung was Unverified. The v1.1 rung is Exposed, which describes the signatures securing funds on a live mainnet, and QANplatform has no public mainnet: there is no deployed scheme to inspect and no balances to assess.

    Placing it on that rung would assert something we cannot check, and placing it higher would credit marketing, so the row is held back under the same rule that withholds Cellframe and Quranium.

    Nothing here disputes QANplatform’s algorithm choice, which is NIST-standardised, or its component audits, which are real. The row returns when a mainnet is live and its signature scheme can be confirmed against a primary source.

  21. Coverage

    Coverage expanded to 24 layer-1 chains

    Fourteen chains were added after verification against primary sources: Hedera, Sui, Polkadot, Zcash, Stellar and Aptos join Tier 3 on the strength of published roadmaps, while BNB Chain, Tron, Avalanche, Dogecoin, Litecoin, TON and Hyperliquid enter Tier 4. Abelian enters Tier 1, having run lattice-based post-quantum signatures on mainnet since 2022. Every added row carries a note and a primary source on all six dimensions.

    Hedera Sui Polkadot Zcash Stellar Aptos Abelian

  22. Coverage

    Cellframe and Quranium held back pending verification

    Both projects market native post-quantum protection and both may well deserve a high placement, but neither could be confirmed. Cellframe documentation lists post-quantum algorithms as available without confirming which scheme secures ordinary transactions by default. Quranium developer documentation was not reachable at the time of writing, leaving its claim resting on announcements rather than an inspectable specification. Publishing an unverified high score would damage this index as much as publishing an unfair low one, so both rows are withheld until the deployed scheme can be checked.

  23. Methodology

    Scope boundary published, and Quant and Starknet ruled out

    The index rates layer-1 blockchains only, meaning networks whose own signature scheme secures the balances people hold. Layer 2s, oracles, middleware, stablecoins and tokens are excluded, each for a stated reason, on the About page.

    Two named exclusions follow: Quant, because Overledger is interoperability middleware and QNT is an ERC-20 token that carries Ethereum exposure rather than its own, and Starknet, because it is an Ethereum layer 2 whose settlement security is partly inherited.

    Starknet is excluded despite substantive post-quantum work, since its hash-based STARK proofs are not vulnerable to Shor while its Stark-curve account keys are, and that distinction is not comparable on a layer-1 scale.

  24. Correction

    IOTA reclassified from Native to Debating

    IOTA is widely described as quantum-resistant on the strength of its original Winternitz one-time signature scheme. That scheme was removed in the Chrysalis upgrade in 2021 and replaced with Ed25519, which is quantum-vulnerable. IOTA’s current post-quantum support (ML-DSA, SLH-DSA and Falcon) sits in IOTA Identity and covers verifiable credentials, not layer-1 transaction signatures. We found no dated plan to restore post-quantum signatures at layer 1, so IOTA enters the index at Tier 4: Debating, not Tier 1: Native.

    IOTA source ↗

  25. Correction

    Nervos CKB classified as Shipping rather than Committed

    Nervos CKB’s SPHINCS+ lock script was audited by ScaleBit and began mainnet deployment in 2025, and a wallet using it has shipped. That is a post-quantum signature protecting real funds on mainnet, which places Nervos in Tier 2: Shipping rather than Tier 3: Committed.

    Nervos CKB source ↗

  26. Coverage

    Index launched with ten chains

    The Hardy Index published its first ranked dataset: Bitcoin, Ethereum, Solana, XRP Ledger, Cardano, Algorand, Nervos CKB, IOTA, QRL and QANplatform. Every dimension score carries a note and a primary source.

  27. Methodology

    Hardy Score methodology v1.0 published

    The six weighted dimensions, their 0 to 10 anchors and the five-tier readiness spine were published in full. The deployment dimension is derived from the tier rather than scored separately, so a tier and a score can never contradict each other.

Spotted something wrong? Send the primary source that contradicts it to index@hardyindex.com. Corrections are logged here, including ours.

This is a security-readiness assessment, not investment advice.