---
title: Why we rate IOTA Tier 5 when much of the market still calls it quantum-safe
description: IOTA replaced its quantum-resistant Winternitz signatures with Ed25519 in April 2021. The dated, sourced history behind the rating we give it today.
url: "https://hardyindex.com/news/iota-quantum-safe-reputation"
section: Readiness history
type: readiness-history
published: 2026-08-12
updated: 2026-08-12
chains: iota
methodology_version: 1.4
---

# Why we rate IOTA Tier 5 when much of the market still calls it quantum-safe

**No. IOTA's layer 1 has not been quantum-resistant since April 2021, when the Chrysalis upgrade replaced its hash-based Winternitz signatures with Ed25519. IOTA does run post-quantum algorithms today, but inside IOTA Identity, protecting credentials rather than tokens. The reputation is real. It just describes a scheme IOTA removed five years ago.**

*Published 12 August 2026. The rating below is current as of 2 October 2026. This is a security-readiness assessment, not investment advice.*

A reputation can outlive the fact it was built on. IOTA's has, by five years and counting.

## Where the quantum-safe reputation came from

If you have read that IOTA is quantum-resistant, you were not reading a myth. You were reading something that used to be true.

IOTA's original protocol signed transactions with Winternitz one-time signatures, a hash-based scheme. Hash-based signatures matter here because Shor's algorithm, the quantum algorithm that breaks the elliptic-curve cryptography almost every other chain relies on, does not break them. IOTA's own specification for the change describes Winternitz as "the currently used" scheme at the time, so this is not a claim outsiders invented.

It came with a hard cost, and IOTA documented that too. A Winternitz key is safe for exactly one signature. As the specification puts it, "starting from the second signature so much information has been exposed, that the private key, and as such the funds on that address, are considered insecure." Every payment you sent had to move to a fresh address, and wallets that got that wrong put real funds at risk.

So IOTA was carrying genuine quantum resistance and a genuine usability problem at the same time. In January 2020 it published a proposal to trade one for the other.

## What actually changed, and when

The clearest evidence about this change is IOTA's own, which is unusual and worth crediting. The proposal did not bury the trade-off; it named it in a single clause.

From IOTA's own specifications and announcements.

- **January 2020**: IOTA published a specification for adopting Ed25519 alongside the Winternitz scheme then in use, stating plainly that it "aims to address all the points above with the drawback of being less quantum robust". The same document set out the mitigation: "the address is chosen as the hash of the public key, which itself is only revealed during the actual signing process."
  Source: https://github.com/iotaledger/tips/blob/1d82efcd67895097ffabdb3f4fcb00f1646859f7/text/0009-ed25519-signature-scheme/0009-ed25519-signature-scheme.md
- **28 April 2021**: The Chrysalis network upgrade went live, described by the foundation as "a token transition from the old WOTS signature scheme to the new EdDSA signatures". Addresses became reusable, and the hash-based signatures were gone.
  Source: https://blog.iota.org/chrysalis-network-migration-release-date/
- **5 May 2025**: IOTA began migrating "from the Stardust network to the new IOTA network", rebuilding the layer-1 protocol. The announcement covers the migration itself and does not discuss signature schemes.
  Source: https://blog.iota.org/rebased-mainnet-upgrade/

Note what the last entry does not say. The 2025 rebuild was a chance to revisit transaction signing, but the announcement does not mention cryptography either way, so we are not going to tell you what it decided. For that, the place to look is the current documentation, which is the next section.

That is the whole story of how the fact changed. What did not change is what people say about it, and that gap is now five years wide.

## What signs an IOTA transaction today

IOTA's current documentation lists four ways to authorise a transaction: pure Ed25519, ECDSA over secp256k1, ECDSA over secp256r1, and multisig combinations of those. None of them is post-quantum. A sufficiently large quantum computer running Shor's algorithm breaks all three underlying curves, and a multisig built from them inherits the weakness rather than escaping it.

There is one piece of good news in the details, and it is the mitigation the 2020 specification promised. An IOTA address is a BLAKE2b-256 hash of the public key rather than the key itself. A funded address that has never signed anything therefore has not published the key that protects it, so it cannot be harvested today and attacked later. The moment you spend from it, the key is on the public record.

> **What that means in practice.** Address hashing buys time for coins that have never moved. It does nothing for any address you have already spent from, which for most active holders is the address that matters.

**Where this stands today.**

- [IOTA](https://hardyindex.com/chains/iota): Tier 5: Exposed, Hardy Score 18.5 of 100.

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded at https://hardyindex.com/changelog.md.

## IOTA does run post-quantum cryptography, just not where your tokens are

This is the part most coverage gets wrong in the other direction, by treating IOTA as if it had done nothing. It has.

IOTA Identity, the library for issuing and verifying digital credentials, added post-quantum signature support in version 1.7. The algorithms are the serious ones: ML-DSA at security levels 44, 65 and 87, SLH-DSA at 128, 192 and 256 bits, and Falcon at 512 and 1024, plus hybrid combinations with EdDSA. ML-DSA and SLH-DSA are NIST standards. This is real work, competently chosen.

It protects a different thing, though. Credentials and presentations are not tokens, and the documentation is candid about where the protection stops, warning that "storing such a DID Document on a non-PQC-capable DLT would be unsafe". That sentence is IOTA describing the gap between its identity layer and its ledger, in its own words.

We looked for a published plan, with a date and a named scheme, to bring post-quantum signatures back to layer-1 transactions. As of 12 August 2026, searching IOTA's documentation, specification repository and foundation blog, we did not find one. That is a statement about what a careful search turned up on that date, not a claim that no work exists. If you can point us at a dated plan we have missed, we will publish the correction.

## What this means if you hold IOTA

Nothing is breaking today. No quantum computer that exists can derive a private key from an Ed25519 public key, and the honest estimates for one that could are still measured in years. This is a preparedness rating, not an alarm.

What the rating tells you is narrower and more useful than a headline. IOTA has already proved it can change its signature scheme across an entire live network, which most chains have never done, and that is a real asset when the time comes. What is missing is a dated commitment to do it again in the direction of post-quantum safety. Capability is demonstrated; intent is not scheduled.

So if you are holding IOTA on the understanding that it is quantum-safe, the useful thing to update is not your position but your reason. That belief was accurate once. It has not been for five years, and the chain's own documents are the clearest place to check that for yourself. Every source behind this piece is linked below, and we would rather you read them than take our word for it.

## Where to go next

- [IOTA: the full rating](https://hardyindex.com/chains/iota.md): every dimension score, with the source behind each one.
- [Is my crypto safe from quantum computers?](https://hardyindex.com/guides/is-my-crypto-safe-from-quantum-computers.md): If you have seen the scary headlines about quantum computers and crypto, here is the calm version. What is true, what it means for the coins you hold, and what is worth doing about it.
- [Which crypto is quantum proof?](https://hardyindex.com/guides/which-crypto-is-quantum-proof.md): Plenty of projects call themselves quantum proof. Here is the independently checked version, and why the phrase itself is worth handling carefully.

## Sources

Every dated event above carries its own primary source. These are those sources, checked on the dates shown.

1. [TIP-0009: Ed25519 Signature Scheme](https://github.com/iotaledger/tips/blob/1d82efcd67895097ffabdb3f4fcb00f1646859f7/text/0009-ed25519-signature-scheme/0009-ed25519-signature-scheme.md): IOTA Foundation (Tangle Improvement Proposals) (primary, checked 12 August 2026)
2. [Chrysalis Network Migration: Release Date](https://blog.iota.org/chrysalis-network-migration-release-date/): IOTA Foundation (primary, checked 12 August 2026)
3. [The IOTA Rebased Mainnet Upgrade](https://blog.iota.org/rebased-mainnet-upgrade/): IOTA Foundation (primary, checked 12 August 2026)
4. [Signatures: transaction authentication](https://docs.iota.org/developer/cryptography/transaction-auth/signatures): IOTA Foundation (primary, checked 12 August 2026)
5. [Keys and Addresses](https://docs.iota.org/developer/cryptography/transaction-auth/keys-addresses): IOTA Foundation (primary, checked 12 August 2026)
6. [Post-Quantum Cryptography: IOTA Identity](https://docs.iota.org/developer/iota-identity/how-tos/post-quantum): IOTA Foundation (primary, checked 12 August 2026)

---
Cite as: The Hardy Index, "Why we rate IOTA Tier 5 when much of the market still calls it quantum-safe", https://hardyindex.com/news/iota-quantum-safe-reputation, published 12 August 2026.
