The short answer
Monero and Mochimo were added to the Hardy Index on 13 August 2026, which took coverage to 25 chains on that date; it now holds 31. Monero entered as the tenth largest layer 1, with funded post-quantum research but no chosen scheme. Mochimo entered with hash-based signing verified in its node source. Neither rating is a forecast.
What moved and why
A record, not a bulletinThis was published on 19 August 2026 and records a change made on 13 August. Chain counts in it are stated as they stood on that date. Every rating shown is read live from the index, so the scores are current even where the narrative is not.
Both additions followed the coverage rule published the same day. A chain enters either on scale, meaning it is large enough that leaving it out would be a hole, or on deployment, meaning it already runs post-quantum signing that can be checked in code.
Monero entered on the scale test. It was the most conspicuous gap in the index. It signs with Ed25519, and its privacy machinery, CLSAG ring signatures, stealth addresses and Bulletproofs, all sits on the same elliptic curve. There is no post-quantum scheme deployed. There is real research: the community funded and completed a dedicated post-quantum study, and lattice-based candidates such as MatRiCT and Raptor have been analysed. Candidates are not a choice, and a choice is not a schedule.
Mochimo entered on the deployment test. It signs with WOTS+, a hash-based one-time signature scheme, and it has done so since genesis rather than bolting one on later. We read that in the node source rather than taking it from project material. The repository contains no elliptic-curve signature implementation of any kind, which is what makes post-quantum signing mandatory here instead of optional.
What these ratings do not mean
Monero's placement is not a claim that a fix is coming. Nothing has been selected and nothing has been scheduled. It is also not a claim that Monero is doing nothing: the research work is genuine and more thorough than several larger chains have managed.
Monero carries the lowest exposure score of any chain in the index, and that needs saying plainly. A one-time output public key is published on chain for every output, so keys are not hidden behind a hash the way they are on some other chains. Worse, a break of the underlying curve would not only affect future spends. It would retroactively unmask senders inside ring signatures that are already recorded. That is a privacy exposure as well as a funds exposure, and it is the reason a wallet you never touch again is still exposed. Our guide on harvest now, decrypt later covers the same shape of problem.
Mochimo's rating is not a clean bill of health either. Its NIST alignment is held at seven out of ten, not full marks. NIST SP 800-208 approves XMSS and LMS, which are stateful hash-based schemes built on Winternitz components. It does not approve the standalone WOTS+ construction Mochimo uses. The maths is well understood and documented in RFC 8391, but a standards body approving a related scheme is not the same as approving this one.
On one-time signaturesWOTS+ keys are safe to use once. Reuse leaks the private key. That is a property of the scheme, handled at the protocol and wallet layer, not a defect we are flagging.
The record
Dated, sourced events behind both rows.
- RFC 8391 publishes the XMSS specification, including the Winternitz one-time signature parameters Mochimo's implementation follows. source
- A Monero community crowdfunding proposal funds dedicated post-quantum research for the protocol. source
- The resulting write-ups are published, reviewing lattice-based linkable ring signature candidates for Monero. source
- NIST publishes SP 800-208, approving the stateful hash-based schemes XMSS and LMS. source
- Mochimo's node source defines its WOTS+ signing parameters, with no elliptic-curve signature code in the repository. source
If you hold either asset
If you hold XMR, the practical point is that there is no migration path to prepare for yet. There is no post-quantum address format to move to and no announced upgrade window. What you can do is follow the protocol research discussion, because a selected scheme is the first thing that would change this rating.
- Monero: no scheme chosen, no schedule, and the privacy exposure is retroactive rather than forward-looking only. See Monero.
- Mochimo: post-quantum signing is the only option the software offers, so there is no opt-in step for you to miss. See Mochimo.
- Neither row is investment guidance. Read them as a description of code and process, nothing more.
If you hold MCM, the thing worth understanding is why the score is not a perfect one. The standards gap is real and it matters for anyone who needs formal compliance. It does not mean the signing is weak. If you are comparing chains on this basis, most quantum resistant blockchain sets out how we weight deployed code against standards alignment.
Where to go next
- Monero: the full rating Every dimension score, with the source behind each one, and what the rating means if you hold it.
- Mochimo: the full rating Every dimension score, with the source behind each one, and what the rating means if you hold it.
- Which is the most quantum-resistant blockchain? One question, one answer, with the working shown. This page is a summary of the Hardy Index, which is the live ranking behind it.
- Harvest now, decrypt later: what it means for your crypto This is the reason experts say the quantum threat is already here, even though the machine that would carry it out is not. It is simpler than it sounds.
- Which crypto is quantum proof? Plenty of projects call themselves quantum proof. Here is the independently checked version, and why the phrase itself is worth handling carefully.
Sources
Every dated event above carries its own primary source. These are those sources, each checked on the date shown.
- Which chains the index covers Hardy Index · primary · checked 19 August 2026
- Post-quantum Monero: semi-technical summary Insight Decentralized Consensus Lab · primary · checked 19 August 2026
- Research: post-quantum Monero Monero Community Crowdfunding System · primary · checked 19 August 2026
- Research lab issue 131 Monero Project · secondary · checked 19 August 2026
- Mochimo node source: wots.h Mochimo · primary · checked 19 August 2026
- Mochimo repository Mochimo · secondary · checked 19 August 2026
- NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes NIST · primary · checked 19 August 2026
- RFC 8391: XMSS eXtended Merkle Signature Scheme IETF · primary · checked 19 August 2026
This is a security-readiness assessment, not investment advice.