Hardy Index Quantum readiness benchmark

What changed · What changed

Monero and Mochimo joined the index on 13 August 2026

Two rows added on 13 August for opposite reasons: one was the biggest gap we had left, the other signs with no elliptic curve at all.

The short answer

Monero and Mochimo were added to the Hardy Index on 13 August 2026, which took coverage to 25 chains on that date; it now holds 31. Monero entered as the tenth largest layer 1, with funded post-quantum research but no chosen scheme. Mochimo entered with hash-based signing verified in its node source. Neither rating is a forecast.

What moved and why

A record, not a bulletinThis was published on 19 August 2026 and records a change made on 13 August. Chain counts in it are stated as they stood on that date. Every rating shown is read live from the index, so the scores are current even where the narrative is not.

Both additions followed the coverage rule published the same day. A chain enters either on scale, meaning it is large enough that leaving it out would be a hole, or on deployment, meaning it already runs post-quantum signing that can be checked in code.

Monero entered on the scale test. It was the most conspicuous gap in the index. It signs with Ed25519, and its privacy machinery, CLSAG ring signatures, stealth addresses and Bulletproofs, all sits on the same elliptic curve. There is no post-quantum scheme deployed. There is real research: the community funded and completed a dedicated post-quantum study, and lattice-based candidates such as MatRiCT and Raptor have been analysed. Candidates are not a choice, and a choice is not a schedule.

Mochimo entered on the deployment test. It signs with WOTS+, a hash-based one-time signature scheme, and it has done so since genesis rather than bolting one on later. We read that in the node source rather than taking it from project material. The repository contains no elliptic-curve signature implementation of any kind, which is what makes post-quantum signing mandatory here instead of optional.

Where this stands today

  • Monero 4 Debating Hardy 21.0 of 100
  • Mochimo 1 Native Hardy 90.0 of 100

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded in the changelog.

What these ratings do not mean

Monero's placement is not a claim that a fix is coming. Nothing has been selected and nothing has been scheduled. It is also not a claim that Monero is doing nothing: the research work is genuine and more thorough than several larger chains have managed.

Monero carries the lowest exposure score of any chain in the index, and that needs saying plainly. A one-time output public key is published on chain for every output, so keys are not hidden behind a hash the way they are on some other chains. Worse, a break of the underlying curve would not only affect future spends. It would retroactively unmask senders inside ring signatures that are already recorded. That is a privacy exposure as well as a funds exposure, and it is the reason a wallet you never touch again is still exposed. Our guide on harvest now, decrypt later covers the same shape of problem.

Mochimo's rating is not a clean bill of health either. Its NIST alignment is held at seven out of ten, not full marks. NIST SP 800-208 approves XMSS and LMS, which are stateful hash-based schemes built on Winternitz components. It does not approve the standalone WOTS+ construction Mochimo uses. The maths is well understood and documented in RFC 8391, but a standards body approving a related scheme is not the same as approving this one.

On one-time signaturesWOTS+ keys are safe to use once. Reuse leaks the private key. That is a property of the scheme, handled at the protocol and wallet layer, not a defect we are flagging.

The record

Dated, sourced events behind both rows.

  1. RFC 8391 publishes the XMSS specification, including the Winternitz one-time signature parameters Mochimo's implementation follows. source
  2. A Monero community crowdfunding proposal funds dedicated post-quantum research for the protocol. source
  3. The resulting write-ups are published, reviewing lattice-based linkable ring signature candidates for Monero. source
  4. NIST publishes SP 800-208, approving the stateful hash-based schemes XMSS and LMS. source
  5. Mochimo's node source defines its WOTS+ signing parameters, with no elliptic-curve signature code in the repository. source

If you hold either asset

If you hold XMR, the practical point is that there is no migration path to prepare for yet. There is no post-quantum address format to move to and no announced upgrade window. What you can do is follow the protocol research discussion, because a selected scheme is the first thing that would change this rating.

  • Monero: no scheme chosen, no schedule, and the privacy exposure is retroactive rather than forward-looking only. See Monero.
  • Mochimo: post-quantum signing is the only option the software offers, so there is no opt-in step for you to miss. See Mochimo.
  • Neither row is investment guidance. Read them as a description of code and process, nothing more.

If you hold MCM, the thing worth understanding is why the score is not a perfect one. The standards gap is real and it matters for anyone who needs formal compliance. It does not mean the signing is weak. If you are comparing chains on this basis, most quantum resistant blockchain sets out how we weight deployed code against standards alignment.

Where to go next

Sources

Every dated event above carries its own primary source. These are those sources, each checked on the date shown.

  1. Which chains the index covers Hardy Index · primary · checked 19 August 2026
  2. Post-quantum Monero: semi-technical summary Insight Decentralized Consensus Lab · primary · checked 19 August 2026
  3. Research: post-quantum Monero Monero Community Crowdfunding System · primary · checked 19 August 2026
  4. Research lab issue 131 Monero Project · secondary · checked 19 August 2026
  5. Mochimo node source: wots.h Mochimo · primary · checked 19 August 2026
  6. Mochimo repository Mochimo · secondary · checked 19 August 2026
  7. NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes NIST · primary · checked 19 August 2026
  8. RFC 8391: XMSS eXtended Merkle Signature Scheme IETF · primary · checked 19 August 2026

This is a security-readiness assessment, not investment advice.