---
title: The quiet chain that already ships a post-quantum signature
description: Nervos CKB has an audited SPHINCS+ lock script live on mainnet, supporting all twelve FIPS 205 parameter sets. Almost nobody noticed. Here is the record.
url: "https://hardyindex.com/news/nervos-ckb-sphincs-plus-on-mainnet"
section: Readiness history
type: readiness-history
published: 2026-08-12
updated: 2026-08-12
chains: nervos-ckb
methodology_version: 1.4
---

# The quiet chain that already ships a post-quantum signature

**Nervos CKB has a SPHINCS+ lock script deployed on mainnet, audited by ScaleBit, supporting all twelve parameter sets in the NIST FIPS 205 standard. It is opt-in rather than default, so most funds still sit behind secp256k1, but the protection is real, shipped and usable today rather than promised.**

*Published 12 August 2026. The rating below is current as of 2 October 2026. This is a security-readiness assessment, not investment advice.*

Post-quantum protection went live on a mainnet, was audited, and drew almost no attention at all.

## The record

A rating agency earns its keep on the stories nobody is telling. This is one of them.

From the Nervos documentation, the implementation repository, and NIST.

- **2023**: The CKB team and researchers at Cryptape implement what the documentation calls a "production-ready Quantum Resistant Lock Script" using SPHINCS+, a hash-based signature scheme.
  Source: https://docs.nervos.org/docs/ckb-features/native-quantum-resistance
- **August 2024**: NIST formally approves SPHINCS+ as SLH-DSA under the FIPS 205 standard, so the scheme already implemented becomes a finalised standard rather than a candidate.
  Source: https://csrc.nist.gov/pubs/fips/205/final
- **2025**: The CKB team begins deploying the SPHINCS+ lock script on CKB mainnet. The deployed script's code hash and deployment transaction are published in the implementation repository, so anyone can verify what is running.
  Source: https://github.com/nervosnetwork/quantum-resistant-lock-script
- **December 2025**: ScaleBit's security audit report on the lock script is dated, covering the implementation that had been deployed.
  Source: https://github.com/nervosnetwork/quantum-resistant-lock-script

## How it works, and why the design is clever

CKB does not hard-code a signature scheme into consensus the way most chains do. Spending conditions live in a lock script, which is a small program attached to a cell, and users choose which lock script guards their funds. Post-quantum signing was therefore added without a hard fork, because it did not need one.

The implementation supports all twelve SPHINCS+ parameter sets defined in FIPS 205, at 128, 192 and 256 bit security levels in both small and fast variants, in what the repository calls an all-in-one mode. You pick your trade-off rather than having one picked for you.

It is not free. A SPHINCS+ signature runs to roughly 20 kilobytes against 64 bytes for a conventional one, which is why they are carried in the transaction's witness rather than anywhere more expensive. Hash-based signatures buy their security with size, and that arithmetic is the same everywhere.

> **The important caveat.** This is opt-in. New addresses referencing the new script's code hash get post-quantum protection, and old addresses continue to work exactly as before. Most CKB in existence is still behind secp256k1, and nothing about this deployment changes that on its own.

## Why this is worth surfacing

Compare the volume of discussion. A draft proposal on a large chain generates months of coverage. An audited post-quantum signature scheme actually running on a mainnet, with a published code hash you can check yourself, generated almost none.

That asymmetry is precisely the gap an index is supposed to close. We score what is deployed and verifiable, not what is discussed, and on that measure Nervos has done something only a handful of chains have done at all.

**Where this stands today.**

- [Nervos CKB](https://hardyindex.com/chains/nervos-ckb): Tier 2: Shipping, Hardy Score 75.5 of 100.

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded at https://hardyindex.com/changelog.md.

## What this means if you hold CKB

You have an option most holders on most chains do not have, and having an option is not the same as having used it. If your funds sit at an ordinary address, they are protected by secp256k1 and the post-quantum lock script is not doing anything for you.

The route exists, it has been audited, and the trade-off you are accepting if you take it is larger transactions and a smaller pool of tooling that understands the script. That is a real cost, and it is a legitimate reason to wait. It is a better position than having nothing to wait for.

## Where to go next

- [Nervos CKB: the full rating](https://hardyindex.com/chains/nervos-ckb.md): every dimension score, with the source behind each one.
- [Which is the most quantum-resistant blockchain?](https://hardyindex.com/guides/most-quantum-resistant-blockchain.md): One question, one answer, with the working shown. This page is a summary of the Hardy Index, which is the live ranking behind it.

## Sources

Every dated event above carries its own primary source. These are those sources, checked on the dates shown.

1. [Native Quantum Resistance](https://docs.nervos.org/docs/ckb-features/native-quantum-resistance): Nervos Network (primary, checked 12 August 2026)
2. [quantum-resistant-lock-script](https://github.com/nervosnetwork/quantum-resistant-lock-script): Nervos Network (primary, checked 12 August 2026)
3. [FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA)](https://csrc.nist.gov/pubs/fips/205/final): NIST (primary, checked 12 August 2026)

---
Cite as: The Hardy Index, "The quiet chain that already ships a post-quantum signature", https://hardyindex.com/news/nervos-ckb-sphincs-plus-on-mainnet, published 12 August 2026.
