---
title: The chain that was quantum-resistant before it was a headline
description: QRL has required hash-based XMSS signatures for every account since 2018. What that purity bought, what it cost, and where the successor chain stands.
url: "https://hardyindex.com/news/qrl-native-original"
section: Readiness history
type: readiness-history
published: 2026-08-12
updated: 2026-08-12
chains: qrl
methodology_version: 1.4
---

# The chain that was quantum-resistant before it was a headline

**QRL has required XMSS, a hash-based signature scheme, for every account since its mainnet launched in June 2018. Nothing was retrofitted and nothing is opt-in. The cost of that purity is stateful key management and large signatures, and the successor chain running NIST-standardised ML-DSA still has no published mainnet date.**

*Published 12 August 2026. The rating below is current as of 2 October 2026. This is a security-readiness assessment, not investment advice.*

Building for this from the first block is a different discipline from retrofitting it later, and it has a price.

## Built for this from the first block

Three chains in this index never needed a migration conversation: QRL, Mochimo and Abelian, each built on quantum-resistant signatures from genesis. Everyone else is having one. QRL started where the others are trying to get to.

Its documentation puts it plainly: rather than relying on traditional ECDSA, QRL implemented XMSS, described as "a hash-based, forward-secure signature that's been audited and proven resistant to quantum-computer attacks". Hash-based signatures do not rest on the discrete logarithm problem, which is the specific thing Shor's algorithm dismantles.

The word doing the work is mandatory. There is no legacy account type, no opt-in flag and no subset of users who are protected while others are not. XMSS is how the chain works.

From QRL's own project pages.

- **June 2018**: Mainnet launches with XMSS as the mandatory signature scheme for every account.
  Source: https://www.theqrl.org/2/
- **December 2022**: A public devnet pre-release of the successor chain appears, beginning a long move toward proof of stake and a lattice-based signature scheme.
  Source: https://www.theqrl.org/2/
- **Q1 2024**: The beta testnet for the successor chain launches.
  Source: https://www.theqrl.org/2/
- **Q1 2025**: Testnet V1 goes live, after a year of beta testing and incremental upgrades.
  Source: https://www.theqrl.org/2/
- **Q1 2026**: Testnet V2 launches as the audit-ready public testnet, integrating NIST-standardised ML-DSA to protect transactions and validator operations.
  Source: https://www.theqrl.org/2/

## What that purity costs

This is the part worth being honest about, because a chain that only ever gets praised for its cryptography is a chain nobody has looked at properly.

XMSS is stateful. Each signature consumes a one-time key from a finite tree, and the wallet has to track which keys it has already used. Lose that state, restore an old backup, or run the same seed in two places, and you can reuse a key, which is the one thing the scheme cannot tolerate. Conventional wallets do not have this failure mode, and it is a genuine burden to place on ordinary users.

The signatures are also large by comparison, and the tree has a finite capacity, so an account has a bounded number of signatures before it needs replacing. These are not flaws in the implementation. They are the intrinsic trade-offs of hash-based signing, and QRL has been living with them in production longer than anyone.

> **Why this is useful to know.** IOTA abandoned hash-based signatures in 2021 for exactly these usability reasons. QRL kept them and built the tooling around them instead. The same trade-off, answered two opposite ways, and both answers are defensible.

## The successor chain, and the date that is not there

QRL 2.0, developed as Project Zond, moves the chain to proof of stake and to ML-DSA, the lattice-based scheme NIST standardised as FIPS 204. That would trade stateful hash-based signing for a stateless standardised scheme, removing the key-management burden that is the main practical objection to XMSS.

The testnet progression is real and public, and it reached an audit-ready V2 in the first quarter of 2026. What does not exist is a mainnet date. QRL says so directly: "We have not yet set a mainnet date. The timing will depend on development, audit outcomes, and overall network stability."

We would rather read that than a date invented for a press release, and refusing to commit to one before an audit completes is the correct engineering instinct. It does mean the successor chain is not something you can rely on yet.

## What this means if you hold QRL

Your signature scheme is not the thing to worry about, and that is a rare sentence in this index.

**Where this stands today.**

- [Quantum Resistant Ledger](https://hardyindex.com/chains/qrl): Tier 1: Native, Hardy Score 92.0 of 100.

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded at https://hardyindex.com/changelog.md.

What deserves your attention is the operational discipline instead. Follow the wallet's guidance about backups and never run the same seed in two places at once, because with a stateful scheme that is a real risk rather than a theoretical one. The cryptography is doing its job. The failure mode that remains is human.

## Where to go next

- [Quantum Resistant Ledger: the full rating](https://hardyindex.com/chains/qrl.md): every dimension score, with the source behind each one.
- [Which is the most quantum-resistant blockchain?](https://hardyindex.com/guides/most-quantum-resistant-blockchain.md): One question, one answer, with the working shown. This page is a summary of the Hardy Index, which is the live ranking behind it.
- [Quantum-safe wallets: what is real and what is marketing](https://hardyindex.com/guides/quantum-safe-wallets.md): Quantum-ready is the fastest-growing label in crypto hardware. Here is what it means, what it does not, and how to choose without paying for a promise nobody can keep yet.

## Sources

Every dated event above carries its own primary source. These are those sources, checked on the dates shown.

1. [QRL 2.0: A blockchain engineered for the post-quantum world](https://www.theqrl.org/2/): The Quantum Resistant Ledger (primary, checked 12 August 2026)
2. [Project Zond, by QRL: a blockchain engineered for the post-quantum era](https://www.theqrl.org/project-zond/): The Quantum Resistant Ledger (primary, checked 12 August 2026)
3. [SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes](https://csrc.nist.gov/pubs/sp/800/208/final): NIST (primary, checked 12 August 2026)
4. [FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA)](https://csrc.nist.gov/pubs/fips/204/final): NIST (primary, checked 12 August 2026)

---
Cite as: The Hardy Index, "The chain that was quantum-resistant before it was a headline", https://hardyindex.com/news/qrl-native-original, published 12 August 2026.
