Cardano is the only chain in the batch with a named PQC lead who will tell you the performance cost out loud. Hoskinson flagged the 10x penalty without hardware acceleration, which is a rare thing: a roadmap that admits its own expense before it has shipped a line of code.
Summary
Cardano has the most detailed PQC roadmap among major L1s (Hoskinson's Nightstream lattice-based ZK replacement for PlonK/Halo2, Mithril proof-chain certificate strategy, declared FIPS 203-206 alignment), paired with the best governance structure (Voltaire/CIP-1694 tripartite: DReps + Constitutional Committee + SPOs, completed March 2026). Hoskinson publicly warned of 10x perf penalty without HW acceleration — a rare empirical voice. eUTXO + BLAKE2b-224 hashed addresses hide unspent keys. KES rotation (~36hr) provides forward security for block production. No PQC code on mainnet; Midnight (launched March 2026) uses classical ZK-SNARKs pending Nightstream.
What the gates say
- Hybrid: PASS. Hybrid-PQ design present.
- Evidence: PASS. Sources reconstructable by third party.
- Primitive naming: PASS. Named primitives at every scored sub-level.
Burn-vs-rescue policy on file
undeclared (Hoskinson noted tradeoffs; no formal burn-vs-rescue position). eUTXO unspent UTXOs analogous to Bitcoin dormant.
Seven dimensions
Each dimension scores 0-100 internally; the weighted roll-up produces the QRI on the left. Open a row to read the sub-score detail.
1 Cryptographic Exposure 40 / 100
KES rotation every ~36 hours limits exposure. eUTXO + BLAKE2b-224 hash addresses hide keys until first spend.
Ed25519 (tx sigs + VRF) · KES Key-Evolving Signatures (Ed25519-based) · BLAKE2b-256 (block hashes) · BLAKE2b-224 (Shelley address derivation) · PlonK/Halo2 (Midnight ZK-SNARKs; elliptic curve based)Nightstream lattice-based ZK replacement in development. Mainnet primitives classical-only.
FIPS 203-206 alignment declared by IOG but no mainnet mapping yet.
2 HNDL Exposure 35 / 100
eUTXO + BLAKE2b-224 hash-of-pubkey addresses. Keys hidden until first spend (Bitcoin-like). Estimated 30-50% ADA in exposed-key UTXOs.
Mainnet since Sept 2017 (Byron era, 102 months). Long history; many wallets never spent. IOG/Foundation/Emurgo ~20% allocation.
KES rotation (~36hr) limits block-producer key exposure. Account Ed25519 sigs Shor-breakable but hashed address hides key pre-spend.
Ouroboros Praos p2p via TLS; MuxTime protocol. Standard NaCl for node-to-node.
3 Metadata & Privacy Exposure 25 / 100
eUTXO pseudonymous. Midnight (privacy sidechain launched Mar 2026) adds optional privacy via ZK-SNARKs.
3000+ SPOs; self-hosted nodes common; AWS concentration among SPOs noted.
Limited bridges (Wanchain, Milkomeda). Cardano-native ecosystem.
Ed25519 Shor-broken; hashed addresses limit retroactive pubkey exposure pre-spend but post-spend is exposed.
4 Migration Architecture 55 / 100
Hard Fork Combinator enables smooth protocol upgrades. eUTXO + Plutus V3 scripts allow custom verification logic. KES rotation model already uses forward-secure signatures.
eUTXO script addresses provide some AA-like flexibility. No native AA.
Byron→Shelley (2020), Alonzo (2021), Vasil (2022), Chang (2024), Voltaire/CIP-1694 (Mar 2026). Smooth Hard Fork Combinator executions; no outages.
Proof chain strategy (Mithril certificates with PQC signatures for historical integrity) is explicitly hybrid. Nightstream adds lattice ZK alongside classical.
5 Deployment Execution 12 / 100
no mainnet PQC traffic
No PQC in cardano-node. Nightstream (lattice ZK) in development.
SPOs use Ed25519 + KES. No PQC.
Nightstream project + Mithril PQC certificate strategy announced. No dated mainnet activation.
Hoskinson vocal on PQC; Nightstream announced with Linux Foundation/Google/Microsoft Research but no shipped code. Modest overhang.
6 Supply Chain Vendor Readiness 10 / 100
7 Governance & Coordination 60 / 100
3000+ SPOs, Nakamoto coefficient ~25-35 (Edinburgh estimates 50+). Best validator distribution in top 10 L1s.
Voltaire completed March 2026. Consistent hard fork cadence 2020-2026.
Intersect MBO (member-based org, March 2024), IOG (Charles Hoskinson), Cardano Foundation, Emurgo. Post-Voltaire tripartite governance: DReps, Constitutional Committee, SPOs.
Successfully executed L1→Voltaire transition. Hoskinson vocal on PQC tradeoffs. Most advanced on-chain governance among major L1s.
The X + Y vs Z inequality
X (data shelf life): 10-20 (eUTXO model hides unspent keys; spent outputs exposed indefinitely; KES rotation helps block-producer keys)
Y (migration time): 5-10 (Hard Fork Combinator + governance velocity; Hoskinson noted 10x perf penalty without HW accel)
Z10 (10% CRQC year): 2036 · Z50 (50%): 2041
Verdict: X+Y > Z (danger).
Four-scenario grid
| Scenario | Value preserved | Privacy preserved |
|---|---|---|
| quantum never | 100% | 100% |
| arrives suddenly pre migration | 40% | 30% |
| arrives slowly post migration | 90% | 80% |
| arrives slowly mid migration | 65% | 50% |
Peers in the L1 profile
Order-book view of the 9 chains closest to Cardano by QRI.
Public artifacts used for this scorecard
Each entry below is a sub-score citation. Clicking the link takes you to the public source. A third party should be able to reconstruct every number on this page from these URLs in 48 hours.
KES rotation every ~36 hours limits exposure. eUTXO + BLAKE2b-224 hash addresses hide keys until first spend.
Supply chain snapshot
A chain's supply chain cannot migrate faster than its slowest dependency. Zero PQC roadmaps in any of the four categories is a structural blocker, not a lagging indicator.
Analyst notes on the scoring
Hybrid gate PASSES (proof-chain strategy + Nightstream hybrid alongside classical). Sutor cap binds at 2 milestones. 3000+ SPOs = best validator distribution in batch. Band 3 Planning justified by named strategy despite zero shipped code.
Scorecard metadata
- Profile: L1
- Scored: 2026-04-18 by
layerqu-v2-scoring-agent-1 - v1 reference:
chainscreen-v1-archive - QRI raw: 26 · after caps: 26
- Confidence interval: ±7
- PQC washing ratio: 1.3x
- Burn-vs-rescue: undeclared (Hoskinson noted tradeoffs; no formal burn-vs-rescue position). eUTXO unspent UTXOs analogous to Bitcoin dormant.
Caps triggered
- mosca_cap_60
- sutor_stage_cap_2