What it is. Cardano is a public blockchain that has been settling transactions since 2017, is kept running by about 2,700 active stake pools, and changes its own rules through recorded votes held on the chain.
What we found. None of its quantum-safety work has reached the live network, and the practical effect for a holder is that any address already spent from stays exposed to a future quantum attacker until the coins are moved to a fresh one.
Why it matters. The research Cardano is paying for is due to end this year in analysis and recommendations rather than protection on the live chain, and nobody has yet decided what happens to coins whose owners never move them.
Cardano mainnet signs transactions with Ed25519 (RFC 8032), signs blocks with KES Sum6KES over Ed25519, elects slot leaders with the Praos ECVRF-Ed25519-SHA512-Elligator2 and aggregates Mithril certificates with BLS12-381, while cardano-node and cardano-base carry no post-quantum implementation, so nothing post-quantum runs on mainnet or on any Cardano testnet. The post-quantum track sits at problem-statement stage: CPS-0027 (Plutus scope, merged 2026-05-12) and CPS-0030 (consensus scope, merged 2026-08-19) each list candidates and each carry an empty proposed-solutions list, so no scheme is selected, Gate 1a-Sig FAILS, and the mainnet-traffic cap sets a QRI ceiling of 60 that the raw score of 32 never reaches.
Summary
QRI 32, Band 4 Architected, Migration Stage 1. Mainnet primitives: Ed25519 (RFC 8032, libsodium) for transaction witnesses and every ledger key role; KES Sum6KES (MMM binary-sum construction, 64 periods, Ed25519 leaves, BLAKE2b-256 tree hashes) for block-producer signing; Praos ECVRF-Ed25519-SHA512-Elligator2 (IETF draft-irtf-cfrg-vrf-03) for leader election; BLAKE2b-256 transaction and block hashes and BLAKE2b-224 address hashes (CIP-19); BLS12-381 in Plutus (CIP-0381) and in Mithril threshold multi-signatures; ECDSA secp256k1 and Schnorr secp256k1 as Plutus verification built-ins (CIP-0049). Every public-key primitive is Shor-broken by discrete log or pairings; BLAKE2b-224 sits at a 112-bit Grover preimage floor, which we record as a margin note rather than a NIST compliance finding. Zero post-quantum primitives on mainnet, zero post-quantum code in the consensus client, zero stake pools on post-quantum keys. Funding and process moved this period: the Cardano Vision 2026 treasury action (32.916M ADA, post-quantum security a named theme) was enacted 2026-06-13 with 74.9% of counted DRep voting power and a 7-0 Constitutional Committee vote, and the van Rossem hard fork of 2026-07-18 added classical built-ins only. Gate 1a-KEM is N/A: node-to-node transport is plaintext TCP, so there is no KEM to hybridize. Architecture-Execution Gap 67 (Dim 4 74, Dim 5 7).
Forge. Forge-dominant: this chain secures value and operations with signatures, so the principal quantum risk is forgery of spends and attestations once Shor breaks the curve. There is no harvest-now component for forgery, the public key alone enables it. Decrypt/HNDL applies only to third-party API and custody transport confidentiality; the protocol's own transport is plaintext.
8 announced → 0 shipped on mainnet under a named primitive. >1.5 deduction (shipped = 0, so the ratio is computed against a floor of one shipped item; eight announced or in-process items in the trailing 12 months against zero shipped primitives).
What the gates say
- Gate 1a, Hybrid signature: FAIL , no documented hybrid signature composition AND/OR with commit-to-hash; mainnet transaction signing is Ed25519-only, block signing is KES over Ed25519
- Gate 1a, Hybrid KEM: COND , no KEM in the core stack: node-to-node traffic runs over unencrypted TCP through the Ouroboros multiplexer and node-to-client over local sockets, so there is no transport KEM to hybridize; third-party API endpoints terminate classical TLS outside the protocol; no hybrid KEM is documented anywhere
- Gate 1b, Commit-to-hash: COND , no OR-composition exists
- Gate 2, Evidence reconstruction: PASS , every sub-score has ≥3 named artifacts
- Gate 3, Primitive naming: PASS , every sub-score names primitives with mechanism
Burn-vs-rescue policy on file
Declared option f, Undeclared. Cardano's own burn-vs-rescue option for unmoved / lost ADA at quantum-vulnerable addresses has not been formally declared. No governance action, CIP, CPS or foundation document found states a position on freezing, rescuing or leaving vulnerable balances. Architecturally, the Hard Fork Combinator plus CIP-1694 tripartite governance enables any of (a-f), but no on-chain action has been taken.
Seven dimensions
Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.
1 Cryptographic Exposure weight 15% 50 / 100
Every active primitive is named with mechanism in the ledger and crypto-library source (StandardCrypto: KES = Sum6KES Ed25519DSIGN Blake2b_256, VRF = PraosVRF, DSIGN = Ed25519DSIGN, HASH = Blake2b_256, ADDRHASH = Blake2b_224). CIP-0381 added Plutus pairing operations over BLS12-381 with Plutus V3 at the Chang hard fork (2024-09-01); the van Rossem hard fork (2026-07-18, protocol version 11) added expModInteger and BLS12-381 multi-scalar-multiplication built-ins, all classical. Mithril uses BLS12-381 stake-based threshold multi-signatures. The chain's own settlement-layer threat model (CPS-0030 draft) names Ed25519 signatures, the Praos VRF, KES and BLS aggregate signatures as the consensus-critical at-risk primitives, and the merged CPS-0027 names the Plutus script-level signature built-in set (Ed25519, ECDSA secp256k1, Schnorr secp256k1) as the script-level exposure.
Ed25519 (EdDSA over Edwards25519, SHA-512, RFC 8032; libsodium implementation in cardano-base), transaction witnesses and all ledger key roles · KES Sum6KES (MMM binary-sum forward-secure construction, 2^6 = 64 periods, Ed25519 at the leaves, BLAKE2b-256 tree hashes), block-producer signing · Praos VRF (ECVRF-Ed25519-SHA512-Elligator2 per IETF draft-irtf-cfrg-vrf-03, IOG libsodium fork; draft-13 batch-compatible variant also implemented), slot leadership · BLAKE2b-256 (ledger HASH type: transaction IDs, block hashes) · BLAKE2b-224 (ledger ADDRHASH type: Shelley payment/stake key hashes and script hashes per CIP-19) · BLS12-381 (CIP-0381 Plutus pairing built-ins since the Chang hard fork, multi-scalar-multiplication built-ins since van Rossem; Mithril stake-based threshold multi-signatures via blst) · ECDSA secp256k1 (Plutus built-in VerifyEcdsaSecp256k1Signature per CIP-0049; script-level verification only, not consensus) · Schnorr secp256k1 (Plutus built-in VerifySchnorrSecp256k1Signature per CIP-0049; script-level verification only, not consensus) PQ-safe primitives: zero on mainnet today.
Ed25519 (transaction witnesses)→ Shor-break-via-DL-without-pairingsKES Sum6KES / Ed25519 at the leaves (block-producer)→ Shor-break-via-DL-without-pairings (forward-secure evolution bounds the forge window to the operational-certificate lifetime, 62 periods x 36 h, about 93 days)Praos VRF (Edwards25519 curve)→ Shor-break-via-DL-without-pairingsBLS12-381 (CIP-0381 Plutus, Mithril aggregation)→ Shor-break-via-pairingsECDSA secp256k1 (Plutus built-in)→ Shor-break-via-DL-without-pairings (script-level verification only)Schnorr secp256k1 (Plutus built-in)→ Shor-break-via-DL-without-pairings (script-level verification only)BLAKE2b-256→ Grover-weaken (256 -> 128-bit preimage)BLAKE2b-224→ Grover-weaken (224 -> 112-bit preimage; margin note, see 1d)SHA-512 (inside Ed25519)→ Grover-weaken (512 -> 256-bit preimage)
0 PQ families on mainnet. All consensus, signing, and Mithril aggregation primitives are classical elliptic-curve or pairing-based. KES is forward-secure but built on Ed25519. Hash family (BLAKE2b) present but Grover-weakened.
Classical primitives only. Ed25519 is about 128-bit classical security and is Shor-broken; BLAKE2b-224 has 224-bit classical preimage and 112-bit collision resistance, with Grover halving preimage strength to about 112 bits (a margin note; NIST IR 8547 does not deprecate 224-bit hashes on quantum grounds). No FIPS 203/204/205 primitive is deployed, and FN-DSA / Falcon (selected by NIST in 2022; no FIPS 206 draft or final text published as of this evaluation) is not deployed either.
Ed25519 via libsodium through cardano-base (cardano-crypto-class FFI). KES Sum6KES is implemented in Haskell in cardano-base (Cardano.Crypto.KES.Sum, the recursive binary-sum composition from the MMM paper, ePrint 2001/034, over Ed25519 with BLAKE2b-256 node hashes); a Rust port exists for tooling. Sum6 gives 2^6 = 64 evolution periods; mainnet genesis sets slotsPerKESPeriod = 129,600 slots (36 h) and maxKESEvolutions = 62, so an operational certificate lives about 93 days. The Praos VRF is the IETF draft-03 ECVRF in IOG's libsodium fork. Ouroboros Praos and Genesis are peer-reviewed (ePrint 2017/573 and 2018/378). KES is stateful by design; key evolution is mandated at the protocol level via operational certificates.
2 Quantum Recovery Exposure weight 10% 46 / 100
Shelley addresses carry payment credentials that are BLAKE2b-224 hashes of Ed25519 verification keys (CIP-19). Pubkeys are not revealed until first spend, similar to Bitcoin P2PKH but with the hash truncated to 224 bits. Once spent, the Ed25519 pubkey is exposed on-chain in the witness; subsequent funds at the same address are quantum-vulnerable. The eUTXO model permits address rotation but does not enforce it. KES rotation does not protect payment keys, only block-producer keys. The chain's own settlement-layer problem statement (CPS-0030) records that many public keys are exposed on-chain and some remain in use for long periods.
Mainnet since 2017-09-29 (Byron). Long dormancy tail. Byron-era addresses use the legacy double hash (SHA3-256 then BLAKE2b-224) of the address root, which still hides the pubkey pre-spend; Byron genesis redeem addresses were issued to early investors (CIP-19), and any genesis or Byron balance never spent still hides its key. BLAKE2b-224 truncation gives a 112-bit Grover preimage floor (margin note, see 1d).
Historical Ed25519 signatures in spent transactions are forgeable post-Shor in principle, but the chain's append-only consensus prevents retroactive substitution. Block-producer KES forward-security bounds the window in which a compromised KES key can be used to backdate blocks (one operational certificate, 62 periods x 36 h, about 93 days). Transaction-level Ed25519 signatures are not forward-secure.
No transport encryption exists in the protocol: node-to-node traffic runs over plain TCP through the Ouroboros multiplexer (the network specification describes TCP bearers and no TLS or authenticated-encryption layer), and node-to-client traffic uses local sockets. Block and mempool contents are public by design, so there is no ciphertext at the gossip layer for a harvest-now adversary to store. The HNDL surface is third-party: wallet-to-API HTTPS sessions (Blockfrost, Koios, Maestro, Demeter) and exchange / custodian channels terminate classical TLS (X25519 / ECDHE key exchange) with no hybrid KEM documented. Exposure is bounded to transport metadata and operator-side sessions.
3 Metadata, Anonymity & Confidentiality weight 13% 36 / 100
Pseudonymous on the eUTXO mainnet. Base addresses embed a stake credential next to the payment credential (CIP-19), so payment addresses sharing a stake key are linkable, increasing graph linkability above pure UTXO chains. Midnight, the privacy-focused partner chain, is live on its own federated mainnet (launched March 2026) using a PLONK-based zk-SNARK prover (midnight-proofs) with selective disclosure, but it is a separate chain, not the Cardano L1 ledger.
About 2,900 registered stake pools (2,677 with nonzero active stake, Koios public API, 2026-08-19); operators typically run their own block producer and relays. Mithril signer participation in the latest certificate is 155 pools holding 3.77B ADA, about 17.5% of active stake (Mithril mainnet aggregator API, 2026-08-19). The API layer (Blockfrost, Koios, Maestro, Demeter) is more concentrated. Mempool gossip is plaintext and fully observable.
Cardano has historically had a limited bridge surface (Wanchain, Milkomeda EVM sidechain). A LayerZero integration was announced 2026-06-08 with a phased rollout through 2026 (Cardano Foundation blog). A smaller bridge footprint lowers passive-observer correlation surface.
Ed25519 (Edwards25519) and the Praos VRF are Shor-broken; once a payment key has signed, the pubkey is on-chain. BLAKE2b-224 hashing limits pre-spend exposure. No on-chain encryption of payloads on the Cardano L1 (Midnight is separate).
No on-chain mixer or cryptographic shuffle in cardano-node. No CoinJoin equivalent in eUTXO mainnet.
4 Migration Architecture weight 10% 74 / 100
The Hard Fork Combinator (HFC) is documented in the consensus layer and has carried ten coordinated hard forks since 2020 per the Cardano Foundation hard-fork register: Shelley (2020-07-29), Allegra (2020-12-16), Mary (2021-03-01), Alonzo (2021-09-12), the protocol-version-6 intra-era fork (2021-10-22), Vasil (2022-09-22), Valentine (2023-02-14), Chang (2024-09-01, Conway era and CIP-1694 bootstrap), Plomin (2025-01-29, CIP-1694 full governance) and van Rossem (2026-07-18, intra-era, protocol version 11). Algorithm-level swap (adding ML-DSA alongside Ed25519) has not been demonstrated; the HFC swaps eras, not primitives, and CIP-0381 / van Rossem added pairing and multi-scalar-multiplication primitives at the Plutus VM level rather than at the consensus signing layer.
KES key evolution is native (block-producer keys evolve every KES period, 36 h, under an operational certificate). No native account abstraction equivalent to ERC-4337 / EIP-7702. eUTXO scripts (Plutus V1/V2/V3) provide programmable spending logic at script addresses, which gives some AA-flavored flexibility, but is not a documented client-layer PQC migration path. A draft improvement proposal (opened 2026-08-07, unmerged, no number formally assigned) proposes an additive post-quantum layer over unchanged CIP-1852 / BIP32-Ed25519 keys: a STARK-based zero-knowledge proof of seed-witness knowledge (RISC Zero zkVM, SHA-256 / HMAC-SHA512 relations), verified off-chain in its first phase with no ledger change (reference figures from the draft: proof about 219 KB, verification 9-10 ms, signing about 12.5 s, one-time derivation certificate about 156 s). The STARK proof system is hash-based, so the hard gate on Shor-breakable proof systems does not fire; the design earns the minimum paper-stage rebind credit only, because it is unmerged, its first phase is off-chain, and the only freeze of raw Ed25519 acceptance it describes is a conditional post-Q-day rule with no deployment path, so the address stays Shor-forgeable throughout.
Ten coordinated hard forks 2020-2026 with no contested hard fork. One unplanned, temporary chain split occurred on 2025-11-21 (about 14 hours of degraded service) when an intentionally malformed transaction triggered a serialization bug in node versions 10.3.1 to 10.5.1; the split resolved under the longest-chain rule after operators upgraded, without central intervention (IOG's own analysis). Voltaire / CIP-1694 enacted on schedule under three-stakeholder coordination (DReps, Constitutional Committee, SPOs). The updated Constitution (v2.4) was ratified with 79.9% of counted DRep voting power (enacted epoch 609, January 2026); the original Constitution passed with 84.9% (February 2025).
The publicly-stated migration architecture is hybrid by design: a post-quantum proof chain (extension of Mithril) is intended to checkpoint the classical L1 with PQ signatures, with full chain merge planned long-term. Architecturally possible. The improvement-proposal track is active at problem-statement stage: CPS-0027 (Approaches to Post-Quantum Signatures, Plutus-builtin scope) merged 2026-05-12, naming ML-DSA per FIPS 204 and SLH-DSA per FIPS 205 as the NIST-finalized candidates, Falcon as still under review for a possible FIPS 206, and SQIsign as unstandardized; CPS-0030 (quantum-secure settlement layer, consensus scope, authored by four IOG researchers) was merged into cardano-foundation/CIPs on 2026-08-19 (pull request 1175) and is live on master; its front-matter Status field reads Open, which is the CPS lifecycle state for an unsolved problem, not a pull-request state. It surveys ML-DSA, FN-DSA, SLH-DSA, SQIsign, FAEST and MAYO, with no scheme selected and the KES / VRF replacement question explicitly open. Both documents carry empty proposed-solutions lists; no hybrid composition spec exists and no code has been merged.
Cardano's only stateful signing primitive is KES Sum6KES, used at the block-producer layer. State management is enforced at the protocol level via operational certificates with bounded KES periods (mainnet: 62 evolutions of 36 h, about 93 days). The 15/15 is awarded for KES discipline, not for PQ stateful-hash deployment.
N/A. Ouroboros Praos uses non-aggregating Ed25519-based KES at the block-producer layer; chains using non-aggregating signatures at consensus are out-of-scope for 4f and the weight redistributes to the other five sub-scores. Mithril uses BLS12-381 threshold-aggregate signatures, but Mithril is a checkpoint / certificate layer, not the Cardano consensus signing layer. Not scored, so it is left out of the dimension total rather than counted as a zero.
5 Deployment Execution weight 22% 7 / 100
0%. No PQ primitive signs Cardano L1 transactions, blocks, or VRF outputs.
cardano-node and cardano-base contain no PQ signature implementation; a full-text code search of the consensus client and of cardano-base for quantum-related code returns zero matches, and the latest tagged release (11.0.1, 2026-05-05) carries no PQ content. The KES code implements the MMM forward-secure construction over Ed25519, not PQ. The Mithril repository contains BLS12-381 (Shor-broken via pairings) for stake aggregation, not PQ. Nightstream, the lattice-based proving project announced February 2026, is an active research repository under the Linux Foundation Decentralized Trust umbrella (a lattice folding scheme for CCS, SuperNeo building on Neo, ePrint 2025/294, with Ajtai / module-SIS commitments and a Poseidon2 transcript, a proving-system component, not a signature or VRF replacement); its own README states chain-facing deployment wiring and independent audit are unfinished and it is not production-ready, and no consensus-client integration exists.
Zero SPOs use PQ keys. KES + Ed25519 only.
VOIDED to 0 while 5a = 0 per v3.1. The funded CV26 program has a dated milestone cadence (four funding tranches of 25%: services agreement, mid-year interim report, Q3 R&D session and report, year-end final report; the 2026-07-16 mid-year report is the second, with 42 committed deliverables across seven work packages, Work Package 1.2 covering post-quantum VRFs and quantum-secure Ouroboros analysis, integration specifications and benchmarks, and completing the post-quantum security analyses listed as an H2 2026 priority), and the founder-stated 3-phase roadmap (research agenda 2025-2026; 2-3 years proof chain; 3+ years merge) names phases. None of this is protocol-enforced: no hard-fork activation epoch, no flag day, no sunset date for Ed25519 / Praos VRF, and no PQ deliverable scoped into the next era (Dijkstra: the Intersect Technical Steering Committee minutes of 2026-07-29 and 2026-08-12 list Leios, CIP-23 part 1 and CIP-50 in scope with a December 2026 target, and a post-quantum action plan only as an open action item).
Announced or in-process PQ items in the trailing 12 months: Project Nightstream (February 2026 announcement, active lattice-folding research repo), the Mithril proof-chain framing restated as the PQ checkpoint mechanism (February 2026), founder statements aligning to NIST FIPS 203/204/205 (November and December 2025; the November statement also named a FIPS 206, which NIST has not published), the enacted CV26 treasury action naming post-quantum security in its title (June 2026), the 2026-07-16 mid-year report recording post-quantum VRF design progress, Intersect's 2030 strategic framework naming post-quantum readiness (drafted July 2025, updated through October 2025), the improvement-proposal track (two merged problem statements, CPS-0027 and CPS-0030, each with an empty proposed-solutions list), and the Intersect Technical Steering Committee's receipt of an IO cryptography-team post-quantum readiness report (2026-07-22) with an action item to draft a PQC action plan (2026-08-12). Shipped PQ on mainnet: 0. The announced-to-shipped gap widened this period: more funded and in-process items against zero shipped code, which is why the ratio rises even as the process matures. Disclosure quality remains disciplined: the merged problem statement lists no proposed solution, the research repo labels itself not production-ready, and the founder's own roughly 10x performance-penalty estimate was published before any code shipped; the narrative-only tag is not applied because every counted item self-labels as research or process rather than claiming deployed protection.
Undisclosed at chain-spec level. No published Cardano-specific bytes-per-block-under-PQ analysis.
6 Supply Chain Vendor Readiness weight 22% 9 / 100
Widely used wallets: Lace (IOG), Eternl, Yoroi (EMURGO); Daedalus is the IOG desktop full-node wallet. PQ roadmap: none of these publishes a PQC roadmap; a search of the Lace repository for quantum-related issues or pull requests returns zero. Ledger and Trezor devices are used as Cardano hardware wallets and have no shipped PQ Cardano firmware.
Relevant bridges: Wanchain, Milkomeda (EVM sidechain), LayerZero (integration announced 2026-06-08, phased rollout through 2026). None publishes a PQ roadmap covering Cardano bridge endpoints.
Cardano-supporting custodians found include BitGo (sdk-coin-ada module in the BitGoJS SDK) and Kraken Institutional (custody asset list). Neither publishes a Cardano-specific PQ migration path, and no custodian-level PQC roadmap naming ADA was found.
API providers: Blockfrost, Koios, Maestro, Demeter; none publishes PQ TLS or hybrid KEM termination. HSM: no PQ HSM integration is documented for Cardano stake-pool cold keys. TEE: not part of Cardano consensus.
7 Governance & Coordination weight 8% 59 / 100
About 2,900 registered stake pools, 2,677 with nonzero active stake (Koios public API, 2026-08-19). The smallest set of individual pools controlling more than one third of active stake is 98, and more than one half is 160 (same data; operator-grouped figures are lower and depend on grouping heuristics, so we publish the per-pool computation only). Client diversity is limited: cardano-node (Haskell) is the reference implementation, Intersect's 2030 framework lists multi-client infrastructure and client diversity as goals still to deliver, and the Rust alternative Amaru self-describes as exploratory. Single-client risk balances strong stake distribution.
Ten coordinated hard forks 2020-2026 with no contested hard fork; CIP-1694 / Voltaire transition completed on schedule (Chang 2024-09-01, Plomin 2025-01-29); the updated Constitution ratified by 79.9% of counted DRep voting power (January 2026). One unplanned, temporary chain split (2025-11-21, about 14 hours) exposed version heterogeneity among operators before the patched release propagated; it resolved under protocol rules.
Intersect MBO (member-based organization; GitHub organization created 2023-06-30), IOG (Charles Hoskinson), Cardano Foundation, EMURGO. Voltaire-era tripartite governance: DReps + Constitutional Committee (7 seated members, staggered terms) + SPOs. The PQ mandate is now institutional rather than personality-fronted: the CV26 treasury action funding the IO Research program (32.916M ADA, post-quantum security a named theme) was enacted by on-chain vote 2026-06-13 with 42 committed deliverables, four funding tranches and a mid-year report already published; Intersect's published 2030 strategic framework names post-quantum readiness as a focus area under Pillar 1 (Infrastructure and Research Excellence), section I.2 Security and Resilience; and the Intersect Technical Steering Committee received an IO cryptography-team post-quantum readiness report on 2026-07-22 and opened a PQC action-plan item on 2026-08-12.
Voltaire transition is a precedent for coordinated change at scale. A second precedent: the CV26 funding vote ran contested (mid-vote press tracking reported a heavy No majority) and concluded Enacted on 2026-06-13 with 74.9% of counted DRep voting power and a 7-0 Constitutional Committee vote, showing the governance system resolving a disputed, security-relevant funding decision on schedule. A third, live adversarial precedent: on 2025-11-21 an intentionally malformed transaction exploited a node serialization bug and split the chain for about 14 hours; operators upgraded and the longest-chain rule converged the network without central intervention. No precedent yet of coordinating a cryptographic migration under an active attacker.
No documented canary, honeypot, rate-limited spending rule, or cryptographic tripwire embedded in Cardano consensus.
Source-disagreement disclosure
v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.
Cardano's proof-chain via Mithril uses BLS12-381 today (Shor-broken via pairings); the framework sees BLS as a substrate to be later upgraded with PQ co-signing. An alternative reading is that any chain whose checkpoint substrate is Shor-vulnerable should be scored as having no checkpoint protection at all.
A third-party governance tracker shows a total No stake of 1.37B ADA for the CV26 treasury action while its explicit-No (288.5M ADA) and no-confidence (198.78M ADA) lines sum to 487M. Re-verified against the Koios public API: the 1.37B figure includes 885M ADA of non-voting DRep stake, which CIP-1694 counts as No for treasury withdrawals; counted DRep voting power was 74.9% Yes / 25.1% No, Constitutional Committee 7-0, ratified epoch 636, enacted epoch 637. Mid-vote press tracking reported a heavy No majority that the final result reversed. The arithmetic conflict is resolved; the mid-vote figures remain single-outlet press numbers.
Secondary news coverage describes Nightstream as co-developed with Google and Microsoft Research; the project's own repository and documentation name neither company, nor Cardano. This evaluation credits Nightstream only for what the primary repository evidences: an active lattice-based proving-system research project under the Linux Foundation Decentralized Trust umbrella, self-labeled not production-ready, with a lead contributor employed at a Cardano-ecosystem tooling vendor.
Some sources describe node-to-node gossip as TLS-protected. The network specification and design documents describe the multiplexer running over plain TCP bearers and treat TLS as outside the protocol; the node-to-client path uses local sockets. We therefore score the gossip layer as plaintext (no quantum-decrypt exposure because there is no ciphertext) and confine the HNDL surface to third-party API and custody channels. Sub-score 2d is held at 14/25 on that reading; a reading that penalizes the absence of any transport confidentiality would lower it, but that is a classical, not quantum, finding.
It is sometimes stated that no chain split had ever occurred. IOG's own analysis describes a temporary chain split on 2025-11-21 (about 14 hours of degraded service) caused by a serialization bug in node versions 10.3.1 to 10.5.1 triggered by an intentionally malformed transaction, resolved by the longest-chain rule after operators upgraded, without central intervention. We read it as one unplanned split resolved by protocol rules, lowering 4c and 7b by one point each and crediting 7d with a live adversarial-coordination precedent; a stricter reading would lower 7b further.
Delta-QRI under alternative weighting
Under the alternative reading on Mithril substrate, 4d would drop from 10 to 5, lowering the Dim 4 normalized score from 74 to about 68 and raw QRI from 32 to about 31. +/-1 around the central 32.
Announcement-to-shipped ratio
Announced: 8. Shipped: 0. Ratio: 8.
Tag: >1.5 deduction (shipped = 0, so the ratio is computed against a floor of one shipped item; eight announced or in-process items in the trailing 12 months against zero shipped primitives)
Peers in the L1 profile
9 chains closest to Cardano by Stage then QRI.