What it is. Internet Computer is a public blockchain that runs whole applications directly on its own hardware, 618 machines working in 42 groups.
What we found. The foundation has published post-quantum research goals but no migration plan and no dates. A community request for one, posted in August 2026, had no reply from a foundation account in the forum sources searched. The only post from the founder's account on the subject in that period shared an argument against moving quickly.
Why it matters. Nothing on the live network would hold up against a future quantum computer, and the wrapped Bitcoin, Ether and dollar tokens held there are guarded by the network's own keys rather than by keys their owners hold.
ICP mainnet runs no post-quantum primitive and dfinity/ic carries no post-quantum implementation: subnet consensus, certified state, cross-subnet messaging, the random beacon, canister signatures and the production vetKD key all rest on BLS12-381 under the interface specification's ciphersuite BLS_SIG_BLS12381G1_XMD:SHA-256_SSWU_RO_NUL_, chain-key custody of ckBTC, ckETH, ckERC20, ckSOL and ckDOGE rests on threshold ECDSA secp256k1 and threshold Schnorr over BIP-340 secp256k1 and Ed25519, and NIDKG resharing hands a subnet's key to new node sets without changing its public key, so one recovered subnet key forges every signature that subnet has ever issued. Mainnet post-quantum signature traffic is 0%, Gate 1a-Sig and Gate 1a-KEM both FAIL, and the mainnet-traffic cap sets a QRI ceiling of 60 that the raw score of 25 never reaches.
Summary
Plain ingress signatures use Ed25519, ECDSA secp256k1 and ECDSA secp256r1; web-authentication delegations use ECDSA P-256 with SHA-256 and RSASSA-PKCS1-v1_5 with SHA-256, the only two the specification allows. Self-authenticating principals are SHA-224 hashes of DER-encoded public keys with a 0x02 suffix, so a public key becomes visible when its owner signs. A dfinity/ic code search on 2026-08-19 returns zero hits for ML-DSA, ML-KEM, SLH-DSA, Falcon, Kyber, Dilithium, SPHINCS+ and XMSS, mainnet and testnet alike; the only first-party post-quantum reference is a crypto-agility comment in the ic-hpke crate, whose own construction is ECDH P-384 with HKDF-SHA-384 and AES-GCM-256. Hybrid X25519MLKEM768 (ML-KEM-768 per FIPS 203) reaches the replica only as an undeclared rustls aws-lc-rs default, ranked last and never negotiated, and the public gateways reject it with alert 40, measured 2026-08-19. vetKD runs in production on BLS12-381 G2, so every key it transports is harvest-now-decrypt-later exposed. NNS Motion 35660, executed 2021-12-21, is the only governance-adopted post-quantum item and selects no scheme, so no parameter set or signature size can be evaluated; 5d voids to 0. No replica holds a post-quantum key: subnet threshold keys are BLS12-381, secp256k1 and Ed25519, and node identity certificates are Ed25519. QRI 25, Band 3 Planning, Migration Stage 1.
Forge. Forge-dominant: this chain secures value and operations with signatures, so the principal quantum risk is forgery of spends and attestations once Shor breaks the curve. There is no harvest-now component for forgery, because the published public key alone enables it. The decrypt component applies to replica and gateway transport confidentiality and to vetKD-transported keys.
0 announced → 0 shipped on mainnet under a named primitive. none (no foundation-authored PQC claims in the trailing 12 months. The only founder-level public statement on the topic, 2026-08-15, argues against a near-term post-quantum transition, which is the inverse of PQC-washing. Third-party ecosystem posts are not foundation claims).
What the gates say
- Gate 1a, Hybrid signature: FAIL , no hybrid signature composition at subnet consensus, threshold signing, canister signing or Internet Identity. Every signature primitive in the stack is classical: BLS12-381, ECDSA secp256k1, ECDSA secp256r1, BIP-340 secp256k1, Ed25519, RSASSA-PKCS1-v1_5
- Gate 1a, Hybrid KEM: FAIL , vetKD encrypted-key delivery is BLS12-381 G2 identity-based encryption with no hybrid KEM. Replica peer-to-peer traffic runs over QUIC, whose handshake takes the same rustls TLS 1.3 configuration the replica builds for direct TLS: it starts from the rustls aws-lc-rs provider default and overrides only the cipher suites, so the key-exchange group list stays at the provider default of X25519, secp256r1, secp384r1 and hybrid X25519MLKEM768 in that order. The hybrid group ranks last because the prefer-post-quantum build feature is not enabled anywhere in the workspace or its third-party rustls dependency declarations, so both peers rank X25519 first and the negotiated group is classical. The setting is a dependency default rather than a declared design, and no ICP document names it. The public HTTPS gateways ic0.app, icp-api.io and internetcomputer.org reject a forced X25519MLKEM768 handshake with alert 40, measured 2026-08-19
- Gate 1b, Commit-to-hash: COND , no OR-composition deployed
- Gate 2, Evidence reconstruction: PASS , with one exception, re-established under a second adversarial pass on 2026-08-19: every sub-score is backed by three or more artifacts we retrieved and that a third party can retrieve again, including the interface specification text, the live registry and governance API, the replica and rustls source at pinned versions, the crates.io dependency records, and live TLS handshake measurement. The one exception is the December 2024 crypto-agility statement by DFINITY's cryptography lead, whose forum location returns an access-denied response on re-check at 2026-08-19 and which now survives only as a second-hand summary inside a later community thread. Sub-scores that leaned on it were lowered.
- Gate 3, Primitive naming: PASS , BLS12-381 G1/G2 with ciphersuite BLS_SIG_BLS12381G1_XMD:SHA-256_SSWU_RO_NUL_, secp256k1, secp256r1, secp384r1, BIP-340, Ed25519, ES256/P-256, RSASSA-PKCS1-v1_5, SHA-256, SHA-224, SHA-384, AES-256-GCM, AES-128-GCM, X25519, X25519MLKEM768, ML-KEM-768, ECDH P-384, HKDF-SHA-384 named with mechanism
Burn-vs-rescue policy on file
Declared option f, Undeclared. No public DFINITY position on classical-vulnerable user accounts, on chain-key custody of ckBTC, ckETH, ckERC20, ckSOL and ckDOGE reserves under a post-Shor BLS12-381 or secp256k1 break, or on historical vetKD-encrypted state. The NNS could in principle execute any of options (a) to (e) but no policy has been published.
Seven dimensions
Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.
1 Cryptographic Exposure weight 15% 36 / 100
Foundation documentation names every primitive with its mechanism, down to ciphersuite strings, object identifiers and encoding rules, and the interface specification is exhaustive about which schemes are and are not accepted at each surface. Subnet consensus, response certification, the random beacon, threshold canister signing, vetKD encrypted-key delivery, replica transport and user authentication are all inventoried and reproducible from public specs, source and live measurement. The one gap is that no ICP document names the hybrid X25519MLKEM768 group that its own transport configuration inherits.
BLS12-381 threshold signatures via non-interactive DKG and resharing (subnet consensus, response certification, cross-subnet message authentication, random beacon, NNS root key); the interface specification names the verification ciphersuite BLS_SIG_BLS12381G1_XMD:SHA-256_SSWU_RO_NUL_, so signatures are G1 elements and public keys G2 elements; construction published as IACR ePrint 2021/339, 'Non-interactive distributed key generation and key resharing', Jens Groth · Threshold ECDSA secp256k1, production key id key_1 on the fiduciary subnet pzp6e with backup on subnet uzr34, test key id test_key_1 on a 13-node subnet; used for Bitcoin legacy and SegWit, Ethereum, EVM chains and Filecoin; public-key derivation is a generalization of BIP32 per IACR ePrint 2021/1330 Appendix D; signatures are the SEC1 r and s values concatenated · Threshold Schnorr BIP-340 over secp256k1, production key id key_1, generated under NNS proposal 131474 executed 2024-08-05; used for Bitcoin Taproot and Ordinals; 64-byte BIP-340 encoding, with an optional BIP-341 Merkle-root auxiliary parameter for Taproot · Threshold Schnorr Ed25519, production key id key_1, generated under the same proposal; used for Solana, TON, Polkadot, Cardano and NEAR; 64-byte RFC 8032 encoding under a custom hierarchical derivation defined in the interface specification · Plain ingress signatures per the interface spec: Ed25519 (DER per RFC 8410), ECDSA secp256k1 with SHA-256 (DER per RFC 5480, OID 1.3.132.0.10, uncompressed points), ECDSA secp256r1 (P-256) with SHA-256; signatures are the 32-byte big-endian r and s concatenated, 64 bytes · Web-authentication delegation per the interface spec: ECDSA P-256 (secp256r1) with SHA-256, and RSASSA-PKCS1-v1_5 with SHA-256. Those are the only two schemes the specification allows for web authentication. Public keys are DER-wrapped COSE keys under OID 1.3.6.1.4.1.56387.1.1 and the signature is a CBOR structure carrying authenticator data, client data JSON and the signature · Canister signatures: CBOR structures carrying a certificate and hash tree, with DER-wrapped public keys under OID 1.3.6.1.4.1.56387.1.2, verified against the subnet's DER-encoded BLS12-381 public key published at /subnet/<subnet_id>/public_key · vetKD threshold key derivation and identity-based encryption over BLS12-381 G2, the only supported curve, production key id Bls12_381_G2:key_1; per the interface spec the derived public key is a compressed G2 element, the caller's transport public key is a compressed G1 element, and the returned encrypted key is a G1, G2, G1 triple evaluated through the pairing · Replica peer-to-peer transport: QUIC via quinn, whose handshake consumes the replica's own rustls configuration: TLS 1.3 only, cipher suites TLS_AES_256_GCM_SHA384 and TLS_AES_128_GCM_SHA256, node certificates authenticated with Ed25519; key-exchange groups left at the rustls aws-lc-rs provider default of X25519, secp256r1, secp384r1 and hybrid X25519MLKEM768 in that preference order · Public HTTPS gateway transport, measured 2026-08-19: TLS 1.3, TLS_AES_256_GCM_SHA384, X25519 key exchange, ECDSA secp384r1 with SHA-384 server certificate on ic0.app and icp-api.io, ECDSA secp256r1 with SHA-256 on internetcomputer.org · ic-hpke utility crate (first-party, outside the consensus path): HPKE per RFC 9180 with ECDH P-384, HKDF-SHA-384 and AES-GCM-256 · SHA-256 and SHA-224: self-authenticating principals are H(public_key) followed by the byte 0x02, 29 bytes total, where H is SHA-224 over the DER-encoded public key BLS12-381 (subnet consensus and certification, random beacon, NNS root key, vetKD, canister signatures, NIDKG)→ Shor-break-via-pairingssecp256k1 ECDSA (threshold ECDSA, ckBTC, ckETH, ckERC20)→ Shor-break-via-DL-without-pairingssecp256k1 BIP-340 Schnorr (threshold Schnorr, Bitcoin Taproot)→ Shor-break-via-DL-without-pairingsEd25519 (threshold Schnorr, plain ingress signatures, replica node certificates, Internet Identity session keys per the specification's examples)→ Shor-break-via-DL-without-pairingsECDSA secp256r1 (plain ingress signatures, WebAuthn ES256)→ Shor-break-via-DL-without-pairingsECDSA secp384r1 (public HTTPS gateway server certificate)→ Shor-break-via-DL-without-pairingsRSASSA-PKCS1-v1_5 (web-authentication delegation)→ Shor-break-via-integer-factorizationX25519 (negotiated key exchange, replica transport and public gateway)→ Shor-break-via-DL-without-pairingsECDH P-384 with HKDF-SHA-384 (ic-hpke crate)→ Shor-break-via-DL-without-pairingsX25519MLKEM768 (present in the replica transport default group list at lowest preference, not negotiated)→ hybrid: the X25519 half is Shor-broken, the ML-KEM-768 half is a FIPS 203 lattice KEM with no known quantum polynomial-time attackSHA-256, SHA-384→ Grover-weaken: preimage security 256 to 128 bits and 384 to 192 bitsSHA-224 (principal derivation)→ Grover-weaken: preimage security 224 to 112 bits; classical collision resistance is already 112 bitsAES-256-GCM, AES-128-GCM→ Grover-weaken: 256 to 128 bits and 128 to 64 bits of key search
Zero post-quantum families are in use on mainnet. Every consensus, threshold-signing, canister-signing, key-derivation and authentication primitive is classical elliptic-curve, pairing-based or RSA. One lattice KEM family (ML-KEM-768 per FIPS 203) is compiled into the replica through the rustls aws-lc-rs dependency and sits in the transport default group list at lowest preference, but it is not the negotiated group and no ICP document declares it, so it does not count as a deployed family.
The classical primitives map to legacy NIST strengths of roughly 128 bits pre-quantum, with SHA-224 principal derivation at 112 bits classically. No post-quantum security category is claimed or in use. FIPS 203 ML-KEM code is present in the replica through a dependency but is not the negotiated group. No FIPS 204 (ML-DSA) or FIPS 205 (SLH-DSA) primitive is deployed. FIPS 203, 204 and 205 were published 2024-08-13; FIPS 206 (FN-DSA, Falcon) is still in development and is not a finalized standard as of 2026-08-19, so no ICP primitive could target it.
The replica is implemented in Rust in dfinity/ic by an in-house cryptography group. The non-interactive DKG and resharing construction is published as IACR ePrint 2021/339; the threshold ECDSA protocol design and security analysis are published as IACR ePrint 2022/506 and 2021/1330, and the interface specification itself cites 2021/1330 for the BIP32 generalization used in key derivation. The elliptic-curve and pairing arithmetic comes from maintained third-party and first-party crates pinned in the lockfile: k256 0.13.4, ed25519-dalek 2.2.0, curve25519-dalek 4.1.3, p256 0.13.2, ic_bls12_381 0.10.1, aws-lc-rs 1.17.3. Constant-time behaviour is not independently verified here; the crates' own claims are the basis. No machine-checked implementation proofs of the threshold protocols are published, and we found no third-party cryptanalysis of the NIDKG construction beyond the design papers themselves. The classical curves in use have decades of public cryptanalysis behind them; the composed threshold constructions do not.
2 Quantum Recovery Exposure weight 10% 25 / 100
Self-authenticating principals are SHA-224 hashes of DER-encoded public keys, so an address alone does not reveal a key, but every signed ingress message reveals the public key, and any principal that has ever transacted is exposed. Internet Identity principals are anchored by canister signatures that verify against the subnet BLS12-381 public key, which is published in the state tree at /subnet/<subnet_id>/public_key, so those identities are exposed by construction. NNS root and subnet public keys, canister signature anchors and threshold public keys are all published. The controlling private keys for ckBTC, ckETH, ckERC20, ckSOL and ckDOGE are held in secret-shared form on chain-key subnets: breaking secp256k1 or Ed25519 recovers the outbound signing capability, and breaking BLS12-381 recovers the certification capability that authorises minter behaviour.
The earliest NNS proposal on the public record is proposal 3, dated 2021-05-06, so more than five years of balances exist, including genesis allocations, early unlock tranches and dormant Internet Identity anchors. Subnet BLS12-381 keys are long-lived and re-shared to new node sets rather than rotated to fresh public keys; the resharing protocol is documented as keeping the subnet public key unchanged while the shares change. The production secp256k1 threshold key key_1 was already addressable in a mainnet ckBTC minter initialisation argument in December 2022 and no rotation to a new public key is on record.
Subnet BLS12-381 threshold signatures sign blocks, certified state, query-response certificates, cross-subnet messages and canister signatures, and those signatures cover the long-term chain-key reserves. They are forgeable once BLS12-381 falls. Threshold ECDSA secp256k1 signatures already broadcast to Bitcoin and Ethereum, and threshold Schnorr signatures already broadcast to Bitcoin Taproot and Solana, are forgeable once the underlying curves fall, and their public keys are permanently on those external chains.
Replica peer-to-peer traffic runs over QUIC, whose handshake uses the replica's rustls configuration: TLS 1.3 only, cipher suites TLS_AES_256_GCM_SHA384 and TLS_AES_128_GCM_SHA256, Ed25519 node certificates. The key-exchange group list is left at the rustls aws-lc-rs default; because the prefer-post-quantum build feature is not enabled anywhere in the workspace or its rustls dependency graph, X25519 ranks first and hybrid X25519MLKEM768 ranks last, so peers negotiate classical X25519 and recorded traffic stays harvest-now-decrypt-later exposed. The public HTTPS gateways ic0.app and icp-api.io terminate TLS 1.3 with X25519 and an ECDSA secp384r1 certificate and reject a forced X25519MLKEM768 handshake with alert 40, measured 2026-08-19. vetKD encrypted-key delivery uses BLS12-381 G2 identity-based encryption, so every key it has transported on mainnet is harvest-now-decrypt-later exposed, and NNS Motion 35660 explicitly names ciphertext harvesting as a reason to start early.
3 Metadata, Anonymity & Confidentiality weight 13% 28 / 100
Pseudonymous. ICRC-1 and ICRC-2 ledger transactions reveal sender and receiver principals on-chain. Internet Identity derives a distinct principal per application origin, which its own documentation describes as preventing cross-application tracking, but per-application on-ledger activity is fully linkable.
The live registry read on 2026-08-19 shows 42 subnets and 618 nodes assigned to them, out of 1,284 registered nodes held by 78 node providers. Subnet sizes are 7 nodes on three subnets, 13 on thirty-five, 34 on three (including the fiduciary chain-key subnet pzp6e) and 40 on the NNS subnet, so replica traffic inside a subnet is observable to between 7 and 40 operators. Per-subnet node-provider Nakamoto coefficients range from 3 to 12 with a median of 5, and per-subnet country Nakamoto coefficients range from 1 to 5. The topology moves: eight subnets were decommissioned by NNS proposals executed 2026-08-17 and the 42 figure already excludes them. API boundary nodes are upgraded through NNS proposals. No validator metadata-retention policy is published.
Chain-key tokens live on mainnet: ckBTC, ckETH, ckERC20 (documented examples ckUSDC, ckUSDT, ckLINK), ckSOL, and ckDOGE, which the documentation marks as in beta. ckBTC was in general community use by April 2023. Minter canisters hold the underlying assets at addresses they control through chain-key threshold signatures, with no private key held anywhere, and outbound EVM traffic runs through Chain Fusion JSON-RPC, so on-chain trails link ICP principals to Bitcoin, Ethereum, Solana and Dogecoin addresses.
Every signing primitive that anchors ICP identity is Shor-vulnerable. Recovering a subnet BLS12-381 key exposes every canister-signature-derived principal that subnet certified, so historical Internet Identity authentications can be re-attributed. vetKD-encrypted payloads are decryptable once BLS12-381 falls.
No on-chain mixer, cryptographic shuffle or mix network exists in the replica. vetKD provides application-layer encryption, not traffic-graph privacy.
4 Migration Architecture weight 10% 56 / 100
NNS-governed proposals replace replica binaries subnet by subnet, and the mechanism runs continuously: of the 100 most recent NNS proposals, read 2026-08-19 and covering 2026-08-13 to 2026-08-19, 79 are version-deployment items (32 subnet replica-version updates, 24 HostOS version settings, 19 API boundary node version updates and 4 version elections), and the remainder includes eight executed subnet decommissionings, Internet Identity and registry canister upgrades, a node-provider removal and a ckERC20 token addition. Thirty-seven of the 42 subnets carry more than 100 historical replica-version entries, with a median of 241. The cryptographic stack is modular at Rust crate boundaries. Shipped cryptographic additions: production BIP-340 secp256k1 and Ed25519 threshold keys generated under NNS proposal 131474 executed 2024-08-05; vetKD test key Bls12_381_G2:test_key_1 under NNS proposal 136589 executed 2025-05-13, followed by the staged production key Bls12_381_G2:key_1 on the fiduciary subnet from 2025-06-20 with backup and public enablement by 2025-06-27; and chain-key signing throughput parameters raised in February 2026 (NNS proposal 140289 executed 2026-02-12 raised the advance pre-signature count from 5 to 100 on subnet pzp6e, with expected throughput of 3.5 signatures per second for threshold ECDSA, 6.5 for threshold Schnorr and 18 for vetKeys announced on 2026-02-25). Two shipped agility hooks reference or enable a future post-quantum transition without using one: the ic-hpke crate embeds explicit protocol and version identifiers so the scheme can be rotated later, though its own KEM is ECDH P-384 and a repository-wide search finds no consumer of the crate outside its own manifests, the workspace member list and CODEOWNERS; and the replica's TLS configuration inherits a key-exchange group list that already contains hybrid X25519MLKEM768, so promoting it would be a build-flag change rather than new cryptography. Against that, no mainnet algorithm swap has ever been demonstrated, and the December 2024 crypto-agility statement by DFINITY's cryptography lead is no longer retrievable at its original location.
Every canister is a smart-contract account with native key management, and the reverse-gas model means most calls need no user-held wallet key at all. The Internet Identity specification defines add, remove and replace device operations, and authn_method_add, authn_method_remove and authn_method_replace in its V2 API, so passkey rotation on an existing anchor is a first-class operation. Authentication methods are WebAuthn passkeys, PIN or temporary key, and recovery phrase or recovery device, with OpenID Connect federation to Google, Apple and Microsoft. The specification gives Ed25519 and ECDSA as session-key examples rather than fixing an exhaustive list. No client-layer post-quantum signing path is published.
NNS-coordinated replica upgrades have run since the network's earliest proposals, dated 2021-05-06, and continue daily; eight subnets were decommissioned by executed proposals in a single day on 2026-08-17 without incident on the public record. Coordinated cryptographic additions with dated on-chain governance records include the production threshold Schnorr keys (proposal 131474, executed 2024-08-05), the vetKD test key (proposal 136589, executed 2025-05-13) and the staged vetKD production key in June 2025, each announced in advance with a published schedule and, where the key backup required it, a stated Internet Identity downtime window of 5 to 10 minutes. No contested chain split is on the public record.
No hybrid post-quantum envelope is published at the subnet-consensus, threshold-signing, vetKD or Internet Identity layer. NNS Motion 35660 committed DFINITY to post-quantum research and lists open research questions, including determining the versatility, efficiency and cryptanalytic resilience of post-quantum primitives, selecting security parameters, and evaluating both lattice-based and hash-based signature candidates, but specifies no hybrid migration architecture and no dates. A September 2025 forum post by a non-staff community member claims a third-party hybrid layer 2 on ICP combining classical ECDSA and Schnorr with ML-DSA-44 and SLH-DSA-SHA2-128f for signatures and ML-KEM-768 for encryption; the claim is the author's own, drew no foundation reply, and the implementation is unverified.
ICP deploys no stateful hash-based signature primitive. A code search of dfinity/ic on 2026-08-19 returns zero hits for XMSS, and the repository lockfile contains no XMSS, LMS, SLH-DSA or SPHINCS+ crate of any kind. Default 15 of 15 for stateless schemes.
Subnet consensus, response certification, cross-subnet message authentication and the random beacon all aggregate BLS12-381 threshold shares produced by the NIDKG construction. No specification, testnet or mainnet pilot of a post-quantum aggregation path has been published. A community forum request opened 2026-08-14, setting out seven specific questions about migrating threshold BLS and the BLS-based random beacon, including whether a hybrid or dual-signature period is planned and how the root and subnet public keys would rotate without a fork, had six replies as of a re-read on 2026-08-19 and none from a DFINITY-affiliated account. On 2026-08-15 the founder amplified without dissent a quoted claim that an aggressive post-quantum transition by 2029 would be a mistake, which weakens the active-research reading that previously held this score above the undeclared floor. NNS Motion 35660, never rescinded, keeps it marginally above zero. Flagged consensus-layer-exposed under the standing-exposure clause: subnet BLS12-381 public keys are long-lived and published, so fast finality is no defence at the consensus layer.
5 Deployment Execution weight 22% 11 / 100
Mainnet post-quantum traffic is 0%. No post-quantum primitive signs subnet blocks, certified state, NNS proposals, threshold canister signatures, vetKD key transport or Internet Identity authentications. At the transport layer the hybrid X25519MLKEM768 group is present in the replica's inherited default group list but ranks below X25519 on both peers, so it is not the negotiated group, and the public HTTPS gateways reject it outright, measured 2026-08-19.
No first-party post-quantum implementation exists. A dfinity/ic code search on 2026-08-19 returns zero hits for ml-dsa, ML_DSA, kyber, dilithium, sphincs, SLH-DSA, falcon, ml-kem, mlkem and XMSS; searching the phrase post-quantum returns a single hit, a design comment in packages/ic-hpke/src/lib.rs stating that the crate's protocol and version identifiers exist so the algorithm can be rotated later, for example to a post-quantum scheme. That crate's own construction is classical HPKE with ECDH P-384, HKDF-SHA-384 and AES-GCM-256, it was added on 2025-03-03, and its last change on 2026-07-20 was a dependency migration that left the comment intact. Post-quantum code does nevertheless reach the shipped replica through a dependency: the TLS stack links aws-lc-rs 1.17.3 through rustls 0.23.37, whose aws-lc-rs default key-exchange group list includes hybrid X25519MLKEM768 (ML-KEM-768 per FIPS 203) in every build configuration, and the replica's TLS configuration, which the peer-to-peer QUIC transport also consumes, overrides only the cipher suites and leaves that list in place. We audited the whole rustls dependency graph and confirmed no manifest enables the prefer-post-quantum feature, so the group stays at lowest preference. The score reflects post-quantum KEM code present in the consensus client binary, unpreferred and undeclared, with no first-party post-quantum signature or KEM implementation anywhere.
No replica holds a post-quantum key. Subnet threshold keys are BLS12-381, secp256k1 and Ed25519 only, and node TLS identity certificates are Ed25519. The ML-KEM-768 material in the transport stack is ephemeral key-exchange material, not a registered or stored key, and it is not negotiated.
Voided to 0 because 5a is 0. The standing dated commitment is NNS Motion 35660, executed 2021-12-21, adopted as a long-term research objective with open research questions and named discussion leads but no completion date. A December 2024 crypto-agility statement by DFINITY's cryptography lead is cited second-hand in a later community thread as saying replacement algorithms would be proposed to the NNS at the appropriate time and that the network public key would have to change; its original forum location returns an access-denied response on re-check at 2026-08-19. No NNS proposal carries a hard-coded activation epoch, flag day, or sunset date for BLS12-381, secp256k1 or Ed25519.
No foundation-authored post-quantum announcement appears in the trailing 12 months. The February 2026 chain-key throughput work is foundation-authored but entirely classical and makes no post-quantum claim, and the only founder-level public statement on the topic, 2026-08-15, argues against a near-term transition, which is the inverse of washing. A forum search across the trailing 12 months returns five post-quantum items, all third-party and none with a foundation reply: a September 2025 hybrid post-quantum layer 2 post, a December 2025 recruitment post for a canister-level post-quantum verification and policy engine, a March 2026 application post claiming client-side Kyber-1024 encryption, a May 2026 canister-user threshold-signing thread whose author reports secp256k1 ECDSA working today and the MAYO signature scheme tested on a replica subnet, and a July 2026 application post claiming ML-KEM-768 keypair generation in a browser library. Post-quantum bytes shipped to mainnet by the foundation: none. No deduction trigger.
No post-quantum signature scheme is selected or specified for ICP consensus, threshold signing, vetKD or Internet Identity, so no signature-size multiplier can be computed. Score 0 per rubric for undisclosed.
6 Supply Chain Vendor Readiness weight 22% 8 / 100
Wallet and identity surfaces we verified live on 2026-08-19: Internet Identity, DFINITY-operated, WebAuthn passkeys plus PIN and recovery methods with OpenID Connect federation to Google, Apple and Microsoft, now served at id.ai after the legacy internetcomputer.org path began redirecting there; Plug Wallet; and NFID Wallet. Ledger hardware wallets list ICP support through Ledger Live, with the device application maintained in the open by Zondax for Nano S+, Nano X, Flex, Stax and Apex P. None of these surfaces publishes a post-quantum roadmap, and none names a post-quantum key type. No public source ranks ICP wallets by usage, so we make no ranking claim.
The chain-key token set on mainnet is ckBTC, ckETH, ckERC20 (documented examples ckUSDC, ckUSDT, ckLINK), ckSOL, and ckDOGE in beta. All of them rest on the same threshold ECDSA secp256k1, threshold Schnorr BIP-340 and Ed25519, and subnet BLS12-381 stack, so the exposure is single-family across the whole set. The tile sits above the floor only because the minter canisters are first-party and are changed through NNS proposals, a mechanism exercised in the observed proposal window by an executed ckERC20 token addition, which is a working change mechanism, not a declared migration plan. No post-quantum roadmap is published for any of them.
No named institutional custodian's ICP support is established by a primary source as of 2026-08-19: the supported-asset listings either did not resolve or required authentication. The only custody-adjacent surface we verified is the Ledger hardware wallet path described in 6a. No ICP-specific post-quantum migration roadmap was found from any custody vendor. The tile therefore rests on an unrebutted negative finding rather than on a verified vendor set, and it is scored at the floor accordingly.
Public HTTPS gateways ic0.app, icp-api.io and internetcomputer.org terminate TLS 1.3 with the X25519 group, TLS_AES_256_GCM_SHA384, and ECDSA secp384r1 or secp256r1 server certificates, and they reject a forced X25519MLKEM768 handshake with alert 40, measured 2026-08-19: no hybrid post-quantum KEM is offered to clients. API boundary nodes are registered on-chain and upgraded through NNS proposals. On the trusted-hardware side, two of the 42 subnets run with AMD SEV enabled per the live registry, one of them carrying the confidential specialization, and a node-swap program to move further subnets onto SEV-enabled hardware was running in the observed proposal window at wave 6. Confidential computing is therefore deployed and expanding, but it sits on a small minority of subnets and it does nothing for post-quantum exposure. We found no published information about hardware security module vendors used by node providers and make no claim about them.
7 Governance & Coordination weight 8% 42 / 100
Live registry, 2026-08-19: 42 subnets, 618 nodes assigned to subnets out of 1,284 registered, held by 78 node providers with node-provider Nakamoto coefficients per subnet ranging from 3 to 12, median 5. Subnet sizes are 7, 13, 34 and 40 nodes. The largest single entity is DFINITY Stiftung with 59 directly operated nodes, 42 of them rewardable, present in 39 subnets, plus 1,325 cloud-engine nodes of which 1,251 are unassigned. Several independent providers cluster at 42 and 37 nodes each. Governance authorship is more concentrated than node counts suggest: of the 100 most recent NNS proposals, read 2026-08-19 and covering 2026-08-13 to 2026-08-19, 95 carry the DFINITY-proposer flag. Node-provider admission and removal both run through NNS proposals.
NNS proposals execute daily, and replica binaries roll subnet by subnet without downtime. Major cryptographic key operations have shipped on published schedules with advance notice, including the staged vetKD production rollout of June 2025, which named the generation, backup and enablement dates and disclosed the 5 to 10 minute Internet Identity downtime the backup required, and the August 2024 threshold Schnorr production-key generation, which disclosed a 6 to 10 minute window on the same subnet. Strong operational record under non-emergency conditions; no emergency cryptographic rollback is on record to test the other case.
NNS Motion 35660 names Jens Groth and Andrea Cerulli as the post-quantum discussion leads, and we found no newer naming. There is no publicly named, mandated post-quantum migration program manager and no quarterly deliverable schedule. The December 2024 crypto-agility statement that previously supported this score is no longer retrievable at its original forum location and survives only as a second-hand summary. A 2026-08-15 post from the founder's account shared a claim that an aggressive post-quantum transition by 2029 would be a mistake, and drew same-day public pushback from a named community developer, and the 2026-08-14 request for a concrete threshold-BLS migration plan had no foundation reply through 2026-08-19. The top coordination authority is currently arguing against near-term migration rather than leading one.
Proposals are genuinely contested rather than rubber-stamped: of the 100 most recent NNS proposals, read 2026-08-19, five drew a no-vote share above 2% of voting power, the highest at 24% on a service-nervous-system creation, and node-provider removal is itself a proposal type in that window. But there is no precedent of a coordinated cryptographic primitive change under active adversarial pressure. The closest operational precedent is the NIDKG resharing protocol that lets subnet membership change without changing the subnet public key, plus the key-backup resharing that the threshold Schnorr and vetKD production rollouts required.
No community honeypot, no rate-limited spending rule, no cryptographic tripwire embedded in subnet consensus, no automated post-quantum event response. A community participant raised a compliance-driven tripwire argument in the August 2026 forum thread; it drew no foundation response and is not a mechanism.
Source-disagreement disclosure
v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.
Resolved. The vetKeys documentation states the vetKD management canister API is live on mainnet, names bls12_381_g2 as the only supported curve, and distinguishes test_key_1 from key_1 with key_1 marked mainnet only. NNS proposal 136589, executed 2025-05-13, generated the test key Bls12_381_G2:test_key_1 on subnet 2fq7c. A DFINITY forum announcement dated 2025-06-11 set out the staged production rollout: generate Bls12_381_G2:key_1 on the fiduciary subnet pzp6e from 2025-06-20, back it up to subnet uzr34 on 2025-06-26, and enable it for public canister use from 2025-06-27. Scores treat vetKD as live production, which widens the confirmed BLS12-381 harvest-now-decrypt-later surface rather than improving any PQC sub-score.
A September 2025 forum thread describing a third-party hybrid post-quantum layer 2 (ML-DSA-44, SLH-DSA-SHA2-128f, ML-KEM-768 alongside classical ECDSA and Schnorr), a December 2025 third-party recruitment post for a canister-level post-quantum verification and policy engine, and two 2026 third-party application posts claiming client-side Kyber-1024 and ML-KEM-768 key generation in a browser library all rank high in search results and could be misread as DFINITY deployments. All four are third-party, none drew a reply from a DFINITY-affiliated account, and none is independently verified beyond its author's own claims. The foundation position remains NNS Motion 35660.
On 2026-08-15 DFINITY's founder posted a quotation from an external cryptographer to the effect that an aggressive post-quantum transition by 2029 would be a mistake and more likely to create a catastrophic bug than protection, and added no disagreement. We verified the post itself verbatim. The linked video is not independently verified here, so the fidelity of the quotation to what the external cryptographer actually said is unestablished, and the quotation as posted is heavily elided. NNS Motion 35660, executed 2021-12-21 and never rescinded, remains the standing long-term post-quantum research commitment, and its own text acknowledges both signature forgery by a quantum adversary and the harvesting of ciphertexts for later decryption. A caution against haste and a long-term research pledge are not formally contradictory. However, a community developer publicly read the post the same day as a stance against quantum readiness, while also writing that the technical argument may well be correct; a forum participant cited it two days later as the official answer; and the 2026-08-14 request for a concrete threshold-BLS migration plan still had no reply from a DFINITY-affiliated account on 2026-08-19. We treat the post as an unrebutted amplification rather than a formal foundation position, and we weight the shipped-evidence record, which is zero post-quantum code, above either posture signal.
The replica's TLS client and server configurations build from the rustls aws-lc-rs provider default and override only the cipher suites, leaving the key-exchange group list untouched. The peer-to-peer QUIC transport does not build its own crypto configuration; it consumes those same configurations and wraps them for quinn, so this is the production node-to-node path and not a side channel. In the rustls version pinned by the repository's lockfile, the aws-lc-rs default group list is X25519, secp256r1, secp384r1 and hybrid X25519MLKEM768, and the group is present in every build configuration; the prefer-post-quantum feature, which is a rustls default feature, changes only whether X25519MLKEM768 ranks first or last. We audited the feature-unification risk directly: the workspace declares rustls with default features off and a feature list that omits prefer-post-quantum, every first-party crate inherits that declaration, and every third-party crate in the graph that depends on rustls also declares default features off without prefer-post-quantum. With the feature off the group ranks last, so two replicas that both rank X25519 first will negotiate X25519. No ICP specification, proposal, release note or blog post we found mentions X25519MLKEM768 or ML-KEM in any form. Two residual gaps remain: the lockfile also carries an older rustls that predates the hybrid group, resolved to different consumers, and we could not observe a live replica-to-replica handshake, so whether the deployed binary advertises the group on the wire is inferred from source and pinned dependency versions rather than measured. The public HTTPS gateways, which we could measure, refuse the group outright.
The Discourse staff, admin and moderator flags are not a safe test of whether a forum reply came from the foundation: the DFINITY cryptography team members who authored the threshold Schnorr production-key announcement, the vetKeys production-key announcement and the chain-key signing performance announcement all post with staff false. We therefore establish the absence of a foundation reply by account identity and by the absence of any DFINITY affiliation marker on every poster, not by the staff flag alone. Under that stricter test the 2026-08-14 threshold-BLS migration thread shows no foundation reply through 2026-08-19.
The live registry read on 2026-08-19 returns 78 node providers, 1,284 registered nodes, 618 nodes assigned to the 42 subnets, and 1,488 rewardable-node allowances, a figure that exceeds the deployed count and is therefore an allowance rather than a subset. Eight subnets were decommissioned by NNS proposals executed on 2026-08-17, and the live count of 42 subnets already excludes all eight.
No primary source states supports a threshold ECDSA general-availability date of August 2022 or a threshold Schnorr general-availability date of September 2024. What is verified: NNS proposal 131474, executed 2024-08-05, generated the production BIP-340 secp256k1 and Ed25519 threshold keys with key id key_1 on the fiduciary subnet pzp6e, and the accompanying DFINITY announcement states that pzp6e also holds the production ECDSA key and that uzr34 is its backup subnet; and the production secp256k1 key key_1 already appeared in a mainnet ckBTC minter initialisation argument quoted in a December 2022 forum post. The card states only what those artifacts support.
Proposal 140289, executed 2026-02-12, is titled 'Update configuration of subnet: pzp6e' and raises the maximum request queue size and the pre-signature pool for the chain keys on that one subnet; it is not itself a network-wide throughput upgrade. The tenfold figure comes from a DFINITY forum post dated 2026-02-25, which states prior sustained limits of 0.5 signatures per second for threshold ECDSA, 1.1 for threshold Schnorr and 5 for vetKeys, a tenfold or better increase in sustained throughput for subnets configured for high signature load, and, as a consequence of proposal 140289 raising the advance pre-signature count from 5 to 100 on pzp6e, expected maximum throughput of 3.5, 6.5 and 18 signatures per second respectively. All of it is classical work with no post-quantum content.
Delta-QRI under alternative weighting
Under a weighting that prioritizes governance-coordination capacity (+5pp Dim 7 at the expense of Dim 6), QRI rises to about 26 and Band 3 still binds. Under a weighting that prioritizes deployment execution (+5pp Dim 5 at the expense of Dim 7), QRI falls to about 24 and Band 3 still binds.
Announcement-to-shipped ratio
Announced: 0. Shipped: 0. Ratio: 0.
Tag: none (no foundation-authored PQC claims in the trailing 12 months. The only founder-level public statement on the topic, 2026-08-15, argues against a near-term post-quantum transition, which is the inverse of PQC-washing. Third-party ecosystem posts are not foundation claims)
Peers in the L1 profile
9 chains closest to Internet Computer (ICP) by Stage then QRI.