Watchlist 0
ZKSYNC ERA · rollup-L2 · QRI 34 · BAND 3 Preparing Hybrid CONDITIONAL (Boojum prover is partially PQ-path; user sig layer classical) · Stage 1 · Washing 1.2x

zkSync Era is the only L2 where signature choice is a contract-level decision because account abstraction is native from genesis. Combine that with the Boojum prover moving toward FRI-based commitments, and the migration tool is already sitting on mainnet. Shipped, unused.

inLinkedIn XPost Scorecard JSON Compare Verified 2026-04-17

Summary

zkSync Era has above-baseline PQ posture via two structural advantages: native account abstraction (signature scheme is a contract-level choice) and the Boojum prover transition toward hash-based FRI-style commitments. User signatures remain classical ECDSA but AA enables per-account migration. Behind Starknet on proof-system PQ-readiness (Boojum transition still in progress vs. Starknet's FRI already-shipped), but ahead of most L2s.

What the gates say

  • Hybrid: COND. Boojum prover is partially PQ-path; user sig layer classical
  • Evidence: PASS. Sources reconstructable by third party.
  • Primitive naming: PASS. Named primitives at every scored sub-level.

Burn-vs-rescue policy on file

AA-rescue likely via per-account rotation; Boojum handles prover-side transition

Seven dimensions

Each dimension scores 0-100 internally; the weighted roll-up produces the QRI on the left. Open a row to read the sub-score detail.

1 Cryptographic Exposure 34 / 100
1a_primitive_inventory 12 / 20

Native AA from genesis; Boojum prover transitions toward FRI-based (PQ-safe proofs on roadmap but current Era still PLONK/BN254).

Primitives: ECDSA secp256k1 (user signatures) · Keccak-256 + Poseidon (hashing) · Boojum (next-gen STARK-like prover with FRI-friendly commitments) · PLONK on BN254 (current prover)
Evidence:
1b_shor_grover_pq_tag 10 / 20
1c_algorithm_family_diversity 4 / 20

Current mainnet: no PQ family. Boojum roadmap introduces hash-based path.

1d_nist_security_category 4 / 20
1e_implementation_quality 4 / 20
2 HNDL Exposure 28 / 100
2a_active_key_exposure 7 / 20

Native AA: per-account key migration possible; user keys inside smart accounts.

2b_cold_key_exposure 7 / 20

~3 years mainnet; moderate dormant.

2c_signature_longterm_validity 7 / 20

Historical ECDSA sigs Shor-forgeable; AA enables rotation for new sigs.

2d_encryption_confidentiality 7 / 20

TLS; no PQ KEM.

3 Metadata & Privacy Exposure 25 / 100
3a_tx_graph_visibility 6 / 20

Transparent ledger.

3b_rpc_mempool_concentration 6 / 20

Matter Labs sequencer (centralized).

3c_cross_chain_bridge_correlation 7 / 20

Canonical bridge + LayerZero.

3d_retroactive_deanon_risk 6 / 20

No shielded pools.

4 Migration Architecture 72 / 100
4a_crypto_agility 19 / 20

Native AA from genesis; Matter Labs has signature-scheme flexibility at the contract level. Boojum architecture allows prover swap without user changes.

4b_account_abstraction_key_rotation 20 / 20

Full AA: every account is a contract. Per-account signature validation means ML-DSA/Falcon can be added via verifier contracts. Among strongest AA in batch alongside Starknet.

4c_hard_fork_track_record 16 / 20

Boojum migration (2024), PLONK to Boojum transition ongoing. Smooth execution.

4d_hybrid_deployment_readiness 17 / 20

Boojum is the transition path toward hash-based proofs. No shipped hybrid signature yet; structural readiness high.

5 Deployment Execution 22 / 100
5a_mainnet_pqc_pct 3 / 20

Boojum's hash-based commitments are partially deployed (prover layer); user signature layer still classical. Partial credit.

5b_pqc_code_in_client 6 / 20

era-boojum repo is shipped code; FRI-friendly primitives present. No ML-DSA signatures yet.

5c_validator_pqc_adoption 3 / 20

Matter Labs sequencer; proving infra upgraded.

5d_published_milestones_count 6 / 20

Milestones: (1) Boojum transition published, (2) Era v24 prover upgrade.

5e_pqc_washing_delta 4 / 20

Moderate: Boojum framed as 'post-quantum path' but consumer claim not overstated.

6 Supply Chain Vendor Readiness 8 / 100
6a_wallet 2 / 20
6b_bridge 2 / 20
6c_custodian 2 / 20
6d_rpc_hsm 2 / 20
7 Governance & Coordination 40 / 100
7a_validator_stake_distribution 6 / 20

Centralized Matter Labs sequencer.

7b_upgrade_cadence_under_pressure 12 / 20

Boojum transition + Era upgrades coordinated.

7c_named_coordination_lead 12 / 20

Named: Alex Gluchowski, Matter Labs, zkSync Association.

7d_adversarial_coordination_precedent 10 / 20

No adversarial precedent.

The X + Y vs Z inequality

X (data shelf life): 3-8 (AA-rotatable)

Y (migration time): 2-5 (AA substrate + Boojum path)

Z10 (10% CRQC year): 2036 · Z50 (50%): 2041

Verdict: X+Y < Z (safe).

Four-scenario grid

ScenarioValue preservedPrivacy preserved
quantum never 100% 100%
arrives suddenly pre migration 30% 20%
arrives slowly post migration 75% 45%
arrives slowly mid migration 55% 30%

Peers in the rollup-L2 profile

Order-book view of the 9 chains closest to zkSync Era by QRI.

Public artifacts used for this scorecard

Each entry below is a sub-score citation. Clicking the link takes you to the public source. A third party should be able to reconstruct every number on this page from these URLs in 48 hours.

Cryptographic Exposure · 1a_primitive_inventory

Native AA from genesis; Boojum prover transitions toward FRI-based (PQ-safe proofs on roadmap but current Era still PLONK/BN254).

Supply chain snapshot

wallet MetaMask · Rabby · Safe 0 PQC roadmaps
bridge Canonical Era bridge · LayerZero · Across 0 PQC roadmaps
custodian Coinbase Custody · BitGo · Anchorage 0 PQC roadmaps
rpc_hsm Matter Labs RPC · Alchemy · QuickNode 0 PQC roadmaps

A chain's supply chain cannot migrate faster than its slowest dependency. Zero PQC roadmaps in any of the four categories is a structural blocker, not a lagging indicator.

Analyst notes on the scoring

Stage 1 (moving to 2 as Boojum completes). Second-strongest L2 PQ posture after Starknet. Boojum is a real PQ-path signal; FRI-friendly commitments reduce proof-layer PQ risk. AA gives migration tool.

Scorecard metadata

  • Profile: rollup-L2
  • Scored: 2026-04-17 by layerqu-v2-scoring-agent-5
  • v1 reference: chainscreen-v1-archive
  • QRI raw: 38 · after caps: 34
  • Confidence interval: ±6
  • PQC washing ratio: 1.2x
  • Burn-vs-rescue: AA-rescue likely via per-account rotation; Boojum handles prover-side transition

Caps triggered

  • mosca_cap_60 (5a partial)
  • aaronson_cap_partial (Boojum FRI components shipping)
LayerQu · zkSync Era scorecard v2 · reconstructs from public evidence
Methodology · Desk · API