Signs with ECDSA on secp256k1 across its chains, with no published post-quantum roadmap found at the time of writing.
Is Avalanche quantum-safe?
No. Avalanche secures accounts with ECDSA on the secp256k1 curve across its C-Chain, X-Chain and P-Chain, and a sufficiently large quantum computer would break it. We could not find a published post-quantum roadmap, a named replacement scheme, or a research programme from Avalanche or Ava Labs at the time of writing. That absence is the finding, and it is worth stating plainly rather than softening: a chain with no published position has not yet begun the work that the chains ranked above it have started. Avalanche's subnet architecture means individual subnets can in principle adopt their own signature rules, which is a genuine structural flexibility, but we found no evidence of that being used for post-quantum signatures.
Where we are making a judgement call Tier 5 records a published position, or rather the absence of one. We found no roadmap, named scheme or research programme for Avalanche, and its signatures on mainnet today are quantum-vulnerable. That is a finding about what Avalanche has published, not a judgement of its engineering, and not a claim that no internal work exists. If Avalanche publishes a post-quantum position, the primary source is the fastest way to move this row.
At a glance
On mainnet today
ECDSA on secp256k1 across the C-Chain, X-Chain and P-Chain
Post-quantum scheme
None selected. No post-quantum scheme was found in published Avalanche material.
NIST standard
None adopted
Readiness tier
Tier 5: Exposed. The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme could be found.
Score breakdown
Each dimension scored 0 to 10. The weight beside it is its share of the
total score.
Avalanche uses ECDSA on secp256k1 across its primary network chains. Nothing post-quantum protects AVAX or assets on Avalanche today.
source
2 Deployment stage 1/10, weighted 25%
Tier 5: Exposed. Avalanche signs with ECDSA on secp256k1 and we found no published roadmap, named scheme or research programme, which is the bottom rung of the spine: quantum-vulnerable signatures and no public post-quantum plan.
source
3 NIST alignment 0/10, weighted 15%
No post-quantum scheme has been named or selected, so there is nothing to align with a NIST standard.
source
4 Migration path 2/10, weighted 15%
No migration plan exists. Avalanche's subnet architecture does give it real optionality, because a subnet can define its own validation rules without the primary network changing, which is a mechanism a future migration could use. No such use has been published.
source
5 Exposure 2/10, weighted 10%
C-Chain addresses are hashes of public keys in the Ethereum style, so a funded account that has never transacted keeps its key private. In practice nearly all economically active accounts have signed and published their keys.
source
6 Verification 6/10, weighted 5%
AvalancheGo is open source, so the signature scheme is directly verifiable from the code. There is no post-quantum claim to verify, which is neither a strength nor a failure of verification, simply an absence.
source
The deployment dimension is not a separate judgement. It is Tier 5
expressed as a number. See the tier mapping.
How it compares
All 23 rated chains on the 0 to 100 scale.
Avalanche is marked. Select any point to open that profile.
No post-quantum roadmap, named scheme or research programme was found from Avalanche or Ava Labs at the time of writing.
source
Exposure
Exposure measures how much of the chain's value already sits behind a public key that an
attacker can record today and break later. This is the part of the threat that a future
upgrade cannot undo.
Avalanche's C-Chain follows Ethereum's address model, deriving an address from a hash of the public key, so an account funded but never spent from has not revealed its key. The protection ends at first signature. Because the C-Chain carries the overwhelming majority of Avalanche's activity and value, and because active accounts sign frequently, the practical position is that most economically meaningful AVAX sits behind a key that is already published on-chain and can be collected today against a future quantum computer.
What this rating means for you
If you hold Avalanche
Avalanche runs quantum-vulnerable signatures with no published post-quantum plan that we could find. Nothing here is urgent today, and there is also nothing scheduled to change it.
Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it
is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating.
How we make money.
Questions
Is Avalanche quantum-safe?
No. Avalanche uses ECDSA on the secp256k1 curve across its chains, which a sufficiently large quantum computer would break. We found no published post-quantum roadmap or named replacement scheme at the time of writing.
Does Avalanche have a post-quantum plan?
None that we could find. We searched for a roadmap, a named scheme, a research programme and a testnet implementation, and found no published position from Avalanche or Ava Labs. If one exists and we have missed it, sending us the primary source is the fastest way to correct this profile.
Could Avalanche subnets adopt post-quantum signatures independently?
In principle yes, and that is a real structural advantage. A subnet can define its own validation rules without the primary network changing, which would let a post-quantum subnet exist without a network-wide fork. We found no evidence of this being used for post-quantum signatures, so it counts as optionality rather than progress.
Why does Avalanche score above zero at all?
Because two dimensions measure things other than post-quantum deployment. Avalanche scores on exposure, since its address model hashes public keys rather than publishing them directly, and on verification, since the client is open source and the cryptography can be checked from the code.
This is a security-readiness assessment, not investment advice.
Cookies. We use Google Analytics to count how many people read a page. That is
the only thing this site measures: no advertising, no profiling, no third-party marketing tags.
Until you choose, nothing is stored on your device.
What we would set, in full.