An audited SPHINCS+ lock script is deployed on CKB mainnet, so users can hold funds under a NIST-standardised post-quantum signature today without a hard fork.
Is Nervos CKB quantum-safe?
Partly, and by user choice rather than by default. Nervos CKB does not hardcode a signature algorithm into its consensus rules. Signature verification runs as a Lock Script on a RISC-V virtual machine, so a post-quantum scheme can be added without changing the protocol. The CKB team used that property to build a SPHINCS+ lock script, audited by ScaleBit, and began deploying it on mainnet in 2025 alongside a wallet that uses it. A CKB holder can therefore move funds to a quantum-resistant address today, permissionlessly and without a fork. What CKB has not done is make that the default: ordinary CKB addresses still use secp256k1, which a sufficiently large quantum computer would break, and the large majority of supply still sits under those classical locks.
Where we are making a judgement call CKB sits in Tier 2 on the strength of an opt-in lock script rather than a protocol-level default. We treat a scheme that protects real mainnet funds today as shipped, even when adoption is small, because that is the literal test the tier sets. Readers who weight default protection more heavily than availability should read this placement as generous.
At a glance
On mainnet today
secp256k1 by default; SPHINCS+ available via an on-chain lock script
SPHINCS+ is available on mainnet as an audited, production-ready lock script supporting twelve parameter sets, and a desktop wallet ships with it. It is opt-in rather than the default, and normal CKB addresses remain secp256k1.
source
2 Deployment stage 8/10, weighted 25%
Tier 2: Shipping. A post-quantum signature scheme protects real funds on CKB mainnet today and users can migrate to it now, which is the defining test for this tier.
source
3 NIST alignment 10/10, weighted 15%
SPHINCS+ was standardised by NIST as SLH-DSA in FIPS 205 in August 2024. CKB is using a finalised standard rather than a candidate, which no other chain in this index does for a scheme that is live on mainnet.
source
4 Migration path 9/10, weighted 15%
CKB's migration is the cleanest in the index. A user creates an address referencing the new lock script's code hash and transfers assets to it. No hard fork is required, the network does not need to coordinate, old addresses keep working, and the upgrade can proceed gradually and permissionlessly.
source
5 Exposure 5/10, weighted 10%
CKB uses a cell model in which addresses commit to a lock script hash, so a public key is not revealed until an output is spent. That limits exposure compared with account-model chains where the address is the public key, but the majority of supply still sits under secp256k1 locks and every spent cell has revealed its key.
source
6 Verification 8/10, weighted 5%
The quantum-resistant lock script is open source and completed a security audit by ScaleBit. The claim is checkable on-chain and in the public repository rather than resting on marketing.
source
The deployment dimension is not a separate judgement. It is Tier 2
expressed as a number. See the tier mapping.
How it compares
All 23 rated chains on the 0 to 100 scale.
Nervos CKB is marked. Select any point to open that profile.
CKB team and Cryptape researchers implement a production-ready quantum-resistant lock script using SPHINCS+.
source
August 2024shipped
NIST approves SPHINCS+ as SLH-DSA under FIPS 205, giving the deployed scheme a finalised standard.
source
2025shipped
The CKB team begins deploying the SPHINCS+ lock script on CKB mainnet, after a security audit by ScaleBit.
source
February 2026shipped
The Quantum Purse desktop wallet ships, giving non-technical holders a route to SPHINCS+-locked funds.
source
Exposure
Exposure measures how much of the chain's value already sits behind a public key that an
attacker can record today and break later. This is the part of the threat that a future
upgrade cannot undo.
CKB's cell model means an address commits to the hash of a lock script rather than to a public key directly, so a key is only revealed when a cell is spent. Unspent, never-spent holdings under secp256k1 are therefore not yet harvestable. This is materially better than account-model chains where every account's public key is on-chain from the first transaction, but it is the same structural position as Bitcoin: reuse and spending progressively expose the network, and the protection erodes rather than holds.
What this rating means for you
If you hold Nervos
Nervos has post-quantum signatures live on mainnet, but they are not the default, so holders have to opt in. That makes this one of the few chains where you can act today rather than wait.
Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it
is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating.
How we make money.
Questions
Is Nervos CKB quantum-safe?
It can be, if a holder chooses it. CKB has an audited SPHINCS+ lock script deployed on mainnet, so funds moved to a SPHINCS+ address are protected by a NIST-standardised post-quantum signature today. Funds left in ordinary CKB addresses use secp256k1 and remain quantum-vulnerable.
Why does CKB not need a hard fork to add post-quantum signatures?
Because CKB does not hardcode a signature algorithm in its consensus rules. Signature verification is implemented as a Lock Script running on a RISC-V virtual machine, so a new cryptographic scheme is deployed as a script on-chain rather than as a protocol change. Users adopt it by creating addresses that reference the new script's code hash.
Has the SPHINCS+ lock script been audited?
Yes. The Nervos documentation states the quantum-resistant lock script completed a security audit conducted by ScaleBit, and the implementation is open source in the nervosnetwork/quantum-resistant-lock-script repository, so the audit claim and the code can both be checked independently.
How much CKB is actually protected by SPHINCS+?
A small share. Deployment began in 2025 and the wallet supporting it shipped in 2026, so the overwhelming majority of CKB supply still sits under secp256k1 locks. Availability is not adoption, and this index scores CKB's signature dimension at 6 rather than higher for exactly that reason.
This is a security-readiness assessment, not investment advice.
Cookies. We use Google Analytics to count how many people read a page. That is
the only thing this site measures: no advertising, no profiling, no third-party marketing tags.
Until you choose, nothing is stored on your device.
What we would set, in full.