The Hardy Index Quantum readiness benchmark

Chain profile

TON

TON Exposed

Signs with Ed25519 and has no published post-quantum roadmap, though its wallet-as-smart-contract model means a new signature scheme could be adopted without changing the protocol.

Is TON quantum-safe?

No. TON accounts are secured by Ed25519, which a sufficiently large quantum computer would break. We found no published post-quantum roadmap, named replacement scheme or research programme for TON at the time of writing. TON does have a structural property worth stating, because it is the same property that gives Ethereum and Starknet their migration route: on TON, a wallet is a smart contract, and the signature checking logic lives in that contract rather than being fixed by the protocol. In principle a new wallet contract could verify a post-quantum signature without any consensus change at all. That is genuine optionality, and it is not the same as a plan. We found no evidence of anyone having built or proposed such a wallet.

Where we are making a judgement call TON sits in Tier 5 because its mainnet signatures are quantum-vulnerable and no post-quantum roadmap, proposal or research programme was found. Its migration score of 3 is higher than peers with the same absence of a plan, because the wallet-as-contract architecture genuinely could support a post-quantum wallet without a consensus change. We are crediting the architecture, not treating it as progress.

At a glance

On mainnet today

Ed25519, verified inside wallet smart contracts

Post-quantum scheme

None proposed. No TON-specific post-quantum work was found.

NIST standard

None adopted

Readiness tier

Tier 5: Exposed. The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme could be found.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
TON Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 1 25% 2.5
3 NIST alignment 0 15% 0.0
4 Migration path 3 15% 4.5
5 Exposure 3 10% 3.0
6 Verification 6 5% 3.0
Hardy Score 13.0

1 Signature scheme 0/10, weighted 30%

TON wallets verify Ed25519 signatures, which are broken by Shor's algorithm. Nothing post-quantum protects TON on mainnet today. source

2 Deployment stage 1/10, weighted 25%

Tier 5: Exposed. TON signs with Ed25519 and no post-quantum roadmap, proposal or research programme was found. See the caveat below on its wallet architecture. source

3 NIST alignment 0/10, weighted 15%

No post-quantum scheme has been named or proposed for TON, so there is nothing to assess against a NIST standard. source

4 Migration path 3/10, weighted 15%

TON's wallets are smart contracts and the signature check lives in contract code, so a post-quantum wallet could in principle be deployed without a consensus change. That is a materially better structural position than a protocol-fixed signature scheme, but no plan, proposal or implementation was found. source

5 Exposure 3/10, weighted 10%

A TON address is derived from a hash of the wallet contract's initial state, which includes the public key, so the address does not publish the key directly. The key becomes visible once the wallet is deployed and used, which is true of essentially every funded wallet. source

6 Verification 6/10, weighted 5%

The TON node implementation is open source and the signature scheme is verifiable from the code and from standard wallet contracts. There is no post-quantum claim to verify. source

The deployment dimension is not a separate judgement. It is Tier 5 expressed as a number. See the tier mapping.

How it compares

All 23 rated chains on the 0 to 100 scale. TON is marked. Select any point to open that profile.

Roadmap

  1. No published position proposed

    No post-quantum roadmap, proposal or research programme for TON was found at the time of writing. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

A TON wallet address is derived from a hash of the contract's initial state, which embeds the owner's public key, so the address itself does not hand an attacker the key. In practice the key becomes readable once the wallet contract is deployed on-chain, and a wallet must be deployed to be used, so essentially every funded and active TON wallet has a visible key that can be recorded today. The position is somewhat better than chains where the address simply is the key, and considerably worse than a UTXO chain where unspent funds keep their keys private.

What this rating means for you

If you hold TON

TON runs quantum-vulnerable signatures with no published post-quantum plan that we could find. Nothing here is urgent today, and there is also nothing scheduled to change it.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

Questions

Is TON quantum-safe?

No. TON wallets verify Ed25519 signatures, which a sufficiently large quantum computer would break. We found no published post-quantum roadmap or proposal for TON at the time of writing.

Could TON adopt post-quantum signatures without a hard fork?

In principle yes, and this is TON's main structural advantage. Wallets on TON are smart contracts and the signature verification happens in contract code rather than in the protocol, so a new wallet contract could verify a post-quantum signature without a consensus change. No such wallet has been proposed or built as far as we could find.

Does TON's address model protect holders?

Only slightly. A TON address is a hash of the wallet contract's initial state, which contains the public key, so the address does not reveal the key directly. But a wallet contract has to be deployed on-chain to be used, and once deployed the key is readable, so nearly all active wallets are exposed.

What would raise TON's score?

A published position would raise the tier. A proposed or deployed post-quantum wallet contract would raise the signature and NIST dimensions substantially, and because that route needs no consensus change, TON could move faster than chains that must coordinate a protocol upgrade.

Sources

  1. TON blockchain node implementation TON Blockchain (GitHub) · primary · checked 12 August 2026
  2. FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) NIST · primary · checked 12 August 2026
  3. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly Google Research · primary · checked 12 August 2026

This is a security-readiness assessment, not investment advice.