Wednesday, October 7, 2026

Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?


<a target="_blank" href="I've been looking into the quantum-resistance question and I'm trying to understand where Monero actually stands today.From what I can tell, Monero is not fully post-quantum resistant yet. Carrot/FCMP++ seem to improve some things significantly, including forward secrecy against a quantum-enabled adversary, and there is active work around Jamtis and post-quantum encryption.But spend authorization still ultimately relies on elliptic-curve cryptography, which would presumably become vulnerable to Shor's algorithm once a sufficiently capable fault-tolerant quantum computer exists.So I have a few questions for people who actually understand the protocol-level work:Which parts of Monero would currently fail first under a cryptographically relevant quantum computer?Is there already a realistic design for making the entire transaction stack post-quantum, including spend authorization, privacy, multisig and address encryption?What is the main blocker today: signature size, performance, rerandomizable keys, zero-knowledge compatibility, multisig, or simply that the required primitives are still too immature?If the community decided that PQ migration was an urgent priority tomorrow, are we talking roughly months, 2-3 years, 5+ years, or is there genuinely no meaningful estimate yet?Could Monero migrate pre-emptively while preserving old outputs, or would users eventually need to move funds into a new PQ output/address scheme before some activation height?How much of this problem can FCMP++ / zero-knowledge proofs solve, and which parts still fundamentally require a new post-quantum signature/key system?My concern is less "quantum computers will definitely break ECC next year" and more about the lead time.AI progress is moving extremely quickly, and I personally wouldn't be comfortable assuming that cryptographically relevant quantum computing is decades away. Even if a serious threat were still several years out, a cryptocurrency probably wants the replacement architecture researched, implemented, audited and deployed well before the first credible machine appears.If, hypothetically, evidence emerged that ECC could be broken within 12-24 months, could Monero realistically get a fully post-quantum protocol into production fast enough?And is there currently an actual PQ migration roadmap somewhere that I should read?Would especially appreciate answers from people involved in MRL / FCMP++ / Carrot / Jamtis." title="Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?">full image</a> <strong> - Repost: Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?</strong> (<i>from Reddit.com, Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?</i>) <br><blockquote> I've been looking into the quantum-resistance question and I'm trying to understand where Monero actually stands today.From what I can tell, Monero is not fully post-quantum resistant yet. Carrot/FCMP++ seem to improve some things significantly, including forward secrecy against a quantum-enabled adversary, and there is active work around Jamtis and post-quantum encryption.But spend authorization still ultimately relies on elliptic-curve cryptography, which would presumably become vulnerable to Shor's algorithm once a sufficiently capable fault-tolerant quantum computer exists.So I have a few questions for people who actually understand the protocol-level work:Which parts of Monero would currently fail first under a cryptographically relevant quantum computer?Is there already a realistic design for making the entire transaction stack post-quantum, including spend authorization, privacy, multisig and address encryption?What is the main blocker today: signature size, performance, rerandomizable keys, zero-knowledge compatibility, multisig, or simply that the required primitives are still too immature?If the community decided that PQ migration was an urgent priority tomorrow, are we talking roughly months, 2-3 years, 5+ years, or is there genuinely no meaningful estimate yet?Could Monero migrate pre-emptively while preserving old outputs, or would users eventually need to move funds into a new PQ output/address scheme before some activation height?How much of this problem can FCMP++ / zero-knowledge proofs solve, and which parts still fundamentally require a new post-quantum signature/key system?My concern is less "quantum computers will definitely break ECC next year" and more about the lead time.AI progress is moving extremely quickly, and I personally wouldn't be comfortable assuming that cryptographically relevant quantum computing is decades away. Even if a serious threat were still several years out, a cryptocurrency probably wants the replacement architecture researched, implemented, audited and deployed well before the first credible machine appears.If, hypothetically, evidence emerged that ECC could be broken within 12-24 months, could Monero realistically get a fully post-quantum protocol into production fast enough?And is there currently an actual PQ migration roadmap somewhere that I should read?Would especially appreciate answers from people involved in MRL / FCMP++ / Carrot / Jamtis. </blockquote> <hr><h3> <hr><strong>Mining:</strong> <br> <a title="Cryptotab browser" target="_blank" href="https://cryptotabbrowser.com/12/4000343"><u>Bitcoin</u>, Cryptotab browser</a> - <a title="Pi Network, CLOUD PHONEMINING" target="_blank" href="https://minepi.com/cusidore"><u>Pi Network</u> cloud PHONE MINING</a> <br><a title="Fone, CLOUD PHONE MINING" target="_blank" href="https://play.google.com/store/apps/details?id=com.cloud.earning"><u>Fone</u>, cloud PHONE MINING</a> cod. dhvd1dkx - <a title="Mintme, PC PHONE MINING" target="_blank" href="https://www.coinimp.com/invite/86d61388-18f9-4f8b-8561-8962c67e7166">Mintme, PC PHONE MINING</a> <hr><strong>Exchanges:</strong> <br> <a title="Coinbase.com" target="_blank" href="http://coinbase.com/join/occhip_8?src=android-link">Coinbase.com</a> - <a title="Stex.com" target="_blank" href="https://stex.com/?ref=27877494">Stex.com</a> - <a title="Probit.com" target="_blank" href="https://www.probit.com/r/46858290">Probit.com</a> <hr><strong>Donations:</strong> <br> <a title="Done crypto" target="_blank" href="https://commerce.coinbase.com/checkout/140e9bb6-c4ef-4156-92cf-9c87a88fd259">Done crypto</a> </h3><br><br>

Comments System

Disqus Shortname

Disqus Shortname

designcart
Powered by Blogger.