Post-quantum privacy-preserving L1 chain
Abelian ABEL
Abelian is assessed as a PQ-native production Layer 1 for native ABEL. Public code and official documentation consistently indicate mandatory lattice-based ownership, transaction, commitment, and privacy mechanisms, with no identified classical native ownership namespace or legacy native balance pool. Native ECC-to-PQC migration is therefore complete by design within this scope, and the PoW L1 has no applicable validator-signature layer. Confidence is Medium because current mainnet artifacts are not supplied and the project-specific quantum-critical constructions lack an evidenced independent cryptographic review. QDay Layer 2, bridges, wrappers, and non-native ABEL representations are not covered.
Category breakdown
QRI Factors
Critical Quantum Blockers
- Production protection materially depends on project-specific lattice authorization, commitment, and privacy constructions for which no in-scope independent cryptographic audit or serious public cryptographic review is supplied.
- The cryptographic soundness and current production use of every quantum-critical bespoke path are not independently established by the supplied mainnet artifacts or review record.
Key Risks
- A structural flaw in the project-specific lattice authorization, commitment, ring-signature, or zero-knowledge constructions could compromise ownership, supply binding, or privacy across the native L1.
- The supplied record does not independently demonstrate through current mainnet artifacts that every production transaction variant uses only the documented post-quantum paths.
- The announced node and wallet audit does not establish independent cryptographic soundness for the bespoke quantum-critical constructions.
- QDay Layer 2, bridges, and wrapped ABEL may have different cryptographic dependencies and require separate assessment; their quantum status is unresolved rather than presumed vulnerable.
Assurance Notes
- Public repositories and official documentation consistently describe a production PQ-native UTXO chain using lattice-based authorization, commitments, linkable ring signatures, and zero-knowledge proofs.
- No reproducible mainnet transaction or block artifact is supplied to independently demonstrate the cryptographic path used by current production transactions.
- A 2024 Hacken audit was announced for full-node and wallet source code, but its report is not supplied and no independent cryptographic review of pqringct/pqringctx, lattice commitments, or range proofs is evidenced.
- The deployed constructions are described as inspired by CRYSTALS-Dilithium and CRYSTALS-Kyber and based on LWE/Ring-LWE, not as direct standardized instantiations for all critical functions.
- Open-source code supports review, but deterministic-build attestations, formal parameter-agility documentation, specialized implementation-hardening analysis, and formal resource benchmarks are not supplied.
- No formal quantum-specific incident-response process is evidenced. This is an assurance caveat rather than a current quantum-readiness deduction.
- QDay Layer 2, bridges, wrappers, and non-native ABEL representations require separate evaluation and must not inherit this native-L1 conclusion.
Non-Scoring Caveats
- The 2024 audit is stale and scope-mismatched for the bespoke quantum-critical constructions.
- No deterministic or reproducible build attestation is supplied.
- No formal quantum-specific incident-response playbook is evidenced.
- No formal performance and resource-impact benchmark is supplied.
- No exchange, custodian, hardware-wallet, or HSM attestation is supplied; this does not reduce native migration credit because no classical native ownership path is evidenced.
- QDay Layer 2, external bridges, and wrapped ABEL are outside scope. Their security cannot be inferred from this report, and no bridge cap is applied without canonical evidence of a vulnerable bridge.
Evidence record
Claims and Caveats
Security Assessment & Evidence Preparedness
Public cryptographic inventory and quantum threat model
Claim: Public materials identify lattice-based spend authorization, linkable ring signatures, commitments, zero-knowledge proofs, LWE/Ring-LWE assumptions, a UTXO model, and PoW consensus as the principal quantum-relevant L1 mechanisms.
Coverage basis: PQ-native native-L1 protocol documentation and public repository inventory.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: The inventory is distributed across documentation and repositories rather than presented as one exhaustive formal threat model.
External bridges and QDay Layer 2 are outside scope.
Security Assessment & Evidence Preparedness
Public evidence record supporting the assessment
Claim: Open-source node, wallet, SDK, and pqringct/pqringctx repositories, together with official technical documentation, provide a public evidence record for the PQ-native architecture.
Coverage basis: Public source code and mutually consistent official documentation.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: No reproducible mainnet transaction example or complete audit report is supplied.
The record supports architecture and implementation availability more strongly than exact current deployment verification.
Production Cryptographic Protection
Spend authorization / transaction signatures
Claim: Native ABEL spend authorization is implemented through lattice-based post-quantum mechanisms, with no identified classical ECC, BLS, Schnorr, or EdDSA native spend path.
Coverage basis: Consistent production-design documentation and open-source node, wallet, and pqringct implementations.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No current mainnet transaction artifact or in-scope independent cryptographic review establishes every spend path and the soundness of its bespoke construction.
Assurance: Public code and consistent primary documentation support full implementation status, while independent verification remains incomplete.
No classical native fallback is identified.
Production Cryptographic Protection
Account, address, public-key exposure, and key derivation
Claim: The native address and key architecture uses lattice-based ownership and does not identify a classical public-key namespace vulnerable to quantum key recovery.
Coverage basis: PQ-native UTXO ownership and privacy-address design.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: A dedicated address-format and key-derivation specification was not separately supplied.
This finding applies only to native ABEL on the Abelian L1.
Production Cryptographic Protection
Consensus-critical authentication
Claim: The Abelian L1 uses PoW and has no identified validator set, validator signature, VRF, threshold signature, or signed-finality layer.
Coverage basis: Architectural applicability for the PoW UTXO L1.
Implementation score: 0 · Evidence confidence: High
Issue classification: none · Score treatment: not applicable
Assurance: This does not assess QDay Layer 2 PoS consensus.
Excluded from applicable-layer normalization.
Production Cryptographic Protection
State-integrity and data-availability mechanisms
Claim: Native state and supply binding use lattice-based commitments and related proof mechanisms, with no identified pairing, KZG, or classical discrete-log commitment dependency.
Coverage basis: Documented lattice-based commitments, UTXO state, and pqringct implementation.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: The binding and implementation security of the project-specific lattice commitments and proofs lack evidenced independent cryptographic review.
Assurance: The announced node and wallet audit does not establish cryptographic soundness for this layer.
No quantum-vulnerable pairing dependency is identified in the native-L1 record.
Production Cryptographic Protection
Privacy and proof layers
Claim: Abelian's privacy layer uses lattice-based linkable ring signatures, commitments, and zero-knowledge proofs intended to provide post-quantum confidential transactions.
Coverage basis: Official documentation and open-source pqringct/pqringctx implementations.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No independent cryptographic audit or serious public review is supplied for the bespoke privacy proofs and linkable ring-signature construction.
Assurance: Public implementation supports deployment status but not independent validation of proof soundness, privacy security, or note-encryption details.
A flaw could cause privacy, forgery, or state-binding failure.
Production Cryptographic Protection
P2P transport, node identity, and peer authentication
Claim: No P2P identity or transport mechanism is evidenced as authorizing native spending, certifying finality, controlling bridge settlement, or binding native ownership.
Coverage basis: PoW architecture isolates native asset authorization in lattice-based transaction mechanisms.
Implementation score: 1 · Evidence confidence: Low
Issue classification: operational/product caveat · Score treatment: note-only
Assurance: The dossier does not provide a detailed P2P cryptographic inventory, so this architectural inference has Low confidence.
General transport, eclipse, and denial-of-service risks are outside QRI unless they enable a quantum-critical compromise.
Production Cryptographic Protection
Critical wallet, custody, HSM, signer, and hardware-wallet workflows
Claim: Official open-source wallets and SDKs support the native lattice-based transaction path, and no classical native key format is identified.
Coverage basis: Public abewallet, SDK, node, and PQ transaction repositories.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: The announced 2024 audit covered wallets, but its report, hardware-wallet assessment, HSM review, and custody attestations are not supplied.
Institutional and off-chain account security are outside the native protocol control path.
Migration Status & Value-at-Risk
Percentage of economically relevant value-at-risk protected
Claim: Native ABEL value is protected by the PQ-native ownership model, with no identified legacy classical native ownership pool.
Coverage basis: PQ-native complete-by-design coverage for the native asset only.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: Coverage is inferred from protocol design rather than measured through address-level analytics, which is appropriate for the native privacy-preserving scope.
Wrapped and bridged representations are excluded and are not counted as protected by this finding.
Migration Status & Value-at-Risk
Critical wallets migrated, protected, or inherently PQ-native
Claim: Native treasuries, exchanges, custodians, foundations, and other holders must use the same PQ-native on-chain authorization path as all other native ABEL holders.
Coverage basis: Protocol-enforced native ownership rather than institution-specific migration attestations.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: Off-chain exchange account controls and non-native wrapped assets are not assessed.
Missing exchange or custody attestations are non-scoring for the native protocol path.
Migration Status & Value-at-Risk
Legacy vulnerable pools identified, measurable, deprecated, migrated, frozen, or absent by design
Claim: No legacy classical native account, UTXO, contract, or balance pool is identified.
Coverage basis: Native launch architecture and absence of a documented classical ownership namespace.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: A dedicated genesis and exhaustive address-format proof was not supplied.
External representations are separate dependencies, not native legacy balances.
Migration Mechanism, Governance & Ecosystem Coordination
Public migration or protection roadmap
Claim: An ECC-to-PQC migration roadmap is unnecessary for native ABEL because the evaluated ownership system is PQ-native from launch.
Coverage basis: Complete-by-design native protection rather than a future migration sequence.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: Future PQ-to-PQ upgrades are not current ECC-to-PQC migration requirements.
This does not grant roadmap credit to QDay Layer 2 or bridges.
Migration Mechanism, Governance & Ecosystem Coordination
Migration accessibility and defaults
Claim: Native wallet and transaction tooling uses the PQ path by default because no classical native ownership or signing alternative is identified.
Coverage basis: Protocol-enforced PQ-native addresses, wallets, SDKs, and transactions.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: Third-party wallet, hardware-wallet, and institutional custody integration coverage is not documented.
Missing migration prompts are not a deduction because no native legacy path is identified.
Migration Mechanism, Governance & Ecosystem Coordination
Migration enforcement and ecosystem coordination
Claim: The native L1 protocol prevents creation or use of a classical native ownership fallback.
Coverage basis: Protocol-level enforcement through the absence of a documented classical address, script, or account namespace.
Implementation score: 1 · Evidence confidence: Medium
Issue classification: none · Score treatment: not applicable
Assurance: Coordination with bridges, wrappers, and QDay Layer 2 is not evidenced and is outside the evaluated scope.
An evidenced unrestricted bridge would require reassessment.
Migration Mechanism, Governance & Ecosystem Coordination
Emergency disclosure, incident response, or quantum governance
Claim: No formal quantum-specific emergency disclosure, incident-response, or governance process is supplied.
Coverage basis: Current native protection does not depend on an emergency ECC-to-PQC migration process.
Implementation score: 1 · Evidence confidence: Low
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: A documented process would improve operational assurance for future cryptographic discoveries.
Treatment would change if a current vulnerable fallback were identified.
Algorithm & Implementation Assurance
Standardized, standards-track, or broadly reviewed PQC algorithm selection
Claim: Abelian uses LWE and Ring-LWE assumptions and constructions inspired by CRYSTALS-Dilithium and CRYSTALS-Kyber, but direct standardized use is not established for its ring-confidential transaction functions.
Coverage basis: Standards-inspired lattice assumptions constrained by project-specific authorization and privacy constructions.
Implementation score: 0.25 · Evidence confidence: Medium
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: The design materially relies on bespoke or adapted constructions without evidenced serious independent cryptographic review.
Assurance: NIST inspiration and standard hardness assumptions do not establish equivalence to standardized, broadly reviewed constructions.
Public-design credit is supported, but high algorithm-assurance credit is not.
Algorithm & Implementation Assurance
Independent cryptographic and implementation audit
Claim: A 2024 Hacken audit of full-node and wallet source code is announced, but no supplied report demonstrates independent cryptographic review of the quantum-critical constructions.
Coverage basis: Reported general implementation review with limited demonstrated relevance to custom cryptography.
Implementation score: 0.25 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No in-scope independent cryptographic audit is evidenced for pqringct/pqringctx, linkable ring signatures, commitments, or zero-knowledge range proofs.
Assurance: The announcement supports limited credit for independent review, but scope, findings, and cryptographic coverage are unavailable.
Audit age alone is not score-reducing.
Algorithm & Implementation Assurance
Open-source, reproducible implementation
Claim: Core node, wallet, SDK, and post-quantum transaction implementations are publicly available as open-source repositories.
Coverage basis: Official GitHub organization containing the relevant production components.
Implementation score: 1 · Evidence confidence: High
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: Source availability is directly evidenced, but deterministic-build and binary-to-source reproduction results are not supplied.
Open source enables review but does not itself prove cryptographic soundness.
Algorithm & Implementation Assurance
Parameter agility and future upgrade path
Claim: No documented parameter-agility or production PQ-to-PQ upgrade procedure is supplied.
Coverage basis: Current production evaluation does not depend on a future PQ algorithm transition.
Implementation score: 1 · Evidence confidence: Low
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: Documented versioning, activation, and parameter-replacement procedures would improve assurance.
This treatment does not assert that a formal agility process exists.
Algorithm & Implementation Assurance
Stateful-signature, side-channel, fault-injection, HSM, and custody implementation risks
Claim: The dossier does not document specialized side-channel, fault-injection, sampling, secret-state, hardware-wallet, HSM, or custody controls for the lattice-based implementations.
Coverage basis: Public production code and an announced general audit provide limited indirect evidence, but specialized implementation-risk analysis is absent.
Implementation score: 0.25 · Evidence confidence: Low
Issue classification: assurance-only caveat · Score treatment: score-reducing
Assurance: The audit may have considered general implementation issues, but its report and specialized cryptographic findings are unavailable.
Stateful-signature reuse is not specifically indicated; broader implementation-hardening controls remain applicable.
Algorithm & Implementation Assurance
Performance and resource-impact analysis
Claim: No formal performance or resource-impact analysis for transaction size, proof verification, block validation, storage, or wallet operation is supplied.
Coverage basis: The mandatory PQ path is represented as active in production, with no evidence that resource costs prevent safe use.
Implementation score: 1 · Evidence confidence: Low
Issue classification: assurance-only caveat · Score treatment: confidence-only
Assurance: Independent measurements of proof size, verification time, memory, bandwidth, and archival growth would improve operational assurance.
This does not assert that comprehensive benchmarks exist.
Report metadata