blockchain network
Avalanche AVAX
Avalanche relies entirely on classical cryptography across all critical layers. Spend authorization uses ECDSA (secp256k1), consensus and Avalanche Warp Messaging (AWM) use BLS12-381, and the Avalanche Bridge relies on ECDSA/TLS. The C-Chain's EVM compatibility means public keys are permanently exposed after the first transaction, creating a growing pool of long-exposure quantum-vulnerable value. While the fast finality of the network reduces the short-exposure attack window, there is currently no formal PQC migration roadmap, prototype, or deployed mitigation. No public cryptographic inventory or quantum threat model exists. The project is classified as Stage 1 (Quantum Risk Assessed) only because the threat is acknowledged in broader ecosystem discussions, but no meaningful production protection or migration mechanism is in place.
Category breakdown
QRI Factors
Critical Quantum Blockers
- Active production spend authorization remains entirely ECC (secp256k1 ECDSA) with no PQC or hybrid-PQC path.
- Consensus authentication relies on BLS12-381, which is quantum-vulnerable.
- No public cryptographic inventory, quantum threat model, or migration roadmap exists.
- Material long-exposure quantum-vulnerable value exists on C-Chain (transacted EOAs) with no migration, freeze, or recovery path.
Key Risks
- Quantum-enabled theft of long-exposure C-Chain EOAs and reused addresses.
- Quantum-enabled forgery of transactions via ECDSA key recovery.
- Quantum-enabled consensus compromise via BLS12-381 validator signature forgery.
- Quantum-enabled bridge compromise via classical signer set or verification layer.
- No migration path for dormant or unmigratable quantum-vulnerable value.
Assurance Notes
- General security audits (Halborn, OpenZeppelin) exist for bridge and smart contracts but do not cover quantum-specific risks or core protocol cryptography.
- No independent audit of post-quantum readiness, cryptographic inventory, or migration planning was identified.
- Deep code inspection of avalanchego consensus and P2P cryptographic layers was not performed; specific BLS/ECDSA usage in validator authentication remains partially inferred from ecosystem knowledge rather than direct source verification in this dossier.
Non-Scoring Caveats
- Fast finality reduces short-exposure attack window for in-flight transactions but does not mitigate long-exposure risks.
- Bridge audits cover classical security but not quantum-specific signer or verification risks.
- Lack of formal quantum-specific incident-response playbook or performance benchmark.
Evidence record
Claims and Caveats
Security Assessment & Evidence Preparedness
Public cryptographic inventory and quantum threat model
Claim: No public cryptographic inventory or quantum threat model exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No public cryptographic inventory or quantum threat model.
Assurance: No evidence of formal risk assessment or inventory.
Project has not published a quantum-specific risk assessment or cryptographic inventory.
Security Assessment & Evidence Preparedness
Public evidence record supporting the assessment
Claim: No public evidence record supporting quantum risk assessment exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No public evidence record for quantum risk.
Assurance: No reproducible analytics, code references, or transaction examples for quantum risk.
No public evidence record identified.
Production Cryptographic Protection
Spend authorization / transaction signatures
Claim: Avalanche VM uses secp256k1 ECDSA for blockchain signatures.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: High
Issue classification: quantum-critical vulnerability · Score treatment: score-reducing
Quantum blocker: Active production spend authorization remains entirely ECC (secp256k1 ECDSA).
Assurance: Official docs confirm ECDSA usage; no PQC or hybrid path.
Primary official docs reference; limits to VM signatures.
Production Cryptographic Protection
Account, address, public-key exposure, and key derivation
Claim: C-Chain EVM compatibility means public keys are permanently exposed after the first transaction.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: High
Issue classification: quantum-critical vulnerability · Score treatment: score-reducing
Quantum blocker: Material long-exposure quantum-vulnerable value exists with no migration path.
Assurance: EVM account model inherently exposes public keys post-transaction.
Long-exposure risk for transacted EOAs and reused addresses.
Production Cryptographic Protection
Consensus-critical authentication
Claim: Consensus and Avalanche Warp Messaging use BLS12-381.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Medium
Issue classification: quantum-critical vulnerability · Score treatment: score-reducing
Quantum blocker: Consensus authentication remains quantum-vulnerable (BLS12-381).
Assurance: BLS12-381 usage inferred from ecosystem knowledge; deep code inspection not performed.
Validator signatures and AWM rely on BLS12-381.
Production Cryptographic Protection
State-integrity and data-availability mechanisms
Claim: No evidence of quantum-safe state-integrity or data-availability mechanisms.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No evidence of quantum-safe commitments or state-binding mechanisms.
State-integrity mechanisms not evaluated for quantum safety.
Production Cryptographic Protection
Privacy and proof layers
Claim: No privacy or proof layer identified.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: none · Score treatment: not applicable
No privacy-specific subfactors apply.
Production Cryptographic Protection
P2P transport, node identity, and peer authentication
Claim: No evidence of PQC or hybrid-PQC P2P identity or transport.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: P2P identity cryptography not evaluated in detail.
P2P node identity and transport not verified for quantum safety.
Production Cryptographic Protection
Critical wallet, custody, HSM, signer, and hardware-wallet workflows
Claim: No evidence of PQC or hybrid-PQC wallet or custody workflows.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No wallet or custody workflow supports PQC.
Critical wallet and custody workflows remain classical.
Migration Status & Value-at-Risk
Percentage of economically relevant value-at-risk protected
Claim: No migration or protection of value-at-risk exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: High
Issue classification: quantum-critical vulnerability · Score treatment: score-reducing
Quantum blocker: Material long-exposure quantum-vulnerable value exists with no migration path.
Assurance: No migration coverage or protection for native or token value-at-risk.
No migration or protection mechanisms identified.
Migration Status & Value-at-Risk
Critical wallets migrated, protected, or inherently PQ-native
Claim: No evidence of critical wallet migration.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No evidence of treasury, exchange, or custodian migration.
Critical wallets remain quantum-vulnerable.
Migration Status & Value-at-Risk
Legacy vulnerable pools identified, measurable, deprecated, migrated, frozen, or absent by design
Claim: No evidence of legacy vulnerable pool identification or mitigation.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Low
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No policy or mechanism for unmigratable vulnerable value.
Legacy vulnerable pools not identified or mitigated.
Migration Mechanism, Governance & Ecosystem Coordination
Public migration or protection roadmap
Claim: No public migration or protection roadmap exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: cap-applying
Quantum blocker: No public migration roadmap.
Assurance: No roadmap, proposal, or public plan for PQC migration.
No public roadmap identified.
Migration Mechanism, Governance & Ecosystem Coordination
Migration accessibility and defaults
Claim: No PQC or hybrid-PQC account creation, wallet tooling, or migration prompts exist.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No migration accessibility or defaults.
No PQC account creation or migration tooling.
Migration Mechanism, Governance & Ecosystem Coordination
Migration enforcement and ecosystem coordination
Claim: No enforcement or coordination mechanisms for migration exist.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No enforcement or coordination for migration.
No deprecation, freeze, or mandatory migration mechanisms.
Migration Mechanism, Governance & Ecosystem Coordination
Emergency disclosure, incident response, or quantum governance
Claim: No emergency disclosure or incident-response process for quantum vulnerabilities exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: assurance-only caveat · Score treatment: note-only
Assurance: No quantum-specific IR playbook or governance process.
General security audits exist but not quantum-specific.
Algorithm & Implementation Assurance
Standardized, standards-track, or broadly reviewed PQC algorithm selection
Claim: No PQC or hybrid-PQC algorithm selection exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No NIST-standardized or broadly reviewed PQC algorithm selected.
No PQC algorithm selection identified.
Algorithm & Implementation Assurance
Independent cryptographic and implementation audit
Claim: General security audits exist but do not cover quantum-specific risks.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Medium
Issue classification: assurance-only caveat · Score treatment: note-only
Assurance: Audits cover classical security, not quantum-specific risks.
Halborn and OpenZeppelin audits exist but are scope-mismatched for quantum readiness.
Algorithm & Implementation Assurance
Open-source, reproducible implementation
Claim: AvalancheGo is open-source but no PQC implementation exists.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: Medium
Issue classification: assurance-only caveat · Score treatment: note-only
Assurance: Open-source code exists but no PQC implementation to reproduce.
AvalancheGo is open-source; no PQC code to evaluate.
Algorithm & Implementation Assurance
Parameter agility and future upgrade path
Claim: No evidence of parameter agility or future upgrade path for PQC.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No documented parameter agility or upgrade path for PQC.
No evidence of future upgrade path for PQC.
Algorithm & Implementation Assurance
Stateful-signature, side-channel, fault-injection, HSM, and custody implementation risks
Claim: No evidence of stateful-signature safety, side-channel, or custody implementation risk controls for PQC.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: quantum-critical uncertainty · Score treatment: score-reducing
Assurance: No PQC implementation risk controls identified.
No PQC implementation to evaluate for risk controls.
Algorithm & Implementation Assurance
Performance and resource-impact analysis
Claim: No evidence of performance or resource-impact analysis for PQC.
Coverage basis: Non-native dependency
Implementation score: 0 · Evidence confidence: None
Issue classification: assurance-only caveat · Score treatment: note-only
Assurance: No PQC performance or resource analysis exists.
No performance benchmark for PQC.
Report metadata