blockchain network

Avalanche AVAX

Avalanche relies entirely on classical cryptography across all critical layers. Spend authorization uses ECDSA (secp256k1), consensus and Avalanche Warp Messaging (AWM) use BLS12-381, and the Avalanche Bridge relies on ECDSA/TLS. The C-Chain's EVM compatibility means public keys are permanently exposed after the first transaction, creating a growing pool of long-exposure quantum-vulnerable value. While the fast finality of the network reduces the short-exposure attack window, there is currently no formal PQC migration roadmap, prototype, or deployed mitigation. No public cryptographic inventory or quantum threat model exists. The project is classified as Stage 1 (Quantum Risk Assessed) only because the threat is acknowledged in broader ecosystem discussions, but no meaningful production protection or migration mechanism is in place.

Roadmap OnlyNot Assessed
Stage Quantum Risk Assessed
Confidence Low
Urgency [Monitor for Updates]
Review Status Draft
Evaluated 2026-08-19
Scope Native asset (AVAX), consensus, P2P, bridge, and C-Chain EVM layer
AI-generated report. This report was produced by the evaluator and synthesis pipeline. Review status: draft.

Category breakdown

QRI Factors

Algorithm & Implementation Assurance 0 / 20
Migration Mechanism, Governance & Ecosystem Coordination 0 / 15
Migration Status & Value-at-Risk 0 / 25
Production Cryptographic Protection 0 / 35
Security Assessment & Evidence Preparedness 0 / 5

Critical Quantum Blockers

  • Active production spend authorization remains entirely ECC (secp256k1 ECDSA) with no PQC or hybrid-PQC path.
  • Consensus authentication relies on BLS12-381, which is quantum-vulnerable.
  • No public cryptographic inventory, quantum threat model, or migration roadmap exists.
  • Material long-exposure quantum-vulnerable value exists on C-Chain (transacted EOAs) with no migration, freeze, or recovery path.

Key Risks

  • Quantum-enabled theft of long-exposure C-Chain EOAs and reused addresses.
  • Quantum-enabled forgery of transactions via ECDSA key recovery.
  • Quantum-enabled consensus compromise via BLS12-381 validator signature forgery.
  • Quantum-enabled bridge compromise via classical signer set or verification layer.
  • No migration path for dormant or unmigratable quantum-vulnerable value.

Assurance Notes

  • General security audits (Halborn, OpenZeppelin) exist for bridge and smart contracts but do not cover quantum-specific risks or core protocol cryptography.
  • No independent audit of post-quantum readiness, cryptographic inventory, or migration planning was identified.
  • Deep code inspection of avalanchego consensus and P2P cryptographic layers was not performed; specific BLS/ECDSA usage in validator authentication remains partially inferred from ecosystem knowledge rather than direct source verification in this dossier.

Non-Scoring Caveats

  • Fast finality reduces short-exposure attack window for in-flight transactions but does not mitigate long-exposure risks.
  • Bridge audits cover classical security but not quantum-specific signer or verification risks.
  • Lack of formal quantum-specific incident-response playbook or performance benchmark.

Evidence record

Claims and Caveats

Security Assessment & Evidence Preparedness

Public cryptographic inventory and quantum threat model

Claim: No public cryptographic inventory or quantum threat model exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: cap-applying

Quantum blocker: No public cryptographic inventory or quantum threat model.

Assurance: No evidence of formal risk assessment or inventory.

Project has not published a quantum-specific risk assessment or cryptographic inventory.

Security Assessment & Evidence Preparedness

Public evidence record supporting the assessment

Claim: No public evidence record supporting quantum risk assessment exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: cap-applying

Quantum blocker: No public evidence record for quantum risk.

Assurance: No reproducible analytics, code references, or transaction examples for quantum risk.

No public evidence record identified.

Production Cryptographic Protection

Spend authorization / transaction signatures

Claim: Avalanche VM uses secp256k1 ECDSA for blockchain signatures.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: High

Issue classification: quantum-critical vulnerability · Score treatment: score-reducing

Quantum blocker: Active production spend authorization remains entirely ECC (secp256k1 ECDSA).

Assurance: Official docs confirm ECDSA usage; no PQC or hybrid path.

Primary official docs reference; limits to VM signatures.

Production Cryptographic Protection

Account, address, public-key exposure, and key derivation

Claim: C-Chain EVM compatibility means public keys are permanently exposed after the first transaction.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: High

Issue classification: quantum-critical vulnerability · Score treatment: score-reducing

Quantum blocker: Material long-exposure quantum-vulnerable value exists with no migration path.

Assurance: EVM account model inherently exposes public keys post-transaction.

Long-exposure risk for transacted EOAs and reused addresses.

Production Cryptographic Protection

Consensus-critical authentication

Claim: Consensus and Avalanche Warp Messaging use BLS12-381.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Medium

Issue classification: quantum-critical vulnerability · Score treatment: score-reducing

Quantum blocker: Consensus authentication remains quantum-vulnerable (BLS12-381).

Assurance: BLS12-381 usage inferred from ecosystem knowledge; deep code inspection not performed.

Validator signatures and AWM rely on BLS12-381.

Production Cryptographic Protection

State-integrity and data-availability mechanisms

Claim: No evidence of quantum-safe state-integrity or data-availability mechanisms.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Low

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No evidence of quantum-safe commitments or state-binding mechanisms.

State-integrity mechanisms not evaluated for quantum safety.

Production Cryptographic Protection

Privacy and proof layers

Claim: No privacy or proof layer identified.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: none · Score treatment: not applicable

No privacy-specific subfactors apply.

Production Cryptographic Protection

P2P transport, node identity, and peer authentication

Claim: No evidence of PQC or hybrid-PQC P2P identity or transport.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Low

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: P2P identity cryptography not evaluated in detail.

P2P node identity and transport not verified for quantum safety.

Production Cryptographic Protection

Critical wallet, custody, HSM, signer, and hardware-wallet workflows

Claim: No evidence of PQC or hybrid-PQC wallet or custody workflows.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Low

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No wallet or custody workflow supports PQC.

Critical wallet and custody workflows remain classical.

Migration Status & Value-at-Risk

Percentage of economically relevant value-at-risk protected

Claim: No migration or protection of value-at-risk exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: High

Issue classification: quantum-critical vulnerability · Score treatment: score-reducing

Quantum blocker: Material long-exposure quantum-vulnerable value exists with no migration path.

Assurance: No migration coverage or protection for native or token value-at-risk.

No migration or protection mechanisms identified.

Migration Status & Value-at-Risk

Critical wallets migrated, protected, or inherently PQ-native

Claim: No evidence of critical wallet migration.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Low

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No evidence of treasury, exchange, or custodian migration.

Critical wallets remain quantum-vulnerable.

Migration Status & Value-at-Risk

Legacy vulnerable pools identified, measurable, deprecated, migrated, frozen, or absent by design

Claim: No evidence of legacy vulnerable pool identification or mitigation.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Low

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No policy or mechanism for unmigratable vulnerable value.

Legacy vulnerable pools not identified or mitigated.

Migration Mechanism, Governance & Ecosystem Coordination

Public migration or protection roadmap

Claim: No public migration or protection roadmap exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: cap-applying

Quantum blocker: No public migration roadmap.

Assurance: No roadmap, proposal, or public plan for PQC migration.

No public roadmap identified.

Migration Mechanism, Governance & Ecosystem Coordination

Migration accessibility and defaults

Claim: No PQC or hybrid-PQC account creation, wallet tooling, or migration prompts exist.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No migration accessibility or defaults.

No PQC account creation or migration tooling.

Migration Mechanism, Governance & Ecosystem Coordination

Migration enforcement and ecosystem coordination

Claim: No enforcement or coordination mechanisms for migration exist.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No enforcement or coordination for migration.

No deprecation, freeze, or mandatory migration mechanisms.

Migration Mechanism, Governance & Ecosystem Coordination

Emergency disclosure, incident response, or quantum governance

Claim: No emergency disclosure or incident-response process for quantum vulnerabilities exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: assurance-only caveat · Score treatment: note-only

Assurance: No quantum-specific IR playbook or governance process.

General security audits exist but not quantum-specific.

Algorithm & Implementation Assurance

Standardized, standards-track, or broadly reviewed PQC algorithm selection

Claim: No PQC or hybrid-PQC algorithm selection exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No NIST-standardized or broadly reviewed PQC algorithm selected.

No PQC algorithm selection identified.

Algorithm & Implementation Assurance

Independent cryptographic and implementation audit

Claim: General security audits exist but do not cover quantum-specific risks.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Medium

Issue classification: assurance-only caveat · Score treatment: note-only

Assurance: Audits cover classical security, not quantum-specific risks.

Halborn and OpenZeppelin audits exist but are scope-mismatched for quantum readiness.

Algorithm & Implementation Assurance

Open-source, reproducible implementation

Claim: AvalancheGo is open-source but no PQC implementation exists.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: Medium

Issue classification: assurance-only caveat · Score treatment: note-only

Assurance: Open-source code exists but no PQC implementation to reproduce.

AvalancheGo is open-source; no PQC code to evaluate.

Algorithm & Implementation Assurance

Parameter agility and future upgrade path

Claim: No evidence of parameter agility or future upgrade path for PQC.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No documented parameter agility or upgrade path for PQC.

No evidence of future upgrade path for PQC.

Algorithm & Implementation Assurance

Stateful-signature, side-channel, fault-injection, HSM, and custody implementation risks

Claim: No evidence of stateful-signature safety, side-channel, or custody implementation risk controls for PQC.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: quantum-critical uncertainty · Score treatment: score-reducing

Assurance: No PQC implementation risk controls identified.

No PQC implementation to evaluate for risk controls.

Algorithm & Implementation Assurance

Performance and resource-impact analysis

Claim: No evidence of performance or resource-impact analysis for PQC.

Coverage basis: Non-native dependency

Implementation score: 0 · Evidence confidence: None

Issue classification: assurance-only caveat · Score treatment: note-only

Assurance: No PQC performance or resource analysis exists.

No performance benchmark for PQC.

Report metadata

Generation Details