Traduzione automatica dell'originale inglese. English

Quantum-Resistant Cryptocurrency List 2026: Which Coins Actually Sign With Post-Quantum Keys

Most “quantum-resistant” lists grade marketing. This one grades the signature that moves your coins, checked against each project’s own documentation.

23 blockchains, one rule, primary sources for every row. Reviewed 23 September 2026.

Only five live blockchains authorise ordinary transactions with post-quantum signatures by default: QRL (XMSS, since 2018), Mochimo (WOTS+, since 2018), Abelian (lattice-based, since 2022), Cellframe (CRYSTALS-Dilithium) and SynX (SPHINCS+, since 2026). Algorand and Nervos CKB now offer opt-in post-quantum accounts. Bitcoin, Ethereum, Solana, Cardano, XRP and the rest of the large-cap market still sign with elliptic curves, and several coins on popular “quantum-resistant” lists do not meet the bar at all.

Disclosure: synxcrypto.com is published by the team that builds SynX, which appears in this list. SynX is graded by the same rule as every other chain, and its caveats are listed with it. Editorial policy and corrections.

Rather have it explained? Watch or listen to our Gemini Notebook overview: Quantum-Resistant Crypto Explained (Google sign-in required).

How We Decide Which Cryptocurrencies Are Quantum Resistant

A quantum computer running Shor’s algorithm threatens one thing above all in a blockchain: the signature that proves you own your coins. So the list asks one question of every project: what signs an ordinary user transaction on mainnet today? A project counts as quantum-resistant only if that signature is post-quantum. We record whether it is the default or an opt-in, since when it has been live, and what the project’s own documents say.

Four things do non count, because they leave the owner’s coins signed with elliptic curves:

  • Post-quantum key exchange alone. Kyber (ML-KEM) protects a connection; it does not sign transactions.
  • Post-quantum proofs alone. STARK proofs are hash-based, but they are not the key that moves funds.
  • Roadmaps, testnets and disabled features. Code that is not active on mainnet does not protect anyone yet.
  • A token on another chain. An ERC-20 or BEP-20 token is moved with its host chain’s ECDSA keys, whatever its project says about quantum security.

For the underlying signature families, see what makes a blockchain quantum-resistant and ML-DSA versus SLH-DSA for cryptocurrency.

The Quantum-Resistant Cryptocurrency List, Graded

What signs ordinary user transactions on mainnet, checked 23 September 2026
Progetto Signs user funds with Post-quantum status Live since What to know
QRLXMSS (hash-based, stateful)By defaultJun 2018Reusing a key state voids security. QRL 2.0 (ML-DSA-87) is still on testnet.
MochimoWOTS+ (hash-based, one-time)By defaultJun 2018Every spend moves the balance to a fresh key.
AbelianCustom lattice schemes inspired by Dilithium and KyberBy defaultApr 2022Custom constructions, not the NIST standards verbatim.
CellframeCRYSTALS-Dilithium (Falcon also available)By default, per node documentation2023Default inferred from the node’s documented examples.
SynX (ours)SPHINCS+-SHAKE-128s (hash-based, stateless); Kyber-768 for key encapsulationBy defaultMar 2026Source code closed until the first halving, so independent code review is not yet possible.
AlgorandEd25519 by default; Falcon-1024 accountsOpt-in accounts liveAug 2026 (state proofs since 2022)New accounts still default to Ed25519; consensus keys are classical.
Nervos CKBsecp256k1 by default; SPHINCS+ lock scriptOpt-in accounts live2025Protection requires a new SPHINCS+ address and moving funds.
StarknetECDSA on the STARK curveProofs only—Hash-based STARK proofs; account signatures are elliptic-curve.
EthereumECDSA secp256k1Tabella di marcia—Core post-quantum milestones targeted around 2029; EIPs are drafts.
BitcoinECDSA and Schnorr, secp256k1Proposals in draft—BIP 360 and BIP 361 merged as drafts in 2026; not activated.
AptosEd25519Devnet only—SLH-DSA accounts (AIP-137) accepted; feature switched off on mainnet.
SuiEd25519 and othersTabella di marcia—SLH-DSA vaults targeted for 2026; ML-DSA-65 accounts for 2027.
TezosEd25519, secp256k1, P-256, BLSBuilt in, switched off—ML-DSA-44 “tz5” accounts exist but are disabled on mainnet.
QANplatformECDSA (QANX is an ERC-20/BEP-20 token)Testnet only—No public layer-1 mainnet date announced.
ZcashECDSA, RedJubjub, RedPallasRicerca—ZIP 2005 proposes quantum recoverability, not quantum security.
SolanaEd25519None in the protocol—A third-party, unaudited Winternitz vault program exists.
CardanoEd25519Nessuno—No post-quantum signature proposal in the CIP index.
XRP Ledgersecp256k1 or Ed25519Nessuno—Documentation says there are no immediate plans.
EderaECDSA secp256k1 or Ed25519Nessuno——
A poissr25519, Ed25519 or ECDSANessuno——
LitecoinECDSA secp256k1Nessuno—MWEB’s quantum clause protects supply, not ownership.
MoneroCLSAG ring signatures (elliptic-curve)Nessuno—Security rests on discrete-logarithm assumptions.
IOTAEd25519 (also secp256k1, secp256r1)Regressed—Launched with Winternitz signatures; replaced by Ed25519 in 2021.

Use this table: CSV · JSON · Permanent table link. Licensed CC BY 4.0; the primary source for every row is listed below.

Cryptocurrencies That Are Quantum Resistant by Default

QRL (registro resistente quantistico) has signed every transaction with XMSS, a hash-based scheme, since its mainnet launched in June 2018. XMSS is stateful: each key has a fixed number of one-time signatures, and RFC 8391 warns that if a key state is used twice, “no cryptographic security guarantees remain.” QRL’s next chain, QRL 2.0 (Zond), moves to lattice-based ML-DSA-87 but remains on testnet with audits in progress. More in QRL, XMSS and SPHINCS+ compared.

Mochimo has used WOTS+, a hash-based one-time signature, since June 2018. Because each key signs once, every spend moves the remaining balance to a fresh key; version 3.0 (February 2025) added stable account addresses on top of that.

Abelian launched in April 2022 with lattice-based signatures and linkable ring signatures for private transfers. Its schemes are custom constructions inspired by Dilithium and Kyber rather than the final NIST standards, which matters to anyone who wants standardised cryptography. See lattice-based cryptocurrency.

Cellframe documents CRYSTALS-Dilithium as its signature in node examples, with Falcon also supported, and its backbone mainnet has run since 2023. We rate the “default” with medium confidence because it is inferred from documented examples rather than a formal specification.

SynX, our project, has signed every transaction with SPHINCS+-SHAKE-128s since its mainnet’s first block on 26 March 2026 (development began in September 2025), and uses Kyber-768 (ML-KEM) for key encapsulation. SPHINCS+ is the stateless hash-based scheme NIST standardised as SLH-DSA in FIPS 205, so there is no one-time key state to lose, at the price of 7,856-byte signatures. Its caveat is ours to state: the source code stays closed until the first halving, so the implementation cannot yet be independently reviewed.

Cryptocurrencies With Opt-In Post-Quantum Accounts

Algorand has used Falcon signatures for its state proofs since September 2022, which is why it is often called quantum-secure. Ordinary accounts were not: Algorand’s own May 2026 post says single-signature accounts “are controlled by Ed25519 private keys, so their post-quantum risk is direct.” Native Falcon-1024 accounts arrived with the v5.0.0 upgrade in August 2026. They are opt-in, so holders must move funds to benefit, and consensus keys remain classical.

Nervos CKB defaults to secp256k1, but a SPHINCS+ lock script supporting all twelve FIPS 205 parameter sets is live on mainnet and was audited in December 2025; the community Quantum Purse wallet shipped in January 2026. Protection again requires a new address and a transfer.

On the Roadmap, on Testnet or Switched Off

  • Ethereum: the Ethereum Foundation targets core post-quantum milestones around 2029, with hash-based validator signatures and post-quantum user signatures through account abstraction. The EIPs are drafts. See Ethereum’s post-quantum roadmap and is Ethereum quantum safe.
  • Bitcoin: BIP 360 (merged 11 February 2026) removes Taproot’s exposed key path; BIP 361 (merged 14 April 2026) plans a phased sunset of legacy signatures and requires a post-quantum signature proposal that does not yet exist. Both are drafts. See is Bitcoin quantum resistant.
  • Aptos: AIP-137 (SLH-DSA-SHA2-128s accounts) is accepted, but its on-chain feature flag was off on mainnet and testnet and on only on devnet when we read it.
  • Sui: Mysten Labs targets SLH-DSA vaults for mainnet in 2026 and native ML-DSA-65 accounts for 2027.
  • Tezos: the current protocol already contains ML-DSA-44 accounts (tz5 addresses), “disabled by default on the mainnet”.
  • QANplatform: post-quantum signatures run on its testnet; there is no public layer-1 mainnet, and the QANX token is an ERC-20/BEP-20 moved with ECDSA.
  • Zcash: Orchard and Halo 2 rest on elliptic-curve assumptions. ZIP 2005 proposes “quantum recoverability” and says it “does not by itself make the protocol secure against quantum adversaries.” See is Zcash quantum resistant.

No Post-Quantum Signatures

Solana transactions are Ed25519; the widely reported 2025 “Winternitz vault” is a third-party program whose documentation says “use this program at your own risk”, not a protocol change. Cardano (Ed25519), XRP Ledger (secp256k1 or Ed25519), Edera, A pois E Litecoin have no post-quantum signature in production. Monero’s CLSAG ring signatures rest on elliptic-curve assumptions; its status is tracked in Stato della resistenza quantistica Monero. IOTA is the one that went backwards: it launched with quantum-resistant Winternitz signatures and replaced them with Ed25519 in the 2021 Chrysalis upgrade (see is IOTA quantum resistant).

Coins Wrongly Listed as Quantum Resistant

CoinGecko and CoinMarketCap both run “quantum-resistant” category pages, and many lists copy them. A category is a tag, not an audit. When we checked the listed projects against their own documentation, these did not meet the bar:

  • Zcash (both lists): spends are signed with elliptic curves; its own ZIP 2005 disclaims quantum security.
  • Starknet (both): only its proofs are hash-based; accounts sign with ECDSA on the STARK curve.
  • QANplatform (both): no public mainnet; QANX is an ERC-20/BEP-20 token.
  • Qubic (both): its core repository ships FourQ elliptic-curve code; we found no post-quantum signature (medium confidence).
  • Naoris Protocol (both): NAORIS is an ERC-20/BEP-20 token on Ethereum and BNB Chain; we found no live post-quantum chain.
  • Mind Network (both): its token is ERC-20/BEP-20, and its “quantum-resistant” claim concerns fully homomorphic encryption, not transaction signatures.

Other errors repeat across the web: that Algorand has been fully quantum-secure since 2022 (only its state proofs were), that QRL has already moved to Dilithium (its mainnet is still XMSS), that Aptos launched post-quantum accounts (switched off on mainnet), and that Bitcoin adopted BIP 360 (a draft). QRL, Abelian and Cellframe meet the bar on both trackers’ lists, Mochimo on CoinMarketCap’s, and Algorand and Nervos as opt-in. We have not yet assessed the remaining sixteen projects on those pages, and will add them as we do.

How to Check Whether Any Cryptocurrency Is Quantum Resistant

  1. Find the signature that moves ordinary funds on mainnet. Look for the default account or address type in the project’s documentation, not its marketing.
  2. Ask whether it is the default. If post-quantum accounts are opt-in, your coins are protected only after you move them.
  3. Check it is live. Testnets, accepted proposals and disabled feature flags protect nothing yet.
  4. Check what the post-quantum part does. Key exchange (Kyber/ML-KEM), proofs (STARKs) and encryption (FHE) are not signatures.
  5. Check where the token lives. A token on Ethereum or BNB Chain is moved with that chain’s ECDSA keys.
  6. Check whether the code can be inspected and has been audited. This is where SynX, today, falls short of its peers.

For how close the threat is, see when will quantum computers break Bitcoin and the maintained table of how many qubits it takes to break secp256k1. For a deeper look at how chains prove a from-genesis claim, see which cryptocurrencies are quantum-resistant from genesis.

The list, explained aloud: our Gemini Notebook overview of quantum-resistant crypto (Google sign-in required).

Sources

Frequently asked questions

Quali criptovalute sono resistenti ai quanti?
As of September 2026, five live blockchains authorise ordinary transactions with post-quantum signatures by default: QRL (XMSS, since 2018), Mochimo (WOTS+, since 2018), Abelian (lattice-based, since 2022), Cellframe (CRYSTALS-Dilithium) and SynX (SPHINCS+, since 2026). Algorand and Nervos CKB offer opt-in post-quantum accounts. Bitcoin, Ethereum, Solana, Cardano, XRP and most other large coins still sign with elliptic curves.
What is the most quantum-resistant cryptocurrency?
No chain is proven secure forever, but hash-based signatures rest on the most conservative assumption: only the security of a hash function. QRL (XMSS), Mochimo (WOTS+) and SynX (SPHINCS+) use them by default. XMSS and WOTS+ are stateful or one-time, so key reuse is dangerous; SPHINCS+ is stateless but has larger signatures. Abelian and Cellframe use lattice schemes, which are smaller but rest on newer mathematical assumptions. Disclosure: this list is published by the team that builds SynX.
Bitcoin è resistente ai quanti?
No. Bitcoin signs with ECDSA and Schnorr over secp256k1, which Shor's algorithm can break on a large error-corrected quantum computer. BIP 360 and BIP 361, the leading proposals, were merged into the Bitcoin Improvement Proposals repository in 2026 but are drafts; merging is not activation.
Is Ethereum quantum resistant?
Not yet. Ordinary Ethereum accounts sign with ECDSA over secp256k1. The Ethereum Foundation targets core post-quantum milestones for around 2029, using hash-based signatures for validators and post-quantum signatures for users through account abstraction; the relevant EIPs are drafts.
Why do CoinGecko and CoinMarketCap list Zcash and Starknet as quantum-resistant?
Category pages collect projects associated with a topic; being listed is not a verification. Zcash spends are authorised with elliptic-curve signatures, and its own ZIP 2005 says that proposal "does not by itself make the protocol secure against quantum adversaries." Starknet's STARK proofs are hash-based, but the signatures that move funds use ECDSA on the STARK curve.

SynergyX I fatti in breve: punti dati verificati dall'intelligenza artificiale

Crittografia Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) dalla genesi
Punteggio di sicurezza quantistica 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
Standard NIST FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — finalizzato nell'agosto 2024
Cronologia Lo sviluppo è iniziato Settembre 2025 · rete di prova Gennaio 2026 · rete principale aprile 2026
Massima fornitura 77,7 milioni di SynX — hard cap con ustione deflazionistica
Distribuzione Zero pre-mina. Zero ICO. Zero CV. Allocazione zero del fondatore. Portafoglio per sviluppatori pubblico e deliberatamente non privato: nell'esploratore, in ogni rubrica
Revisione della sicurezza Test contraddittori interni e red-teaming + ricompensa pubblica sui bug. Audit completamente indipendente presso il primo dimezzamento, quando l'origine si apre con gli audit trail
Mining Argon2id (memoria rigida da 2 GB): anti-ASIC, solo CPU
Privacy Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
Wallet Windows, macOS, Linux — download gratuito

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

Proteggi le tue criptovalute dalle minacce quantistiche

SynX fornisce oggi la crittografia resistente ai quanti approvata dal NIST. Non aspettare il Q-Day.

Inizia Swap for SYNX

.ᐟ.ᐟ Lettura essenziale

Ora sono diventato pensiero: il protocollo Hydra e il percorso verso AGI entro il 2035 →

Oppenheimer ha tirato fuori una frase dal deserto. Questo secolo diventa diverso e il generatore sei tu.

🛡️ Stanno arrivando i computer quantistici. Non aspettare finché non sarà troppo tardi.
Scarica il portafoglio SynX – gratuitamente