Security AnalysisBeginner9 min read2026-10-09
W

Dr. Emily Watson

Applied Cryptography Lead

Is Tezos Quantum Safe? XTZ On-Chain Governance and Quantum Risk

TL;DR: Tezos supports three address types — tz1 (Ed25519), tz2 (secp256k1), and tz3 (secp256r1/P-256) — all of which are elliptic-curve schemes broken by Shor's algorithm. Tezos's on-chain governance mechanism theoretically makes it easier to upgrade than Bitcoin or Ethereum, but as of 2026 no post-quantum governance proposal has been submitted to the Tezos protocol. The upgrade capability exists; the political will to exercise it does not yet appear to.

Understanding Tezos Address Types and Their Cryptography

Tezos is unusual among major blockchains in that it natively supports multiple cryptographic signature schemes, each corresponding to a different address prefix. Understanding which scheme underlies each address type is the starting point for any quantum risk assessment.

tz1 addresses use Ed25519 — specifically the Edwards-curve Digital Signature Algorithm operating over the Curve25519 elliptic curve. Ed25519 is the default key type for Tezos bakers (validators) and is generally considered the most cryptographically modern of the three schemes Tezos supports. However, "modern" in the classical sense does not mean "quantum-resistant." Ed25519 is an elliptic-curve scheme, and Shor's algorithm solves the elliptic-curve discrete logarithm problem (ECDLP) in polynomial time regardless of which specific curve is used. Curve25519 is no more resistant to quantum attack than secp256k1 or P-256.

tz2 addresses use secp256k1 ECDSA — the same curve used by Bitcoin and Ethereum. This was added to Tezos partly to facilitate easier key management for users already holding Bitcoin or Ethereum wallets. It carries all the quantum vulnerabilities of secp256k1 everywhere else.

tz3 addresses use secp256r1 (also called P-256) — a NIST-standardized elliptic curve. P-256 is widely used in enterprise and government settings and is the curve underlying many TLS certificates. Its quantum vulnerability is identical to secp256k1 and Ed25519: Shor's algorithm recovers the private key from the public key on any elliptic curve.

In summary: Tezos offers users three cryptographic choices, and all three choices are quantum-vulnerable. The breadth of options reflects Tezos's design philosophy of flexibility, but it does not provide any quantum safety. An attacker with a cryptographically relevant quantum computer (CRQC) can attack tz1, tz2, and tz3 addresses alike.

Tezos Bakers and the Quantum Threat to Consensus

Bakers are Tezos's equivalent of validators or miners — they create and attest blocks, participate in the Tenderbake consensus protocol, and earn staking rewards. Bakers use tz1 (Ed25519) key pairs as their primary identity. Baker keys are publicly visible on-chain because bakers must register their public keys to participate in consensus.

This public key exposure is precisely the quantum attack surface. Shor's algorithm requires only the public key — which is available to any observer — to derive the corresponding private key. A quantum adversary could recover a baker's private key, then:

  • Double-sign blocks (equivocation), triggering the baker's slashing mechanism and draining their bond
  • Sign fraudulent blocks that appear to originate from a legitimate baker
  • Steal the baker's staked XTZ and rewards without needing physical access to any system
  • Silently vote in governance proposals on behalf of a hijacked baker identity

The governance manipulation attack is particularly significant given Tezos's architecture. If a quantum adversary can control the signing keys of a sufficient number of bakers, they can steer protocol amendment votes — including votes on whether to implement post-quantum migration. A well-timed quantum attack could theoretically block the very upgrade intended to prevent it.

On-Chain Governance: Tezos's Theoretical Advantage

Tezos's most distinctive feature is its self-amending protocol. Unlike Bitcoin or Ethereum, where protocol upgrades require off-chain social consensus and coordinated hard forks, Tezos implements a formal on-chain governance process through which protocol changes are proposed, debated, and activated entirely within the protocol itself. This process has already delivered 15 successful protocol upgrades — named after cities in alphabetical order (Athens, Babylon, Carthage, Delphi, Edo, Florence, Granada, Hangzhou, Ithaca, Jakarta, Kathmandu, Lima, Mumbai, Nairobi, Oxford) — without a single contentious hard fork.

This governance capability is genuinely relevant to the quantum migration question. In theory, a post-quantum migration for Tezos could proceed as follows:

  1. A developer or team submits a protocol amendment proposal that adds a new address type (e.g., tz4 or tz5) supporting NIST-standardized post-quantum signature schemes such as ML-DSA or SLH-DSA.
  2. The proposal enters the exploration phase, where bakers can upvote it. A proposal reaching a supermajority advances.
  3. After testing on a test network, bakers vote on final adoption. A successful vote triggers automatic protocol activation after a set number of blocks.
  4. A migration period allows existing address holders to generate new post-quantum key pairs and transfer their balances to quantum-safe addresses.

This pathway is more structured and less politically contentious than the equivalent process for Bitcoin (which has no formal governance mechanism) or Ethereum (which requires off-chain coordination among developers, miners/validators, and users). Tezos's governance architecture is a genuine technical advantage for post-quantum migration.

The Gap Between Capability and Action

The critical observation for 2026 is that while Tezos has the governance machinery to execute a post-quantum migration, that machinery has not been engaged for this purpose. As of October 2026, no post-quantum governance proposal has been submitted to the Tezos protocol. The Tezos Foundation (TF) has not published a post-quantum cryptography (PQC) research agenda or migration roadmap. Recent protocol upgrades (the Oxford and later amendments) have focused on staking mechanism improvements, smart contract capabilities, and performance optimizations — not cryptographic algorithm agility.

This gap between capability and action is worth examining. Several factors may explain it:

Timeline uncertainty: The standard estimate for cryptographically relevant quantum computers capable of attacking 256-bit elliptic curves is 10-20 years. Some stakeholders may view this timeline as too distant to justify migration work that would introduce significant implementation complexity today.

Migration coordination costs: Even with on-chain governance, a cryptographic migration is not simply a protocol activation. It requires ecosystem-wide software updates (wallets, exchanges, explorers, DeFi applications), user education, and a migration period during which both old and new address types coexist. These coordination costs are real regardless of governance mechanism.

Harvest-now-decrypt-later underappreciation: The harvest-now-decrypt-later (HNDL) threat — where adversaries collect public keys and signed transactions today for future quantum decryption — is not yet widely modeled in blockchain community discussions. If the relevant community does not perceive an active threat, the urgency signal for migration work is low.

Tezos Address Type Signature Scheme Curve Quantum Vulnerable?
tz1 Ed25519 (EdDSA) Curve25519 Yes
tz2 secp256k1 ECDSA secp256k1 Yes
tz3 secp256r1 ECDSA (P-256) P-256 Yes
Smart contract signing (Michelson) Same as above (check_signature instruction) Inherits from key type Yes

Smart Contracts and Michelson: Quantum Risk in Tezos DeFi

Tezos smart contracts are written in Michelson, a stack-based language that includes a CHECK_SIGNATURE instruction for verifying cryptographic signatures within contract logic. Contracts that verify signatures on-chain inherit the quantum vulnerabilities of whatever key types they accept.

Tezos DeFi applications — including decentralized exchanges, lending protocols, and NFT marketplaces built on the ecosystem — are exposed through both the asset security layer (user wallet keys protecting XTZ and FA token balances) and any signature-based authorization logic in the contracts themselves. Multi-signature governance contracts for protocol treasuries or DAO structures use the same elliptic-curve key infrastructure and are therefore vulnerable to quantum key recovery attacks.

Unlike Ethereum's EVM ecosystem, where immutable contracts cannot be upgraded without specific proxy patterns, Tezos contracts can be written with upgrade mechanisms more naturally. However, this does not automatically confer quantum safety — it means the migration pathway, if and when it arrives, may be somewhat less disruptive for well-architected Tezos dApps than for their Ethereum equivalents.

The Hash Function Layer: Partial Quantum Resistance

Tezos addresses themselves are derived from public keys via hashing (Blake2b and SHA-256), which provides a layer of protection against a specific class of quantum attack. An address that has never spent funds has not yet revealed its public key on-chain — the blockchain only stores the hash of the key. Shor's algorithm requires the public key, not just the hash, so unspent addresses are somewhat more protected.

However, this protection is partial and conditional:

  • The moment a tz1/tz2/tz3 address signs and broadcasts a transaction, its public key is revealed. Any address that has sent funds is fully exposed to quantum key recovery.
  • Baker addresses, by definition, must broadcast their public keys to participate in consensus. All active baker identities are exposed.
  • Grover's algorithm (a separate quantum algorithm) provides a quadratic speedup on hash preimage attacks. While not as devastating as Shor's algorithm for elliptic curves, it does reduce the effective security of Tezos's hash-based address derivation.

The hash layer is a partial mitigation for dormant wallets, not a systematic quantum defense. Any operational account — one that has ever sent a transaction — is fully exposed to Shor's algorithm.

What a Tezos Post-Quantum Upgrade Could Look Like

If and when a post-quantum governance proposal is submitted, it would likely follow the pattern of Tezos's existing cryptographic flexibility. Tezos already supports a "BLS12-381" cryptographic library in Michelson for zero-knowledge proof applications, demonstrating that new cryptographic primitives can be added to the protocol. A post-quantum upgrade could introduce:

A new address prefix (e.g., tz4) supporting ML-DSA (Module Lattice Digital Signature Algorithm, NIST FIPS 204) — the primary NIST post-quantum signature standard. ML-DSA has three security levels (ML-DSA-44, ML-DSA-65, ML-DSA-87), with ML-DSA-65 offering security comparable to AES-192 against quantum adversaries.

Alternatively, a composite signature scheme could be introduced — combining a classical scheme with ML-DSA or SLH-DSA, so that both a classical and a quantum adversary must simultaneously break two independent signature systems. Composite schemes are considered the most conservative approach during the migration transition period.

The governance pathway for such a proposal exists. The question is whether the Tezos developer community and baker ecosystem will prioritize it ahead of the quantum threat window closing.

Tezos Quantum Risk: An Honest Summary

Tezos presents an interesting case: a blockchain that is currently as quantum-vulnerable as any other major chain, but that possesses governance machinery theoretically capable of executing a post-quantum migration more cleanly than most. The honest assessment for 2026 is:

Tezos is quantum-vulnerable today. All three of its signature schemes are susceptible to Shor's algorithm. Bakers, token holders, and smart contract users are exposed. The ~$1.5 billion XTZ market cap represents value protected only by classical cryptographic assumptions.

Tezos's governance advantage is real but unexercised. Fifteen protocol upgrades without a hard fork demonstrates that the governance mechanism functions reliably. But none of those fifteen upgrades addressed post-quantum cryptography, and no proposal to do so is currently active.

The Case for Quantum-Safe-by-Default Infrastructure

Tezos's situation illustrates a broader truth about blockchain quantum migration: governance capability is necessary but not sufficient. The hardest part of a post-quantum migration is not technical — it is coordinating ecosystem-wide adoption, motivating baker operators to update their software, educating users about key migration, and doing all of this under live conditions on a protocol processing real value.

The alternative to migration is to build on infrastructure that never required it. QuanChain was designed from genesis with NIST-standardized post-quantum signatures — ML-DSA-87 and SLH-DSA in a composite scheme. Every account, every validator identity, and every transaction on QuanChain uses cryptography that is resistant to Shor's algorithm by construction. There is no migration to execute, no governance vote to coordinate, and no window during which classical and post-quantum keys coexist in a partially-migrated state.

For developers and institutions evaluating blockchain infrastructure on a 10-20 year horizon, the question is whether to rely on a governance process that has not yet been tested for post-quantum migration — or to build on a foundation where quantum resistance was never a migration problem because it was never absent.

For more on the quantum threat timeline, see our quantum computing blockchain timeline guide. For a framework on evaluating any blockchain's quantum posture, see evaluating quantum-resistant blockchains.