What it is. Algorand is a public blockchain that has been adding quantum-safe protection since 2022 and has promised to cover its whole network by the end of 2027.
What we found. Almost all of the quantum-safe signing running today protects the network's own bookkeeping rather than the accounts people keep money in, and the part that votes on new blocks is still only research.
Why it matters. Anyone who never acts stays exposed, because the upgrade gives you a new account instead of protecting the one you already have, and Algorand has published no policy for coins that never move.
Two mainnet surfaces sign under Falcon-1024, State Proof certificates at the 256-round interval and LogicSig-authorized accounts since 2025-09-25, together 0.011 percent of measured mainnet transactions, while the native post-quantum account path, a pqsig envelope carrying a two-byte scheme tag with SHA-512/256 address derivation, is merged to mainline and carried by consensus version v42, which is live on TestNet and ratified on MainNet: node queries on 2026-08-23 return MainNet, TestNet and BetaNet all settled on the v42 spec hash, MainNet having activated it at round 64,318,659 after the upgrade passed by 9,198 of 10,000 votes against a 9,000 threshold. No post-quantum code exists on the consensus vote path, where block proposals and committee votes are signed by a two-level ephemeral Ed25519 construction and sortition runs on an ECVRF, with both public keys registered on-chain roughly 2.8 million rounds ahead of use, so Gate 1a-Sig and Gate 1a-KEM fail and the Supply-Chain Cap binds Migration Stage at 3.
Summary
QRI 41, Band 5 Prototyped, Migration Stage 3. Real code merged in June and July 2026: the pqsig envelope with its two-byte scheme registry, post-quantum delegated LogicSigs specified against Rekey, off-curve LogicSig address salting, large LogicSigs under per-byte size pricing, and Go SDK support. Consensus version v42 carries all of it, and v42 is live on TestNet and scheduled on MainNet. Node queries on 2026-08-23 return MainNet with next-version equal to last-version on the v42 spec hash, i.e. settled on the post-quantum consensus version, having activated at round 64,318,659; the v5.0.0-stable tag was published 2026-08-12, its release notes leading with native Falcon-1024 account signatures. Measured mainnet post-quantum share is 0.011 percent of 3,492,404 transactions over three days; user-initiated Falcon-1024 authorizations alone are 0.0007 percent. Everything deployed or drafted is lattice, Falcon-1024 live and Falcon-512 commented out, so the Cryptographic-Diversity Cap fires, and Falcon has no published FIPS 206 draft, so deployers build against the round-3 submission. Announced-to-shipped is 4.0, firing the PQC-washing cap for the first time. The Architecture-Execution Gap is 37 points. The Supply-Chain Cap holds the stage at 3: no wallet, bridge, custodian or infrastructure vendor publishes an Algorand post-quantum roadmap. Dim 1 scores 66: two primitives sometimes listed as deployed are absent from the client.
Forge. Forge-dominant: this chain secures value and operations with signatures, so the principal quantum risk is forgery of spends and attestations once Shor breaks the curve. There is no harvest-now component for forgery, since the public key alone enables it, and on the consensus path the relevant public keys are published on-chain ahead of use rather than only on spend. Decrypt and harvest-now-decrypt-later applies only to transport and RPC confidentiality.
8 announced → 2 shipped on mainnet under a named primitive. >2.0 deduction plus additional QRI cap 65 (non-binding: raw QRI 41). Shipped counted on the rubric's strict basis, mainnet bytes signed under the exact primitive named, and both were verified by direct query on 2026-08-12: Falcon-1024 State Proof certificates, still being produced every 256 rounds, and Falcon-1024 LogicSig account signatures, twenty-five of them in a three-day sample from four distinct addresses. Announced counted as distinct forward-dated primitive-level claims in the trailing twelve months, all eight traceable to the June 2026 roadmap and its wire release: native post-quantum accounts, network-level multi-scheme cryptographic agility, hybrid ECC-plus-lattice accounts, native post-quantum multisig, native Falcon-512, a post-quantum VRF replacement, post-quantum consensus signatures, and hardware-wallet Falcon-1024 support. Not a narrative-only finding: four of the eight trace to merged, independently verifiable client code. It is a gap finding, and the gap widened sharply because the announcement surface doubled in one document while the mainnet-verifiable surface did not move at all..
What the gates say
- Gate 1a, Hybrid signature: FAIL , parallel, not hybrid. On MainNet an account is authorized by Ed25519 or by a Falcon-1024 LogicSig, or delegates via Rekey; the same account is not co-authorized by both in one signing event. The June 2026 roadmap announces hybrid accounts merging an ECC key with a lattice key, and the two architectural prerequisites it names, network-level support for multiple concurrent signature schemes and a larger LogicSig budget, are both merged to mainline. But no AND-composition or OR-composition combiner is specified in public code or spec, and no strong-unforgeability, non-malleability combiner proof is published, which Gate 1a-Sig requires at SUF-CMA strength for consensus- or txid-relevant signatures. The work is roadmapped and under active construction rather than unaddressed, but the combiner itself remains unspecified. Consequence: QRI cap 60, Stage cap 4.
- Gate 1a, Hybrid KEM: FAIL , a repository-wide search of the consensus client on 2026-08-12 returns no ML-KEM, Kyber or hybrid-KEM implementation of any kind, so no post-quantum or hybrid key establishment exists at node-to-node transport; gossip and RPC are carried over operator-configured TLS with classical key exchange. A community governance proposal specifies ML-KEM-512 combined with X25519, which is a hybrid construction in form, but it is an unfunded application-layer messaging proposal carried inside ordinary transactions, not validator transport, and it is not deployed.
- Gate 1b, Commit-to-hash: COND , no OR-composition / 1-of-2 hybrid declared at any layer
- Gate 2, Evidence reconstruction: PASS , every sub-score reconstructible from public artifacts in 48h: foundation blog and technology pages, a dated commercial wire release, merged pull requests and release tags in the client repository, the protocol specifications repository commit history, the client's own consensus-version and opcode source, and no-authentication public node and indexer API queries against MainNet, TestNet and BetaNet. The mainnet traffic share, the stake concentration and the first Falcon transaction in this card are direct measurements, not estimates, and the queries that produce them are recorded in the internal evidence index.
- Gate 3, Primitive naming: PASS , every primitive named exactly, with network scope and shipped-versus-announced status attached, and every deployed primitive confirmed present in the consensus client source rather than inferred from documentation
Burn-vs-rescue policy on file
Declared option f, Undeclared. The Algorand Foundation still publishes no policy on what happens to quantum-vulnerable accounts that never migrate. The June 2026 roadmap is a forward-migration plan, not a dormant-balance policy: it specifies deriving a Falcon-1024 account from the standard 25-word seed phrase, and the accompanying wire release commits the Foundation to begin migrating its own treasury to post-quantum accounts and to enable staking from post-quantum accounts, all in Q4 2026 and all opt-in. No freeze, no rescue construction, no rate-limit canary and no sunset date for Ed25519 is proposed. The implicit posture is optional user migration, with the existing Rekey primitive as the in-place mechanism, but it has not been declared as policy. Note that the roadmap's own construction derives a new post-quantum address from the same seed rather than rebinding an existing address, so an unmigrated address stays unmigrated whatever its owner does elsewhere.
Seven dimensions
Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.
1 Cryptographic Exposure weight 15% 66 / 100
The Foundation's own published inventory improved materially: it now gives exact key and signature sizes for Ed25519, Falcon-512 and Falcon-1024, the exact native post-quantum address construction, and a plain statement that consensus messages and voter signatures are signed with Ed25519 today. Merged client code independently corroborates the design by carrying a two-byte scheme-tag registry rather than a hardcoded single scheme. Three deductions stand. First, the scheme that actually authorizes consensus votes is named in no Foundation document and is recoverable only from client source. Second, the Foundation's own published materials carry two verifiable primitive-level errors, an inconsistent NIST security-category statement for Falcon-1024 and a signature-size ratio understated by roughly half. Third, Falcon-512 registration exists only as commented-out groundwork. Two primitives sometimes attributed to Algorand are absent from the client and are therefore absent from the inventory above: a pairing-based multi-signature construction, and BLS12-381 in State Proof participation.
Ed25519 per RFC 8032 (default account signatures; also the base scheme of the consensus vote path) · OneTimeSignature: a two-level ephemeral Ed25519 forward-secure construction used for block proposals and committee votes, in which a master key signs a per-batch subkey which signs a per-offset subkey, and used secrets are deleted; this is the scheme the client implements, and it is documented only in client source, not in Foundation materials · ECVRF (cryptographic sortition / committee selection); the VRF public key is published on-chain as the selection participation key · Falcon-1024, deterministic profile (State Proof participation keys since the 2022-03 client release; LogicSig-authorized accounts on MainNet since 2025-09-25), public key 1793 B, constant-time-format signature 1232 B as verified by the virtual machine · Merkle signature scheme over per-256-round ephemeral Falcon-1024 keys, committed on-chain as the state proof participation key and used to sign State Proof certificates · pqsig envelope with two-byte scheme tag ('f1' registered for the deterministic Falcon-1024 profile), one-byte address salt, public key and signature, with native post-quantum address derivation SHA-512/256(post-quantum-address domain separator || scheme[2] || salt[1] || pk); merged to mainline, active on BetaNet consensus v42 only · Falcon-512 (public key 897 B; signature 666 B per the Falcon round-3 specification, published by the Foundation as roughly 640 B), drafted in the client with its scheme registration commented out, not shipped · SHA-512/256 (block hash, transaction hash, native post-quantum address derivation) · SHA-256 (State Proof message hash) · Sumhash512, a subset-sum hash, used inside the State Proof and Merkle-signature constructions; the corresponding virtual-machine opcode 0x86 is not enabled at any activated consensus version and is currently gated to a future virtual-machine version under an explicit EXPERIMENTAL marker in client source · BLS12-381 and BN254, exposed to smart contracts only as elliptic-curve groups for the virtual machine's pairing opcodes; not used in State Proofs, consensus or account authorization · poseidon2 (virtual-machine v13 hash opcode 0xe7, SNARK-friendly; BetaNet only; not a post-quantum signature or KEM primitive) · ML-KEM-512 combined with X25519 (application-layer encrypted messaging, community governance proposal only, not protocol transport, not deployed) The classification is scoped by network and by layer. Two primitives sometimes listed for Algorand are not deployed at all, and one belongs at the application layer rather than at consensus, so any classification blind to network and layer overstates what is in place. The whole consensus path, block proposal, committee vote and sortition, is Shor-breakable; the only PQ-safe signing on MainNet is Falcon-1024 on two surfaces. The poseidon2 opcode is tagged here to prevent conflation with a post-quantum primitive: it is an application hash, no Algorand post-quantum signature scheme is based on it, and the developing-confidence discount for that hash family therefore does not apply. Deduction retained for the research-grade tier of Sumhash512 and poseidon2 and for the lattice-confidence caveat on Falcon.
Ed25519→ Shor-break (discrete log on the Edwards curve)OneTimeSignature (two-level ephemeral Ed25519, consensus votes)→ Shor-break; forward secrecy limits key-compromise damage but gives no protection against a Shor adversary, and the master verifier is published on-chain in advance of useECVRF→ Shor-break; sortition history reconstructable post-ShorFalcon-1024 (deterministic profile)→ PQ-safe lattice (NTRU lattice, Falcon submission targets NIST Category 5; NIST-selected 2022, no draft FIPS published)Falcon-512 (drafted, not shipped)→ PQ-safe lattice (Falcon submission targets NIST Category 1; same family as Falcon-1024, adds no diversity)Merkle signature scheme over ephemeral Falcon-1024 keys (State Proofs)→ PQ-safe; security rests on the underlying lattice signature and on Sumhash512 collision resistance, both lattice/algebraic, so it adds no family diversitySHA-512/256→ Grover-weaken (128-bit effective preimage security)SHA-256→ Grover-weaken (128-bit effective preimage security)Sumhash512→ Grover-weaken; subset-sum construction with less mature classical analysis than SHA-2, and marked experimental in client sourceBLS12-381 / BN254 (virtual-machine pairing opcodes only)→ Shor-break-via-pairings; application-layer exposure only, no role in consensus, State Proofs or account authorizationposeidon2 (virtual-machine v13, BetaNet only)→ Grover-weaken; research-grade cryptanalytic tier, SNARK-friendly application hash, not a post-quantum signature schemeML-KEM-512 with X25519 (application-layer proposal)→ PQ-safe lattice KEM in hybrid form; proposal only, not deployed, not validator transport
PQ-safe families represented: lattice only (Falcon-1024, and the Merkle signature scheme built over it). No hash-based (SLH-DSA per FIPS 205, XMSS per RFC 8391, LMS per RFC 8554) and no code-based (Classic McEliece, BIKE, HQC) PQ signature or KEM scheme is deployed or drafted. The Merkle tree in the State Proof construction is not a hash-based signature scheme: its one-time components are Falcon-1024 keys, not Winternitz chains, so it is the same family. Lattice-only is the rubric's hard cap of 5. Cryptographic-Diversity Cap fires.
The Falcon submission targets NIST security Category 5 for Falcon-1024 and Category 1 for Falcon-512. MainNet deployment is on Falcon-1024, so the deployed signature sits at the Category 5 tier, exceeding the CNSA 2.0 minimum. Hashes: SHA-512/256 and SHA-256 both give 128-bit effective preimage security against Grover. Deduction reflects that the Category 5 claim rests on the round-3 submission specification rather than an approved federal standard, since no draft FIPS for this scheme has been published, and that the chain's own published description of the security level is internally inconsistent.
Library provenance: the client wraps a C implementation of the deterministic Falcon-1024 variant through the algorand/falcon Go package, with a separate Foundation-published signing utility built on the same base; the Foundation credits the underlying work to the Falcon team, with its own research contributions on the deterministic variants. Constant-time coding practice is asserted by the Foundation with no third-party constant-time validation published, and no machine-checked formal verification of the implementation exists. Deployed-verifier provenance is unevidenced: no reproducible build and no independent audit ties the running verification opcode to audited source, so this component scores zero of the three available states. Cryptanalytic tiers: Falcon-1024 is selected-but-not-final. NIST selected it in 2022 and presented a status update on its standardization at its own 2025 post-quantum conference, but on 2026-08-12 the CSRC publication list still tops out at FIPS 205 and every candidate URL for a FIPS 206 draft returns 404, so a deployer builds against the round-3 submission specification. Sumhash512 and poseidon2 are research-grade, and client source marks the Sumhash512 opcode experimental and has bumped it past the consensus v42 virtual-machine version rather than enabling it.
2 Quantum Recovery Exposure weight 10% 33 / 100
Default accounts use Ed25519 and reveal the public key on first transaction. LayerQu measured the exposure directly over rounds 63,900,000 to 63,993,605 on 2026-08-12: of 3,492,404 mainnet transactions, 99.989 percent were authorized by non-post-quantum schemes. Consensus participation compounds this: 1.994 billion ALGO, 20.4 percent of total supply, is online, and every online account publishes its Ed25519 vote participation key, its VRF selection key and its Falcon state proof key on-chain in a key-registration transaction with an explicit validity window, in the sampled case roughly 2.8 million rounds ahead of use. Those consensus keys are therefore epoch-public by construction, not merely revealed on spend.
Mainnet genesis round 1 carries timestamp 2019-06-11, so 86 months of history at the evaluation date. Substantial dormant supply sits on Ed25519 public keys from genesis and early distribution. The Rekey primitive enables migration without changing address, and independent external analysis lists Algorand among the small set of chains with native protocol-level key rotation, but cold balances by definition do not rotate. The roadmap's post-quantum account derivation produces a new address from the same seed rather than rebinding an existing one, so it does not reach dormant balances at all.
All historical Ed25519 transaction signatures are forgeable post-Shor. State Proofs sign block-header commitments with Falcon-1024 through the Merkle signature scheme, providing a quantum-resistant audit trail for state attestations but not for individual user transaction signatures. Pre-State-Proof history has no PQ attestation layer; State Proof production requires the consensus version that introduced it, which followed the 2022-03 client release that first made online participants generate Falcon state proof keys.
A full-text search of the consensus client on 2026-08-12 returns no ML-KEM, Kyber or hybrid-KEM implementation anywhere, so node-to-node gossip and RPC rely entirely on operator-configured TLS with classical key exchange and no post-quantum or hybrid key establishment exists at transport. The community 'Sealed' governance proposal, submitted 2026-04-30 requesting 400,000 ALGO under a mass-adoption category, specifies ML-KEM-512 combined with X25519 for application-layer encrypted messaging carried inside Algorand transactions; it is a proposal, it is not validator transport, and a reviewer in its own public thread raised the objection that encrypting message content does not help while the account key authorizing the transaction stays quantum-vulnerable. No post-quantum transport-layer mechanism is documented.
3 Metadata, Anonymity & Confidentiality weight 13% 25 / 100
Pseudonymous transparent ledger. Public addresses, public balances, public state, and public consensus participation keys bound to specific accounts through key-registration transactions. No native shielded transactions, no on-chain mixing.
The public RPC surface is more concentrated than a provider count suggests: AlgoNode is operated by Nodely, so what was listed as two independent providers is one operator, leaving that operator and the Foundation's own public endpoints as the dominant no-authentication paths. Precise request-share is not publicly published. Mempool gossip is observable to any participant. Validator metadata retention is undeclared at protocol level.
Wormhole is the most widely cited external bridge for Algorand; LayerQu did not find a published bridge-volume ranking and does not assert one. State Proofs enable trustless cross-chain verification outbound from Algorand only. Source-to-destination linkability across bridges is high, since both sides are transparent.
Shor on the Edwards curve breaks the ECVRF, allowing retroactive reconstruction of sortition outcomes and therefore of committee membership for past rounds. The selection key that drives sortition is published on-chain in advance of use, which makes the reconstruction target explicit rather than inferred. The Foundation now states the consequence directly and on the record: an ECC-based VRF would no longer guarantee committee-membership anonymity before a member vote is cast, while its published research indicates attackers cannot falsely claim membership. A specific replacement construction is under security and efficiency analysis with a paper expected by early 2027; nothing is specified, prototyped or deployed. The gap is independently tracked as a client-repository issue filed by a community contributor on 2025-08-08 and still open on 2026-08-12. The Foundation's disclosure improved in quality and dating, while the underlying exposure did not change.
No on-chain mixer, no native commit-reveal shuffle, no integrated mixnet.
4 Migration Architecture weight 10% 74 / 100
Two mechanisms evidence protocol crypto-agility. In production on MainNet: LogicSig accounts verify Falcon-1024 without a hard fork through the falcon_verify opcode (0x85), added at virtual-machine version 12, which consensus v41 enables. LayerQu confirmed this is a live mechanism and not a demo by finding twenty-five Falcon-verifying LogicSig authorizations in a three-day sample of mainnet transactions. Merged to mainline: a general pqsig envelope carrying a two-byte scheme tag, giving network-level support for multiple concurrent signature schemes so that additional schemes can be added without further structural change, plus automatic salting of virtual-machine v13 programs so a LogicSig address cannot decode to a valid Edwards25519 point. Both landed in consensus v42 and the 5.0.0 release line, which runs on BetaNet only. Full credit reflects the rubric's two conditions being met together: a versioned scheme registry in merged code, and a verifiable instance of the agility mechanism in production within five years. The caveat that the registry is not yet MainNet-active is scored in Dim 5, not here. Sumhash512 is sometimes described as shipping alongside falcon_verify at virtual-machine version 12. It did not: it has never been enabled at any activated consensus version, and client source currently gates it to virtual-machine version 14 under an EXPERIMENTAL marker.
LogicSig accounts behave as native account abstraction, and the Rekey primitive permits any account to switch its authorizing key, including from Ed25519 to a Falcon LogicSig, without changing the address or moving funds, with production volume since 2025-09-25. The documented client-layer path is now backed by merged code rather than description: post-quantum delegated LogicSigs specify their interaction with Rekey explicitly, the post-quantum signature type is exported to the Go SDK, and post-quantum key-management commands ship in the same release line. The Ed25519 seed floor applies, since standard Algorand accounts derive an RFC 8032 Ed25519 key from a 25-word seed, but is superseded by the higher account-model component and combined by maximum, not sum. No post-quantum rebind bonus is awarded: the roadmap derives a Falcon account from the same seed phrase, which creates a new address rather than rebinding an existing one inside a post-quantum proof, and no freeze of raw Ed25519 acceptance is proposed. Short of full credit because the native path is not MainNet-active and Falcon LogicSig volume is measurably negligible.
Coordinated protocol upgrades v34 through v41 over five years with no contested fork found in the public record. Consensus v41, which added the Falcon verification opcode, shipped in client release v4.3.0-stable on 2025-09-16 and activated on MainNet nine days later, at round 54,012,570 on 2025-09-25, with smooth node-operator coordination; some sources give the release date as the activation date, which the on-chain record does not support. Consensus v42, the post-quantum account version, corresponds to a specifications commit dated 2026-07-29 and is running on BetaNet, but no MainNet upgrade was pending as of 2026-08-12, so it is an upgrade in flight rather than a completed one and earns no additional track-record credit yet.
The two architectural prerequisites the Foundation itself names for hybrid accounts are now merged code rather than intent: network-level support for multiple concurrent signature schemes through the pqsig scheme-tag envelope, and a larger LogicSig budget delivered as large LogicSigs admitted under per-byte size pricing, shipped in the same release line alongside larger notes and additional program pages. Both are in consensus v42 and run on BetaNet. That makes a single account secured by any combination of an ECC key and a lattice key architecturally demonstrable rather than merely stated, which is the standard this sub-score sets. Held short of full credit because no AND-composition or OR-composition combiner is specified in public code or spec, no non-malleability combiner proof is published, and none of it is MainNet-active. Today's MainNet reality remains parallel coexistence: an account is authorized by Ed25519 or by a Falcon LogicSig, not co-signed by both.
Default 15/15 per the v3.1 rule, which is scoped to stateful hash-based signature schemes: Algorand deploys none. No XMSS per RFC 8391, no LMS per RFC 8554, no leanXMSS at consensus or execution; the deployed post-quantum signature is Falcon-1024, which is stateless. Recorded so a reader is not surprised: Algorand does operate two stateful ephemeral-key schemes whose failure mode is index reuse rather than tree-state loss. State Proof participation keys are a Merkle tree over per-256-round ephemeral Falcon-1024 keys, and consensus votes use a two-level ephemeral Ed25519 scheme with secret deletion. Neither is hash-based, so neither is in scope for this sub-score, but both would be if the chain ever moved its aggregation path onto a hash-based scheme.
Algorand's consensus vote path signs committee votes with a two-level ephemeral Ed25519 forward-secure scheme, with an ECVRF for sortition. Both are Shor-breakable, and both public keys are registered on-chain ahead of use with an explicit validity window. The Foundation has now published a direction of travel: research is ongoing, Falcon is named the strongest candidate following completed vote-compression work, a hybrid Ed25519-plus-Falcon consensus model is considered likely, and more information is promised near the end of 2026. No merged specification, no testnet prototype and no mainnet pilot exists; a repository search across the client, SDK and specification repositories found no matching merged work. Under the rubric a direction-of-travel statement is not a merged spec, so the score stays at zero. Consequences: the chain is flagged consensus-layer-exposed and Stage 5 is barred while this sub-score remains zero. One scoping note for precision: the rubric's standing-exposure clause is written for BLS-aggregating chains, and Algorand does not BLS-aggregate; no pairing-based multi-signature construction exists in the client. The flag is applied on the other limb of the clause, epoch-public validator keys, which LayerQu verified directly in a key-registration transaction on 2026-08-12.
5 Deployment Execution weight 22% 37 / 100
Measured, not estimated. Over rounds 63,900,000 to 63,993,605, a window of roughly three days ending 2026-08-12, MainNet processed 3,492,404 transactions. Post-quantum-signed transactions in that window number approximately 391: about 366 State Proof certificates, produced automatically every 256 rounds, and 25 Falcon-1024 LogicSig authorizations from four distinct addresses out of 6,164 LogicSig transactions in total. That is 0.011 percent, roughly 1,800 times below the 20 percent threshold, and user-initiated post-quantum authorizations alone are 0.0007 percent. A wider one-million-round window ending the same day gives a consistent State Proof share of 0.0103 percent of 37,953,193 transactions. This figure predates the native post-quantum account release: MainNet activated consensus v42 at round 64,318,659 on 2026-08-22, and v42 is the version that enables native Falcon-1024 account signatures. Account-level post-quantum traffic became possible only at that round, so no measured share of it is carried here yet and the figure above covers State Proof signatures alone. The Mainnet-Traffic Cap fires. The score of 1 reflects non-zero, continuously produced mainnet post-quantum signatures that are not traffic-material.
Merged and released post-quantum code in the chain's single consensus client grew materially, and it is verifiable independently of any Foundation statement: the native post-quantum account signature type carrying the general pqsig envelope (merged 2026-07-10), post-quantum delegated LogicSigs specified against the Rekey primitive (merged 2026-07-17), automatic salting of virtual-machine v13 programs to keep LogicSig addresses off-curve (merged 2026-06-25), large LogicSigs under per-byte size pricing, export of the post-quantum signature type to the Go SDK (merged 2026-07-20), and post-quantum key-management commands, all carried by consensus version v42 into the 5.0.0 release line. That is on top of the Falcon verification opcode in mainline since consensus v41 and Falcon State Proof signing since the 2022-03 client release. Deducted because none of the new code is MainNet-active, running on BetaNet only; because no post-quantum code exists in mainline for the consensus-message, voter-signature or VRF paths; and because the second scheme the registry is built for, Falcon-512, exists only as three open pull requests opened 2026-08-11 whose own authors state they add no consensus behaviour, no opcode and no scheme registration, which client source confirms with the Falcon-512 registration left commented out.
Online participants generate Falcon state proof keys when renewing online status, required since the client release of 2022-03, and LayerQu confirmed on 2026-08-12 that live key-registration transactions carry a state proof key alongside the Ed25519 vote participation key and the VRF selection key. The state proof key is a Merkle root over per-256-round ephemeral Falcon-1024 keys. Block proposals and committee votes themselves continue to be signed with the ephemeral Ed25519 scheme. Score reflects partial adoption: post-quantum keys are universal among online validators for attestation, and absent for consensus.
Not voided: 5a is above zero. The June 2026 roadmap, distributed through a dated commercial wire release and independently reported the same day, publishes quarter-dated milestones: native post-quantum accounts with SDK, developer-toolkit and wallet derivation in Q3 2026; post-quantum multisig, the Foundation beginning migration of its own treasury to post-quantum accounts, and staking enabled from post-quantum accounts in Q4 2026; native Falcon-512 by year-end 2026; further post-quantum consensus detail near end-2026; a post-quantum VRF paper by early 2027; broad quantum resilience across all protocol layers by end-2027. The delivery record on previously published dates is good and third-party reconstructible: State Proof keys from the 2022-03 client release, the Falcon verification opcode released 2025-09-16 and activated on MainNet 2025-09-25, the first Falcon-authorized MainNet transaction the same day, and a dated public release ledger in the client repository. Held two points short of full credit because none of these milestones is protocol-enforced: there is no consensus-enforced flag day and no published sunset date for Ed25519, and the Q3 2026 MainNet activation executed at round 64,318,659, inside the quarter the Foundation stated.
Announced-to-shipped ratio 4.0, above the 1.5 deduction threshold and above the 2.0 additional-cap threshold. Shipped is counted on the rubric's basis of mainnet bytes signed under the exact primitive named, which yields two, both re-verified by direct query on 2026-08-12: Falcon-1024 State Proof certificates and Falcon-1024 LogicSig account signatures. Against those, the trailing twelve months carry eight distinct forward-dated primitive-level claims, all eight traceable to the June 2026 roadmap and its wire release. This is not a narrative-only finding, and the floor above zero reflects that: every announced item traces to an identifiable engineering work stream, four of them merged and independently verifiable in the client repository, and two of the claim categories are already MainNet-live under the exact primitive named. It is a gap finding. One document doubled the announcement surface while the MainNet-verifiable surface did not move at all, and the Falcon-512 work opened since is explicitly labelled groundwork by its own authors, with no consensus behaviour, no new opcode and the scheme registration left commented out.
Measured on the first Falcon-authorized MainNet transaction, retrieved and decoded from the public indexer on 2026-08-12: a 1,805-byte virtual-machine v12 LogicSig program embedding the 1,793-byte Falcon-1024 public key and terminating in the falcon_verify opcode, plus a 1,231-byte signature argument that the program prefixes with a one-byte constant to form the 1,232-byte constant-time-format signature. That is 3,036 bytes of authorization data against 96 bytes for a standard Ed25519 payment, a factor of roughly 32 on the full authorization envelope and roughly 19 on the signature alone. The Foundation's own published estimate of 1,280 bytes for a Falcon-1024 signature matches the specification but not the format the virtual machine verifies. Algorand's block design absorbs Falcon LogicSigs at the LogicSig program-budget level without inflating block sizes for Ed25519-only blocks; the Foundation reports verification completing in under 200 microseconds, though the same document elsewhere says under 100, so treat the figure as an order of magnitude rather than a benchmark. The effective per-block multiplier is currently negligible because Falcon authorizations are 0.0007 percent of transactions.
6 Supply Chain Vendor Readiness weight 22% 17 / 100
The wallets most commonly used with Algorand are Pera Wallet, Defly and Ledger hardware wallets; No published wallet-share ranking exists, so this card asserts none. No wallet vendor has published a Falcon roadmap of its own. The Foundation states that Pera Wallet and its developer toolkit are expected to support Falcon account derivation within the Q3 2026 release window, and its wire release goes further, listing post-quantum account creation available within Pera Wallet as a Q3 2026 deliverable, but the public record shows no wallet-vendor-originated announcement, changelog or release note corroborating either statement on 2026-08-12, so it remains a chain-side claim about a third party. A Foundation proof-of-concept on a Trezor Safe 5 (Cortex-M33) performs on-device Falcon-1024 key generation and signing under the deterministic variant, with published medians of 3.79 s key generation under float emulation, 2.22 s using the integer-only ntrugen solver, and roughly 0.69 s per signature at sub-millisecond variance; the Foundation states plainly that it cannot ship hardware-wallet support independently and needs manufacturer collaboration, and no device manufacturer has confirmed those figures or committed to shipping. Foundation leadership has separately called in public for a shared cross-industry standard for deriving quantum-secure keys from seed phrases, which is coordination activity, scored in Dim 7, not a vendor roadmap. Note that no such standard exists: Algorand's own 25-word single-key scheme and its BIP39 / BIP32-Ed25519 / BIP44 hierarchical-deterministic support both need a lattice-key derivation answer that has not been agreed anywhere.
Wormhole is the most widely cited external bridge for Algorand; Algorand State Proofs provide a one-way outbound light-client path. Wormhole has published no PQC roadmap. State Proofs are PQ-secure outbound, signed under Falcon-1024, for trustless cross-chain verification, but inbound bridge surfaces remain classical. Re-verified 2026-08-12: no bridge-vendor post-quantum roadmap found, and sector commentary continues to describe bridge guardian sets as ECDSA-signed with no publicised transition plan. Sourcing note: that sector commentary is secondary analysis, not a vendor statement, and the finding rests principally on the absence of any Wormhole-published PQC material.
The institutional custodians most often named alongside Algorand are BitGo, Anchorage Digital and Fireblocks, alongside tier-1 exchange custody. LayerQu could not resolve a live vendor-published asset-support page for any of the three on 2026-08-12 and therefore does not assert per-vendor Algorand coverage as verified. What is verified is the negative that drives the score: none of them publishes an Algorand-specific post-quantum custody roadmap or migration timetable, re-checked 2026-08-12 with no change found. Sector-level coverage describes institutional custodians broadly aligning with NIST post-quantum standards, but names no Algorand-specific commitment from any of them. The Foundation's Q4 2026 commitment to migrate its own treasury to post-quantum accounts is a chain-side action and is scored in Dim 5, not as custodian readiness.
The dominant no-authentication public RPC surface is Nodely, which operates the AlgoNode endpoints, plus the Foundation's own public endpoints; some readings count Nodely and AlgoNode as separate providers, which they are not. HSMs: validator setups use general-purpose products such as AWS KMS, YubiHSM and Thales offerings, with no Algorand-specific PQC HSM commitment published by any of them, and none of them supports Falcon-1024 signing for Algorand participation keys today. TEE attestation chains are not in the Algorand validator path. No PQC roadmap on any infrastructure tile.
7 Governance & Coordination weight 8% 60 / 100
Pure proof-of-stake with VRF-based committee selection from total online stake. Stake distribution in the June 2026 ecosystem report, published 2026-07-17: community 80.6 percent, Foundation 19.4 percent; participating nodes 2,822, up 2.8 percent month on month from 2,745. LayerQu measured the live picture on 2026-08-12: online stake is 1,994,141,546 ALGO, 20.4 percent of the 9,759,711,225 ALGO total supply, and at address level the largest single online account holds 3.51 percent of online stake, the top three hold 10.04 percent and the top five 15.68 percent. Address-level concentration is therefore lower than an entity-level reading would imply, and no primary source supports a single staking provider near twenty percent. The score does not rise, because addresses are not entities and no public data permits entity attribution, so a distribution that cannot be attributed cannot earn credit. The score does not fall either: a one-third threshold of online stake is 6.7 percent of total supply, which the visible address distribution puts within reach of a small cluster.
Smooth coordinated upgrades v34 through v41 over five years with no contested fork found in the public record, and a release ledger reconstructible from the public client repository: v4.7.0-stable 2026-05-05, v4.7.2-stable 2026-06-09, v4.7.3-stable 2026-06-15, v4.7.4-stable 2026-07-16, v5.0.0-beta 2026-08-07, and v5.0.0-stable 2026-08-12, its release pull request having merged into the stable branch on 2026-08-10. Roughly monthly minor releases with one consensus-version bump, v42, in the eleven months since the previous one. The on-chain grants platform launched on mainnet in October 2025, moving grant distribution from a mostly off-chain quarterly process onto the chain. No time-pressure coordination event occurred in this window, so the score is unchanged.
The Algorand Foundation is the named coordination lead, and its mandate is now published and dated rather than inferred: a June 2026 post-quantum roadmap carrying quarter-dated deliverables through end-2027, distributed through a commercial wire service as well as the Foundation's own channels. The lead is independently corroborated: a major industry outlet published the roadmap the same day and quoted the Foundation's Chief Scientific Officer on record about the multi-year cost of migrating a live protocol, and the Foundation's Chief Strategy and Marketing Officer has separately and publicly engaged on cross-industry post-quantum key-derivation standards, stating the Foundation would propose an approach but not implement one unilaterally until there is industry consensus. Two distinct named executive roles carrying the programme in public, plus a dated published mandate reported by a second party, is materially stronger than a single self-published position. One point short of full credit: there is no standing post-quantum working group with a published charter, and no named independent review body outside the Foundation.
No adversarial-pressure coordination event in Algorand's history. Proactive PQ shipping, State Proof keys from 2022 and the Falcon verification opcode activated 2025-09-25, is a positive signal but not a true adversarial test.
No published rate-limit canary, no cryptographic tripwire embedded in consensus, no Hourglass-equivalent mechanism, no community honeypot for forge detection.
Source-disagreement disclosure
v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.
Some industry coverage treats Algorand's State Proofs (Falcon-signed certificates every 256 rounds) as consensus-level PQ adoption. This evaluation separates State Proofs, a consensus-adjacent protocol-level certificate, from consensus signing itself: block proposals, committee voting and sortition remain a two-level ephemeral Ed25519 scheme with an elliptic-curve VRF. The Foundation's own June 2026 roadmap states the same distinction directly: consensus messages and voter signatures are signed with Ed25519 today.
Coverage and the Foundation's own quarter framing describe the post-quantum account release as a Q3 2026 protocol release, and the 5.0.0-stable release pull request was merged into the stable branch on 2026-08-10. The v5.0.0-stable tag and release object were published 2026-08-12, with release notes leading on native Falcon-1024 account signatures. The live network state contradicts any reading of the release as deployed. Public node queries on 2026-08-12 return MainNet and TestNet on build 4.7.4 at consensus v41, with the next consensus version identical to the current one, meaning no upgrade is pending; only BetaNet returns build 5.0.0 at consensus v42, the post-quantum account version. Merged and released is not activated.
The rubric defines shipped as mainnet bytes signed under the exact primitive named, verifiable on a block explorer. On that basis the shipped count is 2, which is what this evaluation uses. Tooling repositories and command-line utilities are not mainnet deployments and are not counted as shipped.
Nearly every press pickup of the June 2026 roadmap restates the Foundation's 'quantum resilience by 2027' framing without independently checking the client repository or the live network. LayerQu's own repository and node-API checks confirm that the roadmap's technical descriptions match the merged code accurately, and equally confirm that none of the new code is MainNet-active. Readers should treat the roadmap as an accurate engineering document and an inaccurate description of the current network. One wrinkle worth recording: the single most-cited outlet's headline says quantum resistance by 2028 while its own body text and every Foundation artifact say end-2027.
The Foundation's roadmap opens by citing recent external analysis as identifying Algorand 'among the limited set of smart-contract platforms to achieve real-world deployment of post-quantum cryptography'. LayerQu read the cited paper in full. It does say Algorand 'provides an example of real-world deployment of PQC on an otherwise quantum-vulnerable blockchain', which supports the substance. It does not use a 'limited set' framing: it groups Algorand with Solana and the XRP Ledger as chains that 'have made early experimental deployments of post-quantum protocols', separately from chains that are post-quantum from inception. The paper also records the same core exposure this card scores, listing Algorand among chains whose account model makes long-term public-key exposure inevitable. The substance survives; the scarcity framing is the Foundation's, not the paper's.
Four discrepancies were found between the Foundation's published figures and the primitives actually deployed or specified, none of which changes a score but all of which a reader reconstructing the card will hit. First, the Foundation's technical brief states Falcon-1024 gives security 'roughly equivalent to AES-192 (NIST Level 5)'; NIST Category 5 is the AES-256 tier, and the Falcon submission targets Category 5 for Falcon-1024, so the brief is internally inconsistent. Second, the same brief states Falcon signatures are 'approximately 10x larger than Ed25519's 64-byte signatures'; the true ratio is between 19 and 20. Third, the roadmap's key-size table gives Falcon-512 signatures as roughly 640 bytes; the Falcon round-3 specification gives 666. Fourth, the roadmap gives Falcon-1024 signatures as roughly 1280 bytes, which matches the specification, but the signature the virtual machine actually verifies is the 1232-byte constant-time-format signature of the deterministic Falcon-1024 variant, and that is the number a fee or block-size calculation needs. This card uses the deployed values.
The Pixel pairing-based forward-secure multi-signature construction is not a deployed Algorand primitive. A full-text search of the consensus client on 2026-08-12 returns no occurrence of Pixel anywhere; it is published Algorand research that was never deployed. BLS12-381 appears in the client only as one of four elliptic-curve groups exposed to smart contracts through the virtual machine's pairing opcodes, alongside BN254, and has no role in State Proofs, which use a Merkle signature scheme over ephemeral Falcon-1024 keys with a subset-sum hash. 'BM-Ed25519' is not a term the client or any Foundation document uses for the consensus vote scheme. The inventory and its Shor and Grover classification are written against the client source.
AlgoNode is operated by Nodely: algonode.io redirects to nodely.io. Treating them as two independent providers would understate concentration on both the metadata tile and the infrastructure tile, so the scored picture is two operators, not three.
Measured on 2026-08-12: online stake is 1.994 billion ALGO, 20.4 percent of total supply. At address level the largest single online account holds 3.51 percent of online stake, the top three hold 10.04 percent and the top five hold 15.68 percent. Address-level concentration is therefore low, but addresses are not entities and public data does not permit entity attribution, so no credit is added for a distribution that cannot be attributed. No primary source supports a single staking provider at a share that would place two entities near a one-third threshold. The published community-to-Foundation split of 80.6 to 19.4 percent comes from the chain's own June 2026 ecosystem report.
The on-device Falcon-1024 key-generation and signing figures for a Trezor Safe 5 are published by the Foundation and repeated widely, but every repetition traces to that single publication. No device manufacturer has published a confirming measurement, changelog or shipping commitment, and the Foundation states plainly that it cannot ship hardware-wallet support without manufacturer collaboration. Scored as a proof-of-concept, not as vendor readiness.
Delta-QRI under alternative weighting
Under an alternative weighting that credits architecture and merged-but-unactivated client code more heavily than deployment (Dim 4 raised to 22 percent, Dim 5 lowered to 10 percent), QRI reads approximately 45, still Band 5 Prototyped. The Mainnet-Traffic, Cryptographic-Diversity and PQC-washing caps continue to bind above the score under every weighting tested, and the Supply-Chain cap continues to hold Migration Stage at 3.
Announcement-to-shipped ratio
Announced: 8. Shipped: 2. Ratio: 4.
Tag: >2.0 deduction plus additional QRI cap 65 (non-binding: raw QRI 41). Shipped counted on the rubric's strict basis, mainnet bytes signed under the exact primitive named, and both were verified by direct query on 2026-08-12: Falcon-1024 State Proof certificates, still being produced every 256 rounds, and Falcon-1024 LogicSig account signatures, twenty-five of them in a three-day sample from four distinct addresses. Announced counted as distinct forward-dated primitive-level claims in the trailing twelve months, all eight traceable to the June 2026 roadmap and its wire release: native post-quantum accounts, network-level multi-scheme cryptographic agility, hybrid ECC-plus-lattice accounts, native post-quantum multisig, native Falcon-512, a post-quantum VRF replacement, post-quantum consensus signatures, and hardware-wallet Falcon-1024 support. Not a narrative-only finding: four of the eight trace to merged, independently verifiable client code. It is a gap finding, and the gap widened sharply because the announcement surface doubled in one document while the mainnet-verifiable surface did not move at all.
Peers in the L1 profile
9 chains closest to Algorand by Stage then QRI.