★ Watchlist 0
MIDNIGHT · PRIVACY-FOCUSED CHAIN · STAGE 1 ACKNOWLEDGED · QRI 22 v3.2.2 methodology
In plain terms

What it is. Midnight is a public network, live since March 2026 and run by nine named companies, built so a business can keep its records secret and still prove to everyone else that they are correct.

What we found. The effort to make Midnight quantum-safe is real, but it sits in an outside research project that has never been switched on for the live network, and it aims at the machinery that checks transactions rather than the wrapper that keeps each record secret.

Why it matters. The risk lands on records already written, because a copy taken today can be opened later and nothing done afterwards pulls it back.

Midnight mainnet, genesis block 2026-03-17 03:17 UTC, signs, finalizes, proves and encrypts under classical primitives: BIP-340 Schnorr over secp256k1 for transaction signatures, Aura sr25519 for block authoring, GRANDPA Ed25519 for finality, ECDSA over secp256k1 for BEEFY and partner-chain cross-chain keys, Plonk with KZG over BLS12-381 for proving, and Zswap note encryption by non-interactive Diffie-Hellman over Jubjub with Poseidon as a CTR-mode cipher, with no post-quantum primitive in midnight-node, midnight-ledger or midnight-zk on mainnet or on any testnet. Gate 1a-Sig and Gate 1a-KEM both fail, every cap ceiling sits above the raw QRI of 23 so no cap binds, and the governing fact is retroactive: confidentiality rests on the discrete-log problem on Jubjub, so every shielded note committed since genesis is decryptable by whoever harvested it, while the one post-quantum program on the public record, the NightStream lattice proving system approved as a Linux Foundation Decentralized Trust lab on 2025-09-15, carries no release, no tag, no disclosed adopters and a published scope that names no note-encryption KEM.

inLinkedIn ↷Audit access ⇆Compare Last reviewed 2026-08-20

Summary

Midnight is a Cardano partner chain on the Polkadot-SDK partner-chains stack; its genesis block was created 2026-03-17 03:17 UTC. Block authoring uses Aura sr25519 authority keys, finality uses GRANDPA Ed25519, and BEEFY attestation and cross-chain keys use ECDSA over secp256k1; peer transport is libp2p Noise over X25519. Transaction signatures are BIP-340 Schnorr over secp256k1 per the ledger specification, and SHA-256 is the primary hash. Zswap uses SHA-256-derived coin public keys, homomorphic Pedersen value commitments, and note encryption by non-interactive Diffie-Hellman over Jubjub with Poseidon as a CTR-mode cipher. Proving is Plonk with KZG over BLS12-381. A code search of midnight-node, midnight-ledger and midnight-zk returns no post-quantum primitive, and the July 2026 mainnet upgrade was a version bump. The public web and RPC TLS edges negotiate X25519MLKEM768, a transport-edge property, not a ledger or consensus composition. NightStream, approved as a Linux Foundation Decentralized Trust lab on 2025-09-15 with Midnight Foundation and Input Output staff among its committers, implements SuperNeo folding for CCS with Ajtai module-SIS commitments and a Poseidon2 transcript over the 64-bit Goldilocks field; its maintainers call it research software, not production-ready and not independently audited. Confidentiality subtotal 1/40. QRI 22 ± 8, Band 3 Planning, Migration Stage 1.

Dominant quantum risk

Decrypt. Decrypt-dominant: as a privacy-focused chain, encrypted note payloads are harvest-now-decrypt-later vulnerable. An attacker harvesting a note ciphertext today decrypts it once Shor breaks the discrete-log problem on Jubjub, the curve the note-encryption Diffie-Hellman runs over. Forge, meaning account-key forgery on the unshielded path and spend-proof forgery on the shielded path, is also material, but the distinguishing quantum risk here is confidentiality loss.

Forge subtotal 15 / Decrypt subtotal 3
Announced → Shipped

2 announced → 0 shipped on mainnet under a named primitive. >1.5 deduction, announced-with-zero-shipped: 2 verified dated PQ announcements in the trailing 12 months against 0 shipped primitives, so the deduction band applies. Mitigations noted: the program is consistently framed as research by its own maintainers, who state it is not production-ready and not independently audited; it has never claimed live quantum safety; and Midnight's developer dev-diary is silent on it. Watch window: first NightStream integration on a Midnight testnet..

LayerQu scores deployment, not announcements. Announcements score zero.

What the gates say

  • Gate 1a, Hybrid signature: FAIL , no documented hybrid signature composition. Transaction signing is BIP-340 Schnorr over secp256k1 per the ledger specification; block authoring uses Aura sr25519 authority keys; finality uses GRANDPA Ed25519 authority keys; BEEFY attestation and partner-chain cross-chain keys use ECDSA over secp256k1
  • Gate 1a, Hybrid KEM: FAIL , Zswap note encryption is non-interactive Diffie-Hellman over Jubjub with Poseidon used as a CTR-mode cipher, with no PQ KEM. Validator peer transport is libp2p Noise over X25519 with no PQ component. Client-facing RPC and web TLS edges were measured negotiating the X25519MLKEM768 hybrid group, which is a transport-edge property and not a consensus-layer or ledger-layer hybrid composition
  • Gate 1b, Commit-to-hash: COND , no OR-composition declared
  • Gate 2, Evidence reconstruction: PASS , every live sub-score has ≥ 3 evidence sources; reconstructible in 48h
  • Gate 3, Primitive naming: PASS , BLS12-381, KZG, Plonk, Jubjub, Pedersen commitments, Pluto-Eris legacy, BIP-340 Schnorr over secp256k1, sr25519, Ed25519, ECDSA secp256k1, X25519, Poseidon, SHA-256; NightStream R&D scope named as lattice-based folding for CCS with Ajtai module-SIS commitments and a Poseidon2 transcript over the 64-bit Goldilocks field

Burn-vs-rescue policy on file

Declared option f, Undeclared. Midnight Foundation has not published a policy on dormant balances or on legacy private records that become readable post-Shor. The privacy-chain analogue is 'what do we do about every historical encrypted note that becomes publicly readable on Q-day', no statement issued.

Seven dimensions

Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.

1 Cryptographic Exposure weight 12% 27 / 100
1a · primitive inventory 14 / 20

Proving-system and ledger primitives are explicitly specified in the public ledger specification and the node runtime source, both published under Midnight Foundation copyright. Deduction retained because no consolidated Foundation cryptographic specification exists: the consensus authority-key types, the BEEFY and cross-chain key types, and the peer-transport handshake are discoverable only by reading client source, and the public developer glossary and documentation name no curve and no signature scheme. NightStream is inventoried as announced-only R&D: its published lab scope names the protocol family and field but no chosen parameter set, its maintainers describe it as research software that is not production-ready and not independently audited, and nothing from it appears in the shipping client stack.

Primitives: BLS12-381 (outer proving-system curve) · Jubjub (embedded curve over the BLS12-381 scalar field) · KZG polynomial commitments over BLS12-381 · Plonk arithmetization (midnight-proofs crate, began as a fork of PSE halo2 v0.3.0, now standalone) · Pluto-Eris (legacy, replaced on testnet 2025-04-28) · BIP-340 Schnorr over secp256k1 (transaction signatures, per the ledger specification) · Schnorr over Jubjub with a Poseidon challenge (in the ledger's transient-crypto layer) · sr25519 (Aura block-authoring authority keys; Aura-to-BABE migration in progress) · Ed25519 (GRANDPA finality authority keys) · ECDSA over secp256k1 (BEEFY attestation keys and partner-chain cross-chain keys) · X25519 (libp2p Noise handshake for peer transport) · Homomorphic Pedersen commitments (Zswap value commitments) · Poseidon (ZK-friendly hash over the BLS12-381 scalar field; used for key derivation and as a CTR-mode cipher for note encryption) · SHA-256 (primary hash; also the one-way function behind Zswap shielded coin public keys) · NightStream lattice proving system (post-quantum R&D, approved Linux Foundation Decentralized Trust lab; implemented as SuperNeo folding for CCS building on Neo, with HyperNova-style IVC, Ajtai module-SIS commitments and a Poseidon2 transcript over the 64-bit Goldilocks field with a degree-2 extension; no parameter set chosen, not deployed on Midnight mainnet or testnet)
1b · shor grover pq tag 4 / 20
Tags:
  • BLS12-381 → Shor-break-via-pairings
  • KZG over BLS12-381 → Shor-break-via-pairings
  • Plonk-KZG → Shor-break-via-pairings (proof binding rests on the pairing problem)
  • Jubjub → Shor-break-via-DL
  • Pedersen commitments → Shor-break-via-DL (binding only; hiding is information-theoretic)
  • Pluto-Eris (legacy) → Shor-break-via-DL
  • BIP-340 Schnorr over secp256k1 (transactions) → Shor-break-via-DL
  • sr25519 (Aura authoring) → Shor-break-via-DL
  • Ed25519 (GRANDPA finality) → Shor-break-via-DL
  • ECDSA secp256k1 (BEEFY, cross-chain) → Shor-break-via-DL
  • X25519 (libp2p Noise transport) → Shor-break-via-DL, harvest-now-decrypt-later on peer traffic
  • Poseidon → Grover-weaken (research-grade ZK hash)
  • SHA-256 → Grover-weaken (effective 128-bit preimage)
  • NightStream lattice proving system (R&D only, not deployed) → PQ-conjectured-safe lattice (Ajtai module-SIS commitments, SuperNeo folding per the repository; announced-only, zero deployment)
1c · family diversity 0 / 20

Zero PQ families deployed. Pre-cap state.

1d · nist security category 0 / 20

No primitive maps to NIST PQC categories 1-5. BLS12-381 and secp256k1 target roughly 128-bit classical security; Poseidon parameter sets target 128-bit classical. Shor breaks every curve and pairing primitive; Grover halves hash preimage levels.

1e · implementation quality 9 / 20

midnight-proofs began as a fork of PSE halo2 v0.3.0 and is now maintained as a standalone implementation; midnight-curves originated as forks of blstrs and the Zcash jubjub implementation and is likewise standalone. Versions pinned in the shipping node at evaluation: midnight-proofs 0.7.2 and 0.8.1, midnight-curves 0.2.1 and 0.3.1, midnight-ledger 8.1.1, midnight-transient-crypto 2.2.0 and 3.0.0. A 2024 collaboration with an external formal-methods firm and Intersect produced open-source recursive-proof work in Halo2. No formal verification of the Midnight stack and no constant-time validation is published. Plonk plus KZG is Tier 3 cryptanalytic maturity; Poseidon is Tier 4 research-grade. No public audit report for the mainnet cryptographic stack was retrievable at evaluation date.

2 Quantum Recovery Exposure weight 10% 18 / 100
Forge subtotal: 15/75 Decrypt subtotal: 3/25
2a · active key exposure 4 / 20

Unshielded transaction authority is a BIP-340 Schnorr verifying key on secp256k1, revealed on first spend. Shielded Zswap coin public keys are SHA-256 images of a random 256-bit secret, so the coin-spend authority itself is not a revealed curve point, but spend authorization is a zk-SNARK whose soundness rests on Plonk with KZG over BLS12-381 and is therefore forgeable post-Shor. Nine named federated node operators hold Aura sr25519 authoring keys and GRANDPA Ed25519 finality keys that sign every block, a concentrated active-Forge surface.

2b · cold key exposure 6 / 20

Mainnet history is about five months at evaluation (genesis 2026-03-17). The Zswap receiving key includes a Jubjub encryption public key that must be published to receive shielded value, so recipient key material is on the public record independent of spend activity. The NIGHT Glacier Drop distributed to holders of eight token bases (ADA, BTC, ETH, SOL, XRP, BNB, AVAX, BAT), with over 3.5 billion NIGHT claimed by more than 170,000 wallet addresses in the 2025-08-05 to 2025-10-20 window, leaving a large published address set with a long unclaimed tail.

2c · sig long term validity 5 / 20

Every transaction-authorizing signature on the chain since genesis on 2026-03-17 is forgeable post-Shor, whether it is a BIP-340 Schnorr signature on the unshielded path or a zk-SNARK spend proof on the shielded path. Block-authoring and finality signatures carry no PQ attestation layer. Audit-trail non-repudiation does not survive Shor.

2d · encryption confidentiality hndl 3 / 10

Validator peer transport is libp2p Noise over X25519, with no PQ component, so validator-mesh traffic is harvest-now-decrypt-later exposed. Live handshake probes on 2026-08-19 found the public web edge and the public third-party RPC edge both negotiating the X25519MLKEM768 hybrid group under TLS 1.3, which protects client-to-RPC traffic in transit against a harvesting adversary. Partial credit reflects that measured hybrid edge; it is unannounced, undocumented by the chain, may be a content-delivery-network default, and does not extend to the consensus mesh.

2e · note ciphertext payload 0 / 30

Zswap note encryption establishes a shared secret by non-interactive Diffie-Hellman over Jubjub, derives a key from that point with the Poseidon-based transient hash, and encrypts the payload with Poseidon used as a block cipher in CTR mode. Confidentiality therefore rests entirely on the discrete-log problem on Jubjub. An adversary harvesting note ciphertexts today decrypts every Midnight private state transition once Shor lands, exposing the regulated-industry data Midnight is pitched to protect (payroll, KYC, healthcare). No PQ KEM, no hybrid testnet, no historical re-encryption plan.

3 Metadata, Anonymity & Confidentiality weight 25% 26 / 100
Anonymity subtotal: 30/80 Confidentiality subtotal: 1/40
3a · tx graph visibility 14 / 20

The Kachina-based architecture shields private contract state behind zk-SNARK proofs, publishing only the proof, the public state delta and the encrypted note payload. Zswap combines the Zcash and SwapCT designs, keeping unspent coins undeterminable through paired commitment and nullifier sets over a Merkle tree. The Compact DSL forces explicit private and public state declaration, and selective disclosure lets a holder prove facts without revealing the underlying data. A transparent unshielded path also exists. Address reuse persists.

3b · rpc mempool concentration 6 / 20

Top-3 RPC: a public third-party RPC service, Midnight-foundation infrastructure, and node-operator-run endpoints. The federated phase concentrates RPC observability among the nine named node operators. Mempool gossip is observable to the federated operator set. Operator metadata retention is undeclared at protocol level.

3c · cross chain bridge correlation 5 / 20

The canonical interface is the Cardano partner-chain link, which the node reaches by observing Cardano mainchain state through a chain indexer, and which is observable on the Cardano side. The NIGHT Glacier Drop drew claims from holders of ADA, BTC, ETH, SOL, XRP, BNB, AVAX and BAT, so more than 170,000 claiming addresses published correlatable identity material on their source chains. Source-to-destination linkability is high.

3d · retroactive de anonymization 1 / 20

The dominant confidentiality risk. Recipient key derivation, the note-encryption Diffie-Hellman on Jubjub, the Pedersen value-commitment binding, and the Plonk with KZG proof binding over BLS12-381 all rest on discrete-log or pairing hardness. Once Shor lands, every historical Midnight private record encrypted to a published Jubjub encryption key is decryptable by any party that harvested the chain. This is a one-shot mass de-anonymization of every private transition since genesis on 2026-03-17. Partial credit only because the transparent unshielded path is unaffected.

3e · mixnet shuffle 5 / 20

No protocol-level mix network or cryptographic shuffle. Privacy comes from the SNARK-based Kachina and Zswap record model itself. Wallet-level operations across multiple shielded transitions provide some indistinguishability.

3f · content payload encryption 0 / 20

No public commitment covers note or shielded-state payload encryption. The NightStream lab's published scope is a proving system: it names arithmetization, folding, developer tooling, migration paths from existing proof systems, and multi-platform verification targets, and it names no note-encryption KEM. The related integration analyses in Midnight's engineering org cover MPC key custody and P-256 WebAuthn passkey account-binding, not payload confidentiality; the same repository's research tracker lists lattice-friendly address schemes, polynomial commitment schemes, MPC and anonymous credentials as items still open and unchecked. Note encryption remains Diffie-Hellman over Jubjub with Poseidon-CTR, with no hybrid PQ KEM announced, on testnet or deployed, and no historical re-encryption plan. Rubric floor 0: the announcement tier requires a note-encryption-specific announcement, which does not exist.

4 Migration Architecture weight 12% 35 / 100
4a · crypto agility 5 / 15

The Pluto-Eris to BLS12-381 proving-system change, announced 2025-04-15 and shipped as part of the testnet upgrade of 2025-04-28, is a real algorithm-switch event with published effects: verification time 12ms to 6ms per proof and proof size 6KB to 5KB. It is a genuine crypto-agility precedent, though it moved from one Shor-vulnerable curve family to another. No formal crypto-agility specification covers future swaps of curve, signature scheme or proof-system family.

4b · aa key rotation 3 / 20

Key derivation follows the Substrate and partner-chain toolchain; no account-abstraction primitive comparable to ERC-4337, EIP-7702 or native AA in zkSync or Starknet is documented. Selective disclosure enables read-capability sharing but is not algorithm rotation. No client-layer PQC path.

4c · hard fork track record 8 / 15

Short track record. Testnet operated from 2024 with multiple coordinated upgrades, and the Pluto-Eris to BLS12-381 proof-system swap (testnet, 2025-04-28) was a coordinated cryptographic change. Mainnet launched cleanly at genesis on 2026-03-17. Since launch, mainnet was upgraded to the Node 1.0.0 bundle in July 2026, a maintenance version bump rather than a primitive change, aligning production with the Preprod stack (Node 1.0.0, Indexer 4.3.3, Proof Server 8.1.0). Midnight also published node-operator guidance in May 2026 for adapting infrastructure to Cardano's externally-imposed Van Rossem hard fork; no post-event report confirming the outcome or downtime was retrievable, so that episode is not credited as a completed coordination event. No contested forks. No Midnight-initiated mainnet cryptographic fork yet.

4d · hybrid deployment readiness 4 / 15

A named replacement program for the proving core exists in the public record: NightStream, an approved Linux Foundation Decentralized Trust lab whose published scope includes migration paths from Halo 2, PLONK and STARKs, and multi-platform verification targets that name Midnight's Compact, with active public commits through August 2026. Midnight's own public architecture map places NightStream in the ZK proof-system layer alongside BLS12-381 and Plonk with KZG, classing NightStream as research and the other two as current. Midnight's engineering org carries integration analyses written against NightStream's actual constraints (Goldilocks 64-bit field, roughly 1 kHz proved execution, 500MB to 2GB memory, browser and mobile WASM): MPC key-custody candidates (Shamir with a TEE, FROST, GG20 and CGGMP) and a two-phase P-256 WebAuthn passkey to native-key binding design costed at roughly 15K to 25K constraints for the one-time binding proof. This is real design engagement, but it is a pure-PQ proving-system replacement path, not a hybrid classical-plus-PQ composition for consensus signing or note encryption; nothing is Foundation-committed, dated or deployed. Countervailing repository evidence: NightStream removed its Midnight bridge crate, records no publicly disclosed adopters, carries no release and no tag, and lists chain-facing deployment wiring as unfinished. Plonk with KZG over BLS12-381 remains the deepest agility constraint: replacing it requires re-instantiating the Compact compiler, the proving system and the verifier circuits.

4e · stateful hash state management 15 / 15

No stateful hash signature schemes in use. Default 15/15.

4f · bft aggregation path 0 / 20

Block authoring signs with Aura sr25519 authority keys and finality with GRANDPA Ed25519 authority keys, with no signature aggregation at consensus. BEEFY with an MMR provides a classical light-client attestation path on ECDSA secp256k1, not a PQ aggregation path. No PQ aggregation is declared, no spec, no testnet pilot.

5 Deployment Execution weight 18% 5 / 100
5a · mainnet pqc traffic pct 0 / 25

0% of consensus signing, transaction signing, note encryption or proof generation runs on a PQC primitive.

5b · pqc code in consensus client 0 / 15

No PQC primitive in the Midnight client stack. midnight-proofs is Plonk with KZG over BLS12-381; no FRI, no lattice folding, no ML-DSA, no SLH-DSA, no ML-KEM. Re-verified independently at evaluation: a code search of midnight-node, midnight-ledger and midnight-zk for post-quantum, dilithium, ML-KEM, ML-DSA, kyber, sphincs, falcon, lattice and nightstream returns zero hits in all three repositories, each of which was pushed to on 2026-08-19 and is therefore current and indexed. All PQ material in the organization sits in a separate R&D and design repository and one documentation file.

5c · validator pqc key adoption 0 / 15

0 of the 9 named federated node operators run PQC consensus keys. Authority keys remain sr25519 for authoring and Ed25519 for finality.

5d · published dated milestones 0 / 10

VOIDED to 0 per v3.1 rule (5a = 0). No dated, enforcement-mechanism-backed PQ milestone exists in any roadmap publication. The NightStream lab's own published development timeline states four phases each labelled with an unresolved placeholder duration rather than a date, publishes no Midnight-deployment milestone, and its repository carries no release and no tag.

5e · pqc washing delta 5 / 15

Announced PQC exists: the NightStream lab approved under Linux Foundation Decentralized Trust with its proposal merged 2025-09-15, and a stream on Midnight's own video channel on 2026-06-04 titled as a post-quantum proving system, both inside the trailing 12 months. Shipped PQC remains 0: no PQC primitive is verifiable on mainnet under any named scheme. Announced-versus-shipped band above 1.5, so the 10-point Dim 5 deduction applies here. Mitigations recorded, not credited: the program is framed as research by its own maintainers, never claims live quantum safety, and the developer dev-diary is silent on it. A 2026-02-13 conference talk and a reported November 2025 social announcement appear only in secondary coverage, are framed around Cardano rather than Midnight, and are not counted.

5f · signature footprint multiplier 0 / 20

Undisclosed. The NightStream lab's published performance targets are indicative and generic (proof generation in seconds on consumer hardware, proof size in the tens of kilobytes) with no Midnight integration figures, no bytes-per-block and no verifier-cost number. No PQ signature scheme is announced for consensus or account signing, so bytes-per-block under PQ is unknown.

6 Supply Chain Vendor Readiness weight 18% 17 / 100
6a · wallet 4 / 25

The Cardano-native Lace wallet is the primary wallet path via the partner-chain integration, and a wallet SDK education module launched in July 2026 covering seed-based key derivation and DUST registration, not PQC. No top-3 wallet has published a PQC roadmap covering Midnight key derivation. Hardware wallet support is in development; no hardware-wallet vendor has committed to PQ for Midnight's curves.

6b · bridge 4 / 25

The canonical Midnight to Cardano partner-chain link is internal to the partner-chain framework, with the node observing Cardano mainchain state through a chain indexer. External multi-chain bridges are not documented as live. No bridge has a published PQC roadmap.

6c · custodian 5 / 25

The nine named federated node operators include institutional infrastructure and payments firms (Worldpay, Bullish, MoneyGram, Pairpoint by Vodafone, eToro, AlphaTON Capital, Google Cloud, Blockdaemon, Shielded Technologies), several custody-adjacent. Top-tier institutional custody does not yet support Midnight native asset custody at scale. No named operator has published a PQC roadmap covering Midnight keys.

6d · rpc hsm tee infra 4 / 25

RPC is served by a public third-party RPC service, Foundation infrastructure and operator-run endpoints. Live probes on 2026-08-19 show the public third-party RPC edge negotiating the X25519MLKEM768 hybrid TLS group, which is transport-layer only and is not a published PQC roadmap covering Midnight key material. No documented HSM vendor PQC integration for Midnight curve material. TEEs are not in the consensus path, though a hosted TEE prover appears on the roadmap as future work. No tile ships PQC for key material.

7 Governance & Coordination weight 5% 37 / 100
7a · validator stake distribution 7 / 20

Federated mainnet launch (Kūkolu phase) with a named-entity operator set of nine: Worldpay, Bullish, MoneyGram, Pairpoint by Vodafone, eToro, AlphaTON Capital, Google Cloud, Blockdaemon and Shielded Technologies. Concentrated by design during the federated phase. The Foundation states it intends to transition to a fully decentralized network, with the Mōhalu phase opening validator participation more broadly.

7b · upgrade cadence under pressure 11 / 20

The Pluto-Eris to BLS12-381 proving-system migration (testnet, 2025-04-28) is a substantive coordinated cryptographic upgrade. Mainnet reached genesis on 2026-03-17. Post-launch, the mainnet bundle was upgraded to Node 1.0.0 in July 2026, and node-operator guidance was published in May 2026 for adapting to an externally-imposed Cardano-side hard fork, though no post-event outcome report was retrievable. Mainnet window is still short at about five months, and there is no demonstrated coordinated upgrade under live attacker pressure.

7c · named coordination lead 15 / 20

Midnight Foundation (Switzerland) and Input Output are the named institutional leads. Two additions since baseline: a formal Midnight Improvement Proposal process launched 2026-08-04 with defined stages from Idea through Editor Vote, a named accountable author requirement, GPG-signed commits, a minimum two-week community-commentary window and editor votes, a real coordination venue that carries no PQ content yet; and Midnight Foundation plus Input Output staff are named initial committers of the NightStream post-quantum proving-system lab under Linux Foundation Decentralized Trust, which has a published scope and a named sponsor. Still no Foundation-internal PQ migration working group and no named PQ-lead with a migration mandate.

7d · adversarial coordination precedent 4 / 20

No adversarial-pressure coordination event in the short history. The proof-system migration was planned, not attack response.

7e · canary tripwire mechanism 0 / 20

No community honeypot, no rate-limited spending rule, no cryptographic tripwire, no automated-response mechanism.

Source-disagreement disclosure

v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.

Privacy guarantees absolute vs post-Shor

Industry coverage describes Midnight's privacy in absolute terms (regulated-industry-grade, rational privacy) without distinguishing classical confidentiality from post-Shor retroactive decryption. LayerQu separates the two: the Kachina-based record model holds against classical adversaries today; against a future Shor adversary harvesting ciphertexts, the same guarantees fail retroactively.

Mainnet launch date: genesis block vs announcement post

Midnight's own March 2026 network update states the genesis block was created on March 17 at 3:17am UTC. The same update, and general crypto press, are dated 2026-03-31, and secondary coverage has been read as putting the launch on that later date. We anchor every exposure clock to the genesis timestamp of 2026-03-17, which is the date from which private records exist to harvest.

Proving-system migration date

Midnight's dev-diary post announcing the Pluto-Eris to BLS12-381 switch is itself dated 2025-04-15, while its body states the switch happened as part of the testnet upgrade on 2025-04-28. We anchor to 2025-04-28 as the migration event and treat 2025-04-15 as the announcement.

NightStream: lab approval date, framing, and Midnight-channel silence

The lab proposal was merged into the Linux Foundation Decentralized Trust approved-labs record on 2025-09-15, and the lab's GitHub organization was created 2025-10-09. Secondary crypto press instead dates the public reveal to a 2026-02-13 conference talk, frames the program around Cardano rather than Midnight, and does not mention the Linux Foundation at all. Meanwhile Midnight's own developer dev-diary and main blog carry no NightStream or post-quantum content through 2026-08-17, and the Foundation's news page could not be checked (repeatedly unreachable behind a rate-limiting checkpoint). We score from the verifiable engineering record. A reader relying only on Midnight's product documentation would wrongly conclude no PQ program exists; a reader relying only on the press would wrongly conclude this is a Cardano-only program with no institutional home.

NightStream scope text vs shipped implementation

The approved lab scope names a lattice-based folding protocol as 'NEO, LatticeFold+ or similar'. The implementation in the repository is a SuperNeo folding scheme for CCS building on Neo, with a HyperNova-style IVC layer, Ajtai module-SIS commitments and a Poseidon2 transcript, targeting Goldilocks with a degree-2 extension and a Spartan2 terminal compression. No LatticeFold+ instantiation exists in the tree. We name the implemented protocol, not the scope's option list, and we record that no parameter set has been selected.

NightStream to Midnight integration: intent signals vs repository state

Midnight's own public architecture map places NightStream in the ZK proof-system layer next to BLS12-381 and Plonk plus KZG, with NightStream classed as research and the other two classed as current, which is documented intent. Against that, the NightStream repository removed its Midnight bridge crate, its adopters file records that no publicly disclosed adopters are known, it carries no release and no tag, and its own roadmap lists chain-facing deployment wiring as unfinished. We record the intent and decline to describe NightStream as a committed replacement for the Plonk plus KZG core, which no source states.

Hybrid TLS at the client edge vs classical validator transport

Live handshake probes on 2026-08-19 show the public web edge and the public RPC edge both negotiating the X25519MLKEM768 hybrid group under TLS 1.3. Validator peer transport in the node uses libp2p Noise over X25519 with no PQ component. We cannot determine from public sources whether the hybrid edge reflects a Midnight decision or a content-delivery-network default, so it is credited only as a measured transport-edge property and not as a chain PQ commitment.

Delta-QRI under alternative weighting

Under alternative weighting that increases Dim 3-Confidentiality from 10% to 15% (and reduces Dim 6 from 18% to 13%), Midnight's QRI drops from 22 to ~21, reinforcing the Stage-1 and borderline-Acknowledged read.

Announcement-to-shipped ratio

Announced: 2. Shipped: 0. Ratio: 2.

Tag: >1.5 deduction, announced-with-zero-shipped: 2 verified dated PQ announcements in the trailing 12 months against 0 shipped primitives, so the deduction band applies. Mitigations noted: the program is consistently framed as research by its own maintainers, who state it is not production-ready and not independently audited; it has never claimed live quantum safety; and Midnight's developer dev-diary is silent on it. Watch window: first NightStream integration on a Midnight testnet.

Peers in the privacy-focused chain profile

9 chains closest to Midnight by Stage then QRI.

S3 55
S2 32
S1 22
S1 24
S1 25
S1 29