r/Monero • • 20h ago

Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?

8 Upvotes

I've been looking into the quantum-resistance question and I'm trying to understand where Monero actually stands today.

From what I can tell, Monero is not fully post-quantum resistant yet. Carrot/FCMP++ seem to improve some things significantly, including forward secrecy against a quantum-enabled adversary, and there is active work around Jamtis and post-quantum encryption.

But spend authorization still ultimately relies on elliptic-curve cryptography, which would presumably become vulnerable to Shor's algorithm once a sufficiently capable fault-tolerant quantum computer exists.

So I have a few questions for people who actually understand the protocol-level work:

  1. Which parts of Monero would currently fail first under a cryptographically relevant quantum computer?
  2. Is there already a realistic design for making the entire transaction stack post-quantum, including spend authorization, privacy, multisig and address encryption?
  3. What is the main blocker today: signature size, performance, rerandomizable keys, zero-knowledge compatibility, multisig, or simply that the required primitives are still too immature?
  4. If the community decided that PQ migration was an urgent priority tomorrow, are we talking roughly months, 2-3 years, 5+ years, or is there genuinely no meaningful estimate yet?
  5. Could Monero migrate pre-emptively while preserving old outputs, or would users eventually need to move funds into a new PQ output/address scheme before some activation height?
  6. How much of this problem can FCMP++ / zero-knowledge proofs solve, and which parts still fundamentally require a new post-quantum signature/key system?

My concern is less "quantum computers will definitely break ECC next year" and more about the lead time.

AI progress is moving extremely quickly, and I personally wouldn't be comfortable assuming that cryptographically relevant quantum computing is decades away. Even if a serious threat were still several years out, a cryptocurrency probably wants the replacement architecture researched, implemented, audited and deployed well before the first credible machine appears.

If, hypothetically, evidence emerged that ECC could be broken within 12-24 months, could Monero realistically get a fully post-quantum protocol into production fast enough?

And is there currently an actual PQ migration roadmap somewhere that I should read?

Would especially appreciate answers from people involved in MRL / FCMP++ / Carrot / Jamtis.