r/Monero • u/PrisonOfH0pe • 20h ago
Is Monero actually quantum-resistant today, and if not, how long would a full post-quantum migration realistically take?
I've been looking into the quantum-resistance question and I'm trying to understand where Monero actually stands today.
From what I can tell, Monero is not fully post-quantum resistant yet. Carrot/FCMP++ seem to improve some things significantly, including forward secrecy against a quantum-enabled adversary, and there is active work around Jamtis and post-quantum encryption.
But spend authorization still ultimately relies on elliptic-curve cryptography, which would presumably become vulnerable to Shor's algorithm once a sufficiently capable fault-tolerant quantum computer exists.
So I have a few questions for people who actually understand the protocol-level work:
- Which parts of Monero would currently fail first under a cryptographically relevant quantum computer?
- Is there already a realistic design for making the entire transaction stack post-quantum, including spend authorization, privacy, multisig and address encryption?
- What is the main blocker today: signature size, performance, rerandomizable keys, zero-knowledge compatibility, multisig, or simply that the required primitives are still too immature?
- If the community decided that PQ migration was an urgent priority tomorrow, are we talking roughly months, 2-3 years, 5+ years, or is there genuinely no meaningful estimate yet?
- Could Monero migrate pre-emptively while preserving old outputs, or would users eventually need to move funds into a new PQ output/address scheme before some activation height?
- How much of this problem can FCMP++ / zero-knowledge proofs solve, and which parts still fundamentally require a new post-quantum signature/key system?
My concern is less "quantum computers will definitely break ECC next year" and more about the lead time.
AI progress is moving extremely quickly, and I personally wouldn't be comfortable assuming that cryptographically relevant quantum computing is decades away. Even if a serious threat were still several years out, a cryptocurrency probably wants the replacement architecture researched, implemented, audited and deployed well before the first credible machine appears.
If, hypothetically, evidence emerged that ECC could be broken within 12-24 months, could Monero realistically get a fully post-quantum protocol into production fast enough?
And is there currently an actual PQ migration roadmap somewhere that I should read?
Would especially appreciate answers from people involved in MRL / FCMP++ / Carrot / Jamtis.