Watchlist 0
SUI · L1 · QRI 25 · BAND 2 Planning Hybrid FAIL (no shipped hybrid) · Stage 1 · Washing 0.5x

Sui is that rare chain with four signature schemes already live (Ed25519, secp256k1, secp256r1, BLS12-381) and a cryptography team that reads the literature. What it does not have is any of those schemes being post-quantum. The type system is ready for ML-DSA. The code is not.

inLinkedIn XPost Scorecard JSON Compare Verified 2026-04-17

Summary

Sui has above-baseline crypto agility thanks to multi-scheme native signature support (Ed25519/secp256k1/secp256r1/BLS) and MystenLabs' research bench (fastcrypto, Truncator). No mainnet PQC code, no published PQ roadmap. Stage 1 assignment rests on research output and type-system readiness rather than deployment.

What the gates say

  • Hybrid: FAIL. no shipped hybrid
  • Evidence: PASS. Sources reconstructable by third party.
  • Primitive naming: PASS. Named primitives at every scored sub-level.

Burn-vs-rescue policy on file

none-announced; multi-scheme substrate suggests rescue-favored path

Seven dimensions

Each dimension scores 0-100 internally; the weighted roll-up produces the QRI on the left. Open a row to read the sub-score detail.

1 Cryptographic Exposure 38 / 100
1a_primitive_inventory 14 / 20

Multi-scheme signature support native in Move.

Primitives: Ed25519 (default) · ECDSA secp256k1 · ECDSA secp256r1 (P-256) · BLS12-381 (aggregation) · SHA-3 / Blake2b (hashing)
Evidence:
1b_shor_grover_pq_tag 8 / 20
1c_algorithm_family_diversity 6 / 20

Multiple elliptic-curve families but no PQ family deployed.

1d_nist_security_category 4 / 20
1e_implementation_quality 6 / 20
2 HNDL Exposure 35 / 100
2a_active_key_exposure 8 / 20

Pubkeys exposed on first tx. ~28 months mainnet age.

2b_cold_key_exposure 10 / 20

Younger chain; smaller dormant surface. MystenLabs / SUI Foundation holdings classical.

2c_signature_longterm_validity 9 / 20

Multi-scheme but all classical; historical sigs Shor-forgeable.

2d_encryption_confidentiality 8 / 20

Standard TLS; no PQ KEM observed.

3 Metadata & Privacy Exposure 30 / 100
3a_tx_graph_visibility 7 / 20

Transparent ledger; object-centric model exposes ownership graph.

3b_rpc_mempool_concentration 8 / 20

MystenLabs RPC, BlockVision, Shinami concentration.

3c_cross_chain_bridge_correlation 8 / 20

Wormhole, LayerZero bridges correlate addresses.

3d_retroactive_deanon_risk 7 / 20

No shielded pools; transparent-inference risk.

4 Migration Architecture 55 / 100
4a_crypto_agility 16 / 20

Multi-scheme signature support (Ed25519/secp256k1/secp256r1/BLS) shows in-protocol agility; adding ML-DSA requires protocol upgrade but type-system is prepared.

4b_account_abstraction_key_rotation 14 / 20

zkLogin + Passkeys + Move object-centric accounts allow some migration; not full AA parity.

4c_hard_fork_track_record 14 / 20

Regular protocol upgrades; smooth coordination with validators.

4d_hybrid_deployment_readiness 11 / 20

Truncator research (MystenLabs) on signature compression suggests PQ literacy; no shipped hybrid.

5 Deployment Execution 12 / 100
5a_mainnet_pqc_pct 0 / 20

Zero PQC on mainnet. Mosca cap triggers.

5b_pqc_code_in_client 3 / 20

fastcrypto is extensible; no ML-DSA/Falcon merged.

5c_validator_pqc_adoption 0 / 20

Zero PQ validators.

5d_published_milestones_count 6 / 20

Milestones: (1) Truncator PQ-adjacent research, (2) multi-scheme signature support as agility prep.

5e_pqc_washing_delta 3 / 20

Low: modest research claims, no overclaim.

6 Supply Chain Vendor Readiness 10 / 100
6a_wallet 2 / 20
6b_bridge 3 / 20
6c_custodian 3 / 20
6d_rpc_hsm 2 / 20
7 Governance & Coordination 48 / 100
7a_validator_stake_distribution 10 / 20

~110 validators; concentration in top stakers moderate.

7b_upgrade_cadence_under_pressure 13 / 20

Protocol versioning and epoch-based upgrades coordinated by MystenLabs / SUI Foundation.

7c_named_coordination_lead 14 / 20

Named: MystenLabs (Evan Cheng, Kostas Chalkias), SUI Foundation.

7d_adversarial_coordination_precedent 11 / 20

No cryptographic emergency; regular upgrades show coordination but no adversarial precedent.

The X + Y vs Z inequality

X (data shelf life): 5-15

Y (migration time): 4-8 (multi-scheme substrate helps)

Z10 (10% CRQC year): 2036 · Z50 (50%): 2041

Verdict: X+Y > Z (danger).

Four-scenario grid

ScenarioValue preservedPrivacy preserved
quantum never 100% 100%
arrives suddenly pre migration 15% 10%
arrives slowly post migration 65% 35%
arrives slowly mid migration 40% 20%

Peers in the L1 profile

Order-book view of the 9 chains closest to Sui by QRI.

Public artifacts used for this scorecard

Each entry below is a sub-score citation. Clicking the link takes you to the public source. A third party should be able to reconstruct every number on this page from these URLs in 48 hours.

Cryptographic Exposure · 1a_primitive_inventory

Multi-scheme signature support native in Move.

Supply chain snapshot

wallet Sui Wallet · Suiet · Nightly 0 PQC roadmaps
bridge Wormhole · LayerZero · Portal 0 PQC roadmaps
custodian Coinbase Custody · BitGo · Copper 0 PQC roadmaps
rpc_hsm MystenLabs RPC · BlockVision · Shinami 0 PQC roadmaps

A chain's supply chain cannot migrate faster than its slowest dependency. Zero PQC roadmaps in any of the four categories is a structural blocker, not a lagging indicator.

Analyst notes on the scoring

Stage 1. Better structural agility than most L1 peers. Gate failure: no shipped hybrid. MystenLabs cryptography team (Chalkias) is a credibility asset if they ship.

Scorecard metadata

  • Profile: L1
  • Scored: 2026-04-17 by layerqu-v2-scoring-agent-5
  • v1 reference: chainscreen-v1-archive
  • QRI raw: 28 · after caps: 25
  • Confidence interval: ±6
  • PQC washing ratio: 0.5x
  • Burn-vs-rescue: none-announced; multi-scheme substrate suggests rescue-favored path

Caps triggered

  • mosca_cap_60 (5a=0)
  • sutor_cap_50 (only 2 milestones)
LayerQu · Sui scorecard v2 · reconstructs from public evidence
Methodology · Desk · API