industry · quantum risk
Is Exchange customer auth Quantum Proof? Industry Quantum Risk
Verdict
Exchange customer authentication is not quantum-proof while TLS and tokens are classical. Strong phishing-resistant MFA helps classical risk; still plan algorithm migration on edges.
Overview
User account security is a different layer from wallet crypto—but takeover still empties accounts.
Cryptographic profile
- Signatures: Login TLS, Session tokens, Optional WebAuthn/FIDO, Withdrawal email/2FA channels
- Hash: Session integrity
- Public-key exposure: Account takeover paths into classical withdrawal keys.
- Vertical: exchanges
What breaks
- SMS-only 2FA
- Long-lived sessions
- Classical-only TLS on APIs
Mitigations
- Phishing-resistant MFA
- Hybrid TLS on web/API
- Withdrawal allowlists and delays
FAQ
Related?
/is-quantum-proof/passwordless-fido-quantum
Hub?
/industries/exchanges
Key concepts (technical dictionary)
Terms used on this page — open a definition: