industry · quantum risk
Aave governance & Quantum Risk
Verdict
Aave governance is not quantum-proof. Classical signatures authorize votes and executions; Guardian remains a high-value classical role.
Overview
Aave already has an admin-keys spoke; this page focuses on governance power—delegates, proposals, and executors.
Quantum inventory should include large delegates and any emergency Guardian EOAs/multisigs.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: AAVE voters, delegates, Guardian, executor payloads
- Hosts/context: AAVE / governance v3 executors
What breaks
- Compromise of governance related keys for Aave
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/aave for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Admin vs governance?
Both matter; see also /is-quantum-proof/aave-admin-keys
Category?
/is-quantum-proof/lending
Key concepts (technical dictionary)
Terms used on this page — open a definition: