industry · quantum risk
Aave oracles & Quantum Risk
Verdict
Aave oracle paths are not quantum-proof. Liquidations and LTV logic depend on classical feed integrity and admin rights to change sources.
Overview
Aave markets are only as sound as their prices. Document oracle providers and who can rotate them on each network deployment.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: Oracle providers and Aave oracle admin roles
- Hosts/context: Aave price oracles per deployment
What breaks
- Compromise of oracles related keys for Aave
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/aave for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Related?
/is-quantum-proof/oracles and chainlink pages
Protocol?
/is-quantum-proof/aave
Key concepts (technical dictionary)
Terms used on this page — open a definition: