industry · quantum risk
Compound admin keys & Quantum Risk
Verdict
Compound admin and guardian keys are not quantum-proof. Classical signatures still control pauses, upgrades, and risk parameter paths unless a PQ scheme is verified.
Overview
Compound-style money markets separate user positions from privileged roles that can pause markets or execute governance.
Quantum inventory for Compound must list those privileged addresses and the EOAs behind any multisig—not only cToken holders.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: Pause/guardian, COMP governance executors, market listing roles
- Hosts/context: Ethereum and multi-chain Compound deployments
What breaks
- Compromise of admin keys related keys for Compound
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/compound for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Does governance replace admin risk?
Governance changes who holds power; it does not change classical signature hardness.
Full protocol page?
/is-quantum-proof/compound
Key concepts (technical dictionary)
Terms used on this page — open a definition: