industry · quantum risk
Compound governance & Quantum Risk
Verdict
Compound governance is not quantum-proof. Voting and execution use classical host-chain signatures and privileged executors.
Overview
COMP governance can change market parameters and upgrades through on-chain processes with delays.
Large delegates and executor keys are high-value classical targets under CRQC assumptions on secp256k1.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: COMP voters, delegates, timelock/executor keys
- Hosts/context: COMP holders and Governor executors
What breaks
- Compromise of governance related keys for Compound
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/compound for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Is voting quantum-safe?
Votes authorize with classical keys today on typical deployments.
Related hub?
/is-quantum-proof/lending
Key concepts (technical dictionary)
Terms used on this page — open a definition: