industry · quantum risk
Compound oracles & Quantum Risk
Verdict
Compound oracle dependencies are not quantum-proof. Bad or forged classical oracle signatures can trigger wrongful liquidations or freeze risk logic.
Overview
Lending safety depends on correct prices. Oracle adapters and reporter keys are first-class crypto inventory items.
Cross-read Chainlink/Pyth and the oracles hub for feed-level framing.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: Oracle adapters and underlying feed signers
- Hosts/context: Price feeds securing markets
What breaks
- Compromise of oracles related keys for Compound
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/compound for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Multiple oracles = PQC?
Redundancy is classical resilience; algorithms may still be classical.
Related?
/is-quantum-proof/oracles
Key concepts (technical dictionary)
Terms used on this page — open a definition: