industry · quantum risk
Curve oracles & Quantum Risk
Verdict
Curve-related oracle usage is not quantum-proof. Integrations that treat pool prices as oracles inherit manipulation and classical key risks on consumer protocols.
Overview
Many protocols read Curve pool prices. That is an oracle pattern even when Curve itself is an AMM—inventory both sides.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: Pool price readers and external oracle consumers
- Hosts/context: EMA/pool prices and external feeds used by integrations
What breaks
- Compromise of oracles related keys for Curve
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/curve for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Is Curve an oracle network?
Primarily an AMM; price reads act as oracles for integrators.
Related?
/is-quantum-proof/oracles
Key concepts (technical dictionary)
Terms used on this page — open a definition: