industry · quantum risk
ENS admin keys & Quantum Risk
Verdict
ENS admin keys are not quantum-proof. Controllers that can affect registrations are classical privileged roles.
Overview
Compromise of naming admins is an integrity failure mode—even without moving ERC-20 balances.
Cryptographic profile
- Signatures: Host-chain account signatures for role holders (typically classical ECDSA/Ed25519), Multisig/module keys as deployed
- Hash: Host-chain dependent
- Public-key exposure: Root/controller roles and DAO-executable admins
- Hosts/context: Registrar and controller contracts
What breaks
- Compromise of admin keys related keys for ENS
- Equating role separation or multisig with post-quantum algorithms
- Untracked multi-chain deployments of the same protocol
Mitigations
- Document privileged addresses from official docs per chain
- Hardware/MPC for guardians, admins, and large governors
- Return to /is-quantum-proof/ens for protocol context
- Use category hubs: lending, dex, perps, stablecoins
FAQ
Governance?
/is-quantum-proof/ens-governance
Related?
/is-quantum-proof/dnssec
Key concepts (technical dictionary)
Terms used on this page — open a definition: