Functor, scanned by Quantum Core

Functor's own CBOM

Every Functor release is scanned by Quantum Core before it ships. The release fails if any cryptographic weakness is found. The cryptography inventory (CycloneDX 1.6 CBOM) is published here, unedited.

Result

Loading the published scan…

Cryptographic assets

One row per algorithm, with every file it appears in. NIST quantum level is the NIST post-quantum security category the algorithm meets (0 = none: Shor's algorithm breaks it on a large enough quantum computer).

AssetRoleClassical bitsNIST quantum levelPlacesMigration priorityFiles

What it means

  • No weaknesses. Nothing broken today: no weak hashes, no insecure randomness in security code, no hardcoded secrets in shipped code. A release with any of these does not deploy.
  • The quantum exposure is the signatures. Accounts sign orders with ECDSA over secp256k1 (EIP-712, the same as Ethereum and Hyperliquid), so wallets like MetaMask and Rabby work. A large quantum computer could forge these signatures. Functor's migration plan adds a post-quantum signature (ML-DSA, NIST FIPS 204) alongside, before mainnet.
  • The hashes are fine. SHA-256 (state roots, block hashes) and Keccak-256 (signing digests) keep about 128 bits of security against quantum search. They stay.
  • Releases of Quantum Core itself are signed with ML-DSA-65 (how to verify).

A CBOM is a heuristic inventory of the source, not a formal audit. Scope: what Functor ships (the chain, the test node host, the app's JavaScript, the options engine, the posting worker), defined in the repository's .quantumignore.

Migration plan

NIST will disallow ECDSA after 2035 (NIST IR 8547). Functor's plan: hybrid first (a post-quantum signature alongside, never instead of, the wallet's), then post-quantum only for anything that moves money.

SignatureChangeWhen
Validator votesML-DSA-44 (FIPS 204) from day one, no ECDSA everwith multi-validator consensus, Jan–Feb 2027
Bridge attestationsML-DSA-44 and ECDSA; the escape hatch already rests on SHA-256with the bridge, Apr–Jun 2027
Accountsopt-in post-quantum key: withdrawals and transfers then need both signaturesmainnet alpha, Apr–Jun 2027
Session keys (trading only)Falcon-based standard once final, else ML-DSA-44when NIST finalises it
Defaultnew accounts register a post-quantum key before their first withdrawal2028
ECDSA-onlycan no longer move money (trading continues); announced 12 months aheadno later than 2030, sooner in an emergency

Downloads