Repository
ethereum/go-ethereum
Scanned on May 20, 2026
Risk score/ 100
High risk
Summary
The ethereum/go-ethereum repository exhibits high quantum vulnerability due to extensive reliance on secp256k1 elliptic curve cryptography and ECDH key exchange mechanisms. These cryptographic primitives will be completely broken by quantum computers running Shor's algorithm, threatening the entire Ethereum blockchain's security model. Immediate planning for post-quantum migration is critical for long-term viability.
0
4
0
0
Top findings
- Highsecp256k1 (Bitcoin curve)
crypto/secp256k1/libsecp256k1/dummy.go:8
Raw evidence
package libsecp256k1 - Highsecp256k1 (Bitcoin curve)
crypto/secp256k1/libsecp256k1/src/int128_struct.h:10
Raw evidence
} secp256k1_uint128; - Highsecp256k1 (Bitcoin curve)
crypto/secp256k1/libsecp256k1/src/int128_struct.h:12
Raw evidence
typedef secp256k1_uint128 secp256k1_int128; - HighECDH / ECDHE
crypto/secp256k1/libsecp256k1/src/modules/ecdh/dummy.go:8
ML-KEM (CRYSTALS-Kyber)
Raw evidence
package ecdh
Scan your own repository
Free. Results in ~90 seconds. CBOM + DORA/NIS2 PDF included.