Direct answer · §01 Proof system

Are STARKs post-quantum secure?

Short answer

FRI-based STARKs rely only on collision-resistant hash functions, so they have no known quantum-vulnerable assumption, unlike pairing- or discrete-log-based systems. This is a plausibility argument about assumptions, not a proof of quantum security, and it says nothing about the rest of your system — signatures, key exchange and encryption remain separate problems. See Section 01.

Cite this page
MarketComp (2026). Are STARKs post-quantum secure?. The ZK Field Manual (Version 1.3). MarketComp. https://zkpick.com/faq/are-starks-post-quantum-secure/
@misc{zkfieldmanual-are-starks-post-quantum-secure,
  title        = {Are STARKs post-quantum secure? — The ZK Field Manual},
  author       = {MarketComp},
  year         = {2026},
  version      = {1.3},
  howpublished = {\url{https://zkpick.com/faq/are-starks-post-quantum-secure/}},
  note         = {Accessed: YYYY-MM-DD}
}