Crypto Reality Index · Vol.1 · correction appendix

We are withdrawing
a number we published
four days ago.

Vol.1 reported that financial institutions were the least post-quantum ready of the three sectors we measured: 12 endpoints, 4 hybrid, 8 classical, 33% ready. A pre-registered re-measurement on 1 September returned 10 of 11. We cannot reconcile the two, because we did not keep the first sample. The figure is withdrawn.

Issued 1 September 2026 · Dong Nguyen · companion to Crypto Reality Index Vol.1, published 28 August 2026

Vol.1 offered hybrid post-quantum key exchange to 45 public endpoints and reported, for one sector:

Financial institutions — 12 measured · 4 hybrid post-quantum · 8 classical · 33% ready

under the headline “The sector with the tightest deadline is the least ready”. The same page states the work is “reproducible in one command”.

That 33% figure, and the sector verdict built on it, are withdrawn. Four things, in order.

1. We cannot reproduce it, because we did not keep the sample. That is our fault.

The run behind that row went out with no retained host list, no raw tool output, and no recorded tool version. A reader who wants to check it has nothing to check against — and neither do we. The line “reproducible in one command” was not backed by artifacts. This is a process failure on our side, not a caveat about the world.

2. The same finding existed internally in two versions that disagreed.

A companion working document described the same probe as 9/12 (75%) classical-only, 2/12 hybrid, where the published page says 8 classical and 4 hybrid. The two cannot both be right, and the working document’s own figures do not sum to its own denominator. We did not notice until we tried to re-measure. A number that exists in two versions has already stopped being a measurement.

3. A new, pre-registered sample points the other way.

The old sample could not be re-run, so we drew a new one and wrote the selection rule and the resulting host list to disk before running any measurement, so the list demonstrably predates the result.

sample rule : cohort file, sector = banking, sorted by hostname, first 12 (of 64 banking rows)
measured    : 2026-09-01 17:34 (UTC+7)
12 registered -> 11 measured   (one host did not resolve = NOT MEASURED, not a negative)

KEY EXCHANGE    10 of 11 negotiated X25519MLKEM768 (hybrid post-quantum).
                The one exception is a TLS 1.2 endpoint, where hybrid post-quantum
                key exchange does not exist at all.
AUTHENTICATION  0 of 11 post-quantum signatures. All 27 certificate positions across
                the 11 chains are classical: 22 sha256-RSA, 3 sha384-RSA, 2 ECDSA
                (SHA-384). Leaf keys: 10 RSA, 1 ECDSA.

It is consistent with a 40-host run the same day: 31/40 hybrid key exchange, 0/40 post-quantum signatures.

One qualification we would rather state than be asked: that run is not independent of this one on the banking side. Five of the eleven organisations measured here also appear among its sixteen banks. The other twenty-four hosts in it — internet infrastructure, and a control group chosen because they lead on cryptography — share no organisation with this sample, and every one of them is also 0 for post-quantum signatures.

4. Four days is not enough time for the world to have moved.

Vol.1 is dated 28 August. This run is 1 September. Hybrid key exchange has been rolling out fast, but not from 4-of-12 to 10-of-11 in four days. And because the earlier host list was not kept, we cannot establish whether the two samples overlap at all.

That leaves two candidate explanations: the earlier run was measured wrong, or its twelve were not representative of the sector they were used to judge. Both are failures of the report rather than findings about banks — which is why the number is withdrawn rather than revised. Choosing between them would require the artifacts named in (1), and those do not exist.

What does not change — and what it inverts

0 of 11 post-quantum signatures, matching 0/40 in the larger run and 0 of all 27 certificate positions we examined. Key exchange is migrating at the front door. Authentication is not, in any sample we have run.

Vol.1 argued the opposite priority:

“The usual answer to post-quantum is that the deadline is 2030 or 2035, so there is time. That answer holds for signatures. It does not hold for key exchange.”

On our own new numbers that framing is backwards at the front door. The half we called urgent is the half that has largely moved. The half we said had time is the half sitting at zero across every sample we have run. That is the finding Vol.1 should have led with, and it is the one still standing.

Scope note

This sample is not the Vol.1 sample, and cannot be presented as a re-run of it. Both were drawn from the same cohort file, which holds 64 banking hosts; Vol.1 used twelve of them and did not record which. Calling this a before-and-after would be a second unfounded claim.

Reproduce it

tool     one TLS handshake per host (openssl s_client -showcerts), parsed for
         negotiated key exchange and for the signature algorithm of every
         certificate in the chain
sample   cohort file, sector = banking, sorted by hostname, first 12
         - rule written to disk before the run, so the list demonstrably
           predates the result

The host list and the raw JSON are not published here, for the same reason Vol.1 named no institution: this is aggregate reporting about a market, not a scorecard about identifiable organisations. They are retained, and available to a named requester who wants to check our arithmetic.

That is a weaker form of reproducibility than publishing the list, and we say so plainly rather than let the word “reproducible” do work it has not earned — which is the mistake this appendix exists to correct. The finding itself does not depend on our sample: one handshake against any dozen bank front doors will show the same asymmetry, and we would rather a reader run their own.

Public endpoints only: TLS handshake observation, nothing authenticated, nothing intrusive — the same class of check a public SSL test performs. Aggregate reporting only; no organisation is named.

Why this page exists

A measurement report is worth exactly what its worst-supported number is worth. We would rather withdraw one in public, four days after publishing it, than leave it standing and hope nobody checks.

If you find another number in our work you cannot reproduce, tell us and we will either show the artifacts or withdraw it here.

dongnx@atkvn.com  ·  read Vol.1