The Web3 Ranking: Measured, Not Sold
Most Web3 rankings are built from numbers the projects report about themselves. This one is built from measurements of their own domains against public sources: registry records, DNS, web archives, DeFi data and the chain itself.
It measures 143 projects across five families, 142 of them published — Web2 domains of Web3 projects, Powerful contracts, Memes, NFTs and Web3 names (ENS) — and every row carries its coverage, its exclusions and its limits. Where a signal could not be measured, the row says so instead of guessing.

What we measured
Nine modules run against each domain: identity and ownership, DNS trust records, AI crawler exposure, ecosystem interactions, on-chain contract verification, own-registry attestation, web archive history, agent readiness and agent discovery. Each one either measures something from a verifiable source or declares that it could not.
The score is renormalised over the weight that was actually measured. That detail matters: a module that cannot run must not look like a defect of the project. Coverage is shown next to every row — AAA means the deep layers were measured too, A means the entry layer only. In this snapshot, 128 of 142 published rows reached AAA.
WSEP, and why it is not the free score
The number in this table is WSEP: the engine’s aggregate over five weighted dimensions — identity 30, performance 15, security 20, ecosystem authority 20, tech stack 15 — renormalised over the weight actually measured. It carries no brand term and no post-quantum term: this column says how findable and how verifiable a project is, and nothing else.
The free score publishes a different formula on the same target: 60% web3 SEO presence and 40% post-quantum risk, with the weights the engine declares. It also reads brand recognition and the on-chain asset profile, which this table deliberately leaves out — that is why a well-known project can sit higher there than here.
Same domain, same day, measured 27 September 2026: aave.com — WSEP 76 in the engine, 79/100 on the free score. larvalabs.com — WSEP 56, 60/100. Two formulas, both ours, both published.
And it is not the same date: the rows here carry the pass each of them was measured in — 23 Sept – 28 Sept 2026 — and every row prints its own three dates, while the free score is measured the moment you ask for it. The date at the top of this page is the most recent source consulted, not the day the whole table was measured: reading the two without their dates is what makes them look like a contradiction.
The post-quantum verdict is also the order of the rows: own cryptography first, then borrowed from the CDN, then no signal, and last the rows whose verdict could not be measured. Inside each group the higher search exposure goes first. The column is the measurement; the order is the priority.
That is why the numbers can read out of order: Milady Maker shows 48 and sits below Moonbirds, which shows 21 — the two rows are not in the same post-quantum group, and the group decides before the number does. Read the number as the measurement and the position as the priority; neither one is a mistake.
Why post-quantum readiness is the priority
NIST’s transition draft (IR 8547, initial public draft of November 2024 — not final) deprecates RSA and ECDSA at the 112-bit security level after 2030 and disallows them after 2035; traffic recorded today can be read then. So the ranking does not ask whether a project looks modern — it asks whose cryptography it actually carries. The five verdicts are never merged:
- PQ proved with its own keythe domain signed a fresh challenge with the private key behind the public key it publishes — only the key’s owner can do that, and a CDN standing in front of the site cannot: it holds no private key. It is the only verdict that cannot be rented
- PQ in its own codepost-quantum code found in the JavaScript the project itself serves. It is a floor, not a ceiling: the probe reads the browser side, so cryptography running where it cannot look — a backend — would be a false negative, and this verdict says nothing about the key exchange, which is the layer a harvest-now-decrypt-later attack waits on. Shor breaks both layers; a broken signature is noticed, a broken key exchange is not
- PQ on its own edgethe hybrid key exchange is served by their own network, not by a CDN
- PQ borrowed from its CDNthe hybrid key exchange comes from the CDN in front of them — Cloudflare, Fastly, Akamai, CloudFront, Bunny. It is real protection, but it is not their work
- no PQ measuredno PQ signal measured anywhere: classical key exchange
One further case is declared instead of scored: not measurable. It is not a small remainder — 1 of the 142 published rows are in it — and it is stated on the row, not hidden in a footnote.
That is what the table is for. Not a leaderboard for its own sake: a reading of how far the market has got before 2030, with measurements instead of press releases — and with the rows where nothing could be measured still visible, because a gap you can see is information and a gap you cannot is a sales pitch.
The five families
- Web2 domains of Web3 projects — 10 rows. The top of the measured sample by TVL on DefiLlama. Each row carries its TVL as DefiLlama declares it, next to how findable the site is. Every row is a DNS name: a decentralised name has no registry record or DNS entry for these modules to read, which is exactly why the .eth names are measured in the last family of the ranking — on-chain and through their gateway — instead of being scored as zeros in this one.the ten highest-scoring rows of the measured sample (top projects by DefiLlama TVL). The rest of the sample is not published in this family, and any row that was measured and kept out is declared with its score instead of disappearing.See this family in the ranking →
- Powerful contracts — 4 rows. Oracles and money-heavy contracts whose address DefiLlama publishes. The chain answers two questions: is the source readable, and does the contract verify signatures with ECDSA — the layer a quantum computer breaks in public. The other half of the problem is the key exchange, which is broken in secret, and that is what the post-quantum column above reports.oracles and contracts holding money, with the address DefiLlama declaresSee this family in the ranking →
- Memes — 7 rows. The most valuable memes that declare a site of their own. Market cap comes from CoinGecko by coin id, never by ticker: two projects can share a symbol, and a ranking that mixes them is wrong.the largest by market capitalisation with a project site of their own (CoinGecko, by id)See this family in the ranking →
- NFTs — 7 rows. Well-known collections, chosen by hand and declared as such. A floor price needs a paid source, so this family publishes no power column at all: the missing source is declared in one line instead of printed as seven empty cells.an editorial selection of well-known collections (no free source for volume)See this family in the ranking →
- Web3 names (ENS) — 114 rows. The .eth names that still answer with a page through their gateway, out of a pool published in full: every name with a certificate issued for its gateway plus the registry read on-chain. A row here is a name that answers — the ones that stopped answering are counted, not printed as empty rows. What the gateway serves is the gateway’s, and every row says so.every .eth name that serves a page through its gateway today, out of a pool declared in full (Certificate Transparency plus the registry read on-chain) — a census, not a selectionSee this family in the ranking →
Four things the measurements showed
- Not one project proves its post-quantum key — and that is measurable today, which it was not before. The engine challenges the domain itself: it asks it to sign a fresh 32-byte nonce with the post-quantum key that domain publishes, and verifies the signature (ML-DSA-65, FIPS 204). 0 of the 142 published rows could do it. Every post-quantum signal in the table is borrowed from a CDN, and most of those rows borrow it from the same one. Ours is not rented: stygiascore.com carries the verdict PQ proved with its own key, and the check is one command anybody can run without our keys — curl -s https://api.stygiascore.com/v1/pqc/proof/stygiascore.com A CDN standing in front of a site cannot answer that: it does not hold the private key.
- No project in this snapshot carries post-quantum cryptography in its own code. The probe reads the scripts each site serves and looks for the algorithms by name — ML-DSA, SLH-DSA, ML-KEM — and found none: 0 of the 142 published rows. An earlier pass did credit a meme with ML-KEM, and that is written here on purpose: the hit was a token list carrying “Kyber Network”, the exchange, not the algorithm. The detector now asks for the name in context and the row went back to what it is. Of the 142 rows, 139 borrow the hybrid key exchange from the CDN in front of them — 15 Cloudflare, 122 Amazon CloudFront, 1 Imperva, 1 Fastly — 2 show no post-quantum signal at all, and there is no room in the table for a project to be credited with work its CDN did. Read that count for what it is: 114 of those 139 are not 114 projects — they are one gateway (eth.limo) measured once and inherited by every row of the name census behind it. Outside those rows the table has 25 borrowed, 2 with no post-quantum signal at all and 1 not measurable: that is the size of the sample the headline is really made of. And the probe reads the JavaScript each site serves, not its backend: a project doing post-quantum cryptography on a server the browser never sees would come out as a zero here, which is why that verdict is published as a floor and not as a verdict on the whole project.
- Borrowed is not prepared. 2 rows show no post-quantum signal anywhere — OKX, Milady Maker — and their edge did not negotiate the hybrid handshake, so they rank below projects that did nothing and simply sit behind a CDN that does. Nobody should read that as “Cloudflare is bad” or as “that collection is careless”: it is the difference between owning your cryptography and renting it, and the column exists precisely to keep those two apart.
- What could not be read is declared, not averaged away. In the contracts family there is no balance to show: the address DefiLlama publishes for those protocols is their token contract, and its native balance is zero — the contracts that hold the money are not the ones with a published address.
The limits, declared
The sample is a selection, not Web3 as a whole — each family says how its rows were chosen, and a different rule gives a different table. A project behind a CDN inherits hybrid key exchange without doing anything, so the post-quantum column must be read as “whose cryptography is this”, never as “how ready is this project”. Exposure is not traffic: no search-volume or ranking-position data is used, and two of the five modules declared as not implemented — backlinks and keywords — are the search ones, so this is a hygiene and identity score for a domain rather than an SEO-performance score. The post-quantum verdict is a floor and not a verdict on the backend: the probe reads the JavaScript a site serves, so cryptography running on a server the browser never sees would come out as a zero. The weights are still being calibrated and this is a dated snapshot, not a verdict: the next step is to anchor the hash of each measurement on-chain, so a published table cannot be rewritten afterwards — by anyone, including us.
The order is not for sale
No project can buy a position, a score or a module result. What can be bought is the diagnosis: which module costs you points, what is fixable, and what it would move. Every row carries the date it was last read, and the next step announced above is to anchor each measurement on-chain — so that a published table cannot be rewritten afterwards, by anyone including us. The measurement stays independent, because that is the only reason a ranking is worth anything.