Governance

Corrections

Linkmerica publishes versioned scores that institutions may cite months after publication. That only works if the record is honest about its own errors. This page states the correction policy and logs every correction issued.

Correction policy

Locked outputs are never silently edited. Every published score is locked at publication and carries a SHA-256 integrity hash recorded in a public log. A corrected score is issued as a new, separately dated version. The original file remains unaltered, and its original hash continues to verify against its original content — including its error. Corrections are additive records, not retroactive edits.

A correction and a rescore are different things. A rescore reflects new evidence about the subject: the product changed, a vulnerability was disclosed, a manufacturer shipped something new. A correction reflects an error in Linkmerica's own work: a research gap, a factual mistake, a misstatement. Both are dated and published. They are not the same event and are not described as though they were.

A correction is issued when a factual error is identified in a published output, or when the evidence base underlying a score is found to have been incomplete or inaccurate at the time of scoring.

Every correction states plainly whether any score was affected. Where the answer is no, that is stated directly rather than implied.

Correction log

2026-08-04 · SYSTEMATIC

Quantum Resistance Readiness — systematic defect, all seven scores re-audited

What was wrong: Quantum readiness scoring searched for news about a manufacturer’s post-quantum posture rather than reading what the manufacturer had published. Where a search returned nothing, the score asserted no position existed. That assertion was wrong in four of seven cases. In every one the manufacturer had published relevant material before the scoring date, on its own site or documentation.

Every error ran the same direction — risk overstated. This was a single mechanism producing consistent directional bias, not scatter. Every manufacturer that had published something was mis-scored; the three scores found accurate are the three manufacturers that had genuinely published nothing.

WalletBeforeAfterOutcome
Trezor7.8 HIGH4.4 MODERATECorrected
Foundation Passport Prime7.3 HIGH6.3 HIGHCorrected
Ledger6.8 HIGH5.4 MODERATECorrected
Tangem9.1 CRITICAL8.0 HIGHCorrected
SafePal8.3 CRITICAL8.3 CRITICALVerified accurate
ELLIPAL8.7 CRITICAL8.7 CRITICALVerified accurate
BitBox027.6 HIGH7.6 HIGHVerified accurate

What changed in the methodology: quantum readiness scoring now begins with manufacturer technical documentation. Search is secondary. A rationale may assert a manufacturer has published nothing only after those sources are checked directly. See the standard.

What did not change: the framework itself. No score moved because the tiers or categories were wrong. The substantive findings largely survived — in each corrected case the manufacturer’s material established that a position existed, not that post-quantum protection reaches the custody layer. Five of seven wallets remain HIGH risk or above. All original files remain locked and unaltered with their original integrity hashes; both versions of every corrected score stay in the public record.

2026-08-02

Ledger Quantum Resistance Readiness — incorrect claim about published implementation

Affected output: Ledger Quantum Resistance Readiness score, published 2026-06-28.

What was wrong: Two category rationales stated that Ledger had announced no production post-quantum implementation and published no explicit FIPS alignment statement. Ledger’s Embedded OS team had published a technical implementation guide for ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in June 2026, before the scoring date, documenting constant-time decapsulation and side-channel considerations.

What was not wrong: The implementation sits in the SDK, available to applications, rather than protecting the boot chain, firmware verification, or transaction signing. That distinction caps the credit and is why the score does not move further.

Root cause: Linkmerica assessed Ledger’s quantum posture on 2026-07-24 based on an engineer’s post on social media rather than the manufacturer’s published technical documentation. This is the third correction in three weeks arising from the same failure — searching for news about a manufacturer’s quantum posture instead of reading what the manufacturer has published.

Was any score affected? Yes. Quantum Resistance Readiness moved from 6.8 to 5.4, and the tier from HIGH to MODERATE. Both versions remain in the public record. View the current score.

This correction was later found to be one instance of a systematic defect. See the 2026-08-04 entry above for the full re-audit of all seven quantum readiness scores and the methodology change.

This correction was later found to be one instance of a systematic defect. See the 2026-08-04 entry above for the full re-audit of all seven quantum readiness scores and the methodology change.

This correction was later found to be one instance of a systematic defect. See the 2026-08-04 entry above for the full re-audit of all seven quantum readiness scores and the methodology change.

2026-07-29

Foundation Passport Prime Quantum Resistance Readiness — incorrect claim about algorithm disclosure

Affected output: Foundation Passport Prime Quantum Resistance Readiness score, published 2026-07-12.

What was wrong: Two category rationales asserted that Foundation had not publicly named a NIST-standardized post-quantum algorithm. Foundation had named ML-KEM, the NIST FIPS 203 standard, in its general-availability announcement seven weeks before the scoring date, and in its blog and product documentation.

What was not wrong: The score's central judgment stands unchanged — the feature in question protects the wireless transport channel, not the wallet's transaction-signing cryptography or its boot and firmware verification. Transport-layer post-quantum protection is not custody-layer post-quantum protection. The original score identified the feature and referenced it repeatedly; the error was a specific incorrect claim about public disclosure, not a failure to find it.

What changed: A dated correction note was published and a new score version issued on 2026-07-29. The 2026-07-12 file remains locked and unaltered with its original integrity hash.

Was any score affected? Yes. The Quantum Resistance Readiness score moved from 7.3 to 6.3. The risk tier did not change — it remains HIGH. Both versions remain in the public record. View the current score.

2026-07-27

Synthesis brief withdrawn and rebuilt before announcement

Affected output: Research brief, "Five Ways an Agentic Protocol Fails Custody."

What was wrong: The first published version contained factual errors introduced during drafting. All three rated protocols were given incorrect formal names. Both Linkmerica framework acronyms were expanded incorrectly. A statement describing a rated party's response to published research was included without any source. A specification publication date was stated without a source. Two of Linkmerica's own prior rescore dates were stated incorrectly, contradicting the locked score files. One transaction-volume figure was overstated, and two cumulative figures were described as monthly rates.

What changed: The brief was withdrawn and rebuilt the same day from the locked score files, with every factual claim constrained to verified sources. It was republished before any announcement was posted. An editorial verification gate was built the same day and now runs against every brief before publication, checking score claims and dates against locked files and flagging any statement attributed to a named third party.

Was any score affected? No. All five agentic protocol scores referenced in the brief were correct, locked, and hashed throughout. The error was confined to the brief's prose.

2026-07-24

Trezor Quantum Resistance Readiness — research gap in original score

Affected output: Trezor Quantum Resistance Readiness score, published 2026-06-28.

What was wrong: The score's rationale stated that no public quantum-readiness statement from the manufacturer had been identified. This was incorrect at the time of scoring. Trezor had published quantum-readiness technical content in March 2026, over three months before the scoring date, and it was publicly accessible throughout.

What changed: A dated correction note was published, and a new score version was issued on 2026-07-24 incorporating the manufacturer's disclosures. That version also documents a device-generation change in what the Trezor entry assesses. The original 2026-06-28 file remains locked and unaltered with its original integrity hash.

Was any score affected? Yes. The Quantum Resistance Readiness score moved from 7.8 (HIGH) to 4.4 (MODERATE). Both versions remain in the public record. View the current score.

Corrections are listed most recent first. For score changes driven by new evidence rather than Linkmerica error, see the changelog.

← Back to homepage