Published a phased post-quantum migration roadmap in April 2026, targeting a new post-quantum key type for users in 2027 with existing keys continuing to work.
Is Hedera quantum-safe?
No, not today. Hedera accounts are secured by Ed25519 or ECDSA on secp256k1, and a sufficiently large quantum computer breaks both. Hedera has said so itself, in its own words: Ed25519 and ECDSA remain secure today but are vulnerable in the face of future quantum advances. In April 2026 Hedera published a phased migration roadmap moving to NIST-standardised algorithms, with a new post-quantum key type for users targeted for a 2027 release and testnet trials before that. The plan is explicitly backward compatible, so existing Ed25519 and ECDSA keys keep working through the transition rather than being invalidated. That combination, a named standard and a dated release window with no break for existing holders, is why Hedera scores well on migration despite having nothing post-quantum live on mainnet.
At a glance
On mainnet today
Ed25519 or ECDSA on secp256k1, selectable per account
Post-quantum scheme
A new post-quantum key type targeted for 2027, using Falcon or ML-DSA if the Falcon standard is delayed
NIST standard
FIPS 204 (ML-DSA); Falcon pending final publication
Readiness tier
Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.
Score breakdown
Each dimension scored 0 to 10. The weight beside it is its share of the
total score.
Hedera accounts and transactions are signed with Ed25519 or ECDSA on secp256k1 today. Both are broken by Shor's algorithm, and no post-quantum signature protects live HBAR.
source
2 Deployment stage 5/10, weighted 25%
Tier 3: Committed. A phased migration roadmap was published in April 2026 with a named scheme and a target release window, and testnet trials are scheduled ahead of it, but nothing post-quantum is live on mainnet.
source
3 NIST alignment 8/10, weighted 15%
The roadmap commits to NIST-standardised algorithms and names ML-DSA, finalised as FIPS 204, as the fallback if the Falcon standard slips. That is a committed selection of a published standard rather than a survey of candidates.
source
4 Migration path 8/10, weighted 15%
The transition is designed to be backward compatible: existing Ed25519 and ECDSA keys keep working while a new post-quantum key type is added alongside them. A migration that does not invalidate existing holders is the hard part, and Hedera has designed for it explicitly.
source
5 Exposure 2/10, weighted 10%
Hedera is an account-model network where an account's public key is recorded in state and readable from the mirror nodes, so keys are effectively public rather than revealed only on spend. Classical balances are harvestable today.
source
6 Verification 7/10, weighted 5%
Hedera published its own analysis of the vulnerability of its current keys and a dated migration roadmap under its own name, which is checkable against the dates as they pass. The network is governed by a named council rather than being anonymous.
source
The deployment dimension is not a separate judgement. It is Tier 3
expressed as a number. See the tier mapping.
How it compares
All 23 rated chains on the 0 to 100 scale.
Hedera is marked. Select any point to open that profile.
Hedera publishes a phased post-quantum migration roadmap moving from Ed25519 and ECDSA to NIST-standardised algorithms.
source
2026in-progress
Testnet trials of the post-quantum key type.
source
2027planned
A new post-quantum key type for users, with existing Ed25519 and ECDSA keys continuing to work alongside it.
source
Exposure
Exposure measures how much of the chain's value already sits behind a public key that an
attacker can record today and break later. This is the part of the threat that a future
upgrade cannot undo.
Hedera records account keys in network state, and mirror nodes expose that state publicly. That means an account's public key is generally readable without the account ever having spent, which removes the protection that hash-based addressing gives chains like Bitcoin and Cardano. Any balance held under a classical Ed25519 or ECDSA key is therefore harvestable today against a future quantum computer, which is the gap the 2027 key type is meant to close.
What this rating means for you
If you hold Hedera
Hedera has a funded roadmap but no post-quantum signature protecting funds on mainnet yet. Until it ships, your exposure is the ordinary one, and the steps that reduce it cost nothing.
Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it
is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating.
How we make money.
Questions
Is Hedera quantum-safe?
Not today. Hedera accounts use Ed25519 or ECDSA on secp256k1, both of which a sufficiently large quantum computer would break. Hedera published a migration roadmap in April 2026 targeting a post-quantum key type for users in 2027, but nothing post-quantum protects HBAR on mainnet at present.
Does Hedera already use Dilithium?
No. Claims that Hedera uses Dilithium today are premature. Hedera's published roadmap places a post-quantum key type in a 2027 release window and names ML-DSA, which is the standardised form of Dilithium, as the algorithm it would use if the Falcon standard is delayed. That is a plan, not a deployment.
Will existing Hedera accounts stop working?
No, according to the published roadmap. Hedera's transition is designed to be backward compatible, with existing Ed25519 and ECDSA keys continuing to work while the new post-quantum key type is introduced alongside them. That is a materially easier position than chains proposing to sunset legacy signatures.
Why does Hedera score badly on exposure?
Because account public keys are held in network state and are readable through public mirror nodes. On chains where an address is a hash of a key, an account that has never spent keeps its key private. Hedera does not get that protection, so classical balances are exposed to harvest-now-decrypt-later collection today.
This is a security-readiness assessment, not investment advice.
Cookies. We use Google Analytics to count how many people read a page. That is
the only thing this site measures: no advertising, no profiling, no third-party marketing tags.
Until you choose, nothing is stored on your device.
What we would set, in full.