---
title: Is Hedera quantum-safe?
chain: Hedera
ticker: HBAR
hardy_score: 42
rank: 8 of 23
tier: "3: Committed"
url: "https://hardyindex.com/chains/hedera"
updated: 2026-08-12
methodology_version: 1.1
---

# Is Hedera quantum-safe?

**Hardy Score 42.0 / 100. Rank 8 of 23. Tier 3: Committed. As of 12 August 2026.**

No, not today. Hedera accounts are secured by Ed25519 or ECDSA on secp256k1, and a sufficiently large quantum computer breaks both. Hedera has said so itself, in its own words: Ed25519 and ECDSA remain secure today but are vulnerable in the face of future quantum advances. In April 2026 Hedera published a phased migration roadmap moving to NIST-standardised algorithms, with a new post-quantum key type for users targeted for a 2027 release and testnet trials before that. The plan is explicitly backward compatible, so existing Ed25519 and ECDSA keys keep working through the transition rather than being invalidated. That combination, a named standard and a dated release window with no break for existing holders, is why Hedera scores well on migration despite having nothing post-quantum live on mainnet.

> This is a security-readiness assessment, not investment advice.

## Summary

Published a phased post-quantum migration roadmap in April 2026, targeting a new post-quantum key type for users in 2027 with existing keys continuing to work.


## Score breakdown

| # | Dimension | Score | Weight | Contribution |
|---:|---|---:|---:|---:|
| 1 | Signature scheme | 0/10 | 30% | 0.0 |
| 2 | Deployment stage | 5/10 | 25% | 12.5 |
| 3 | NIST alignment | 8/10 | 15% | 12.0 |
| 4 | Migration path | 8/10 | 15% | 12.0 |
| 5 | Exposure | 2/10 | 10% | 2.0 |
| 6 | Verification | 7/10 | 5% | 3.5 |
| | **Hardy Score** | | | **42.0** |

### 1. Signature scheme: 0/10

Hedera accounts and transactions are signed with Ed25519 or ECDSA on secp256k1 today. Both are broken by Shor's algorithm, and no post-quantum signature protects live HBAR.

Source: https://hedera.com/blog/are-ed25519-keys-quantum-resistant-exploring-the-future-of-cryptography/

### 2. Deployment stage: 5/10

Tier 3: Committed. A phased migration roadmap was published in April 2026 with a named scheme and a target release window, and testnet trials are scheduled ahead of it, but nothing post-quantum is live on mainnet.

Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/

### 3. NIST alignment: 8/10

The roadmap commits to NIST-standardised algorithms and names ML-DSA, finalised as FIPS 204, as the fallback if the Falcon standard slips. That is a committed selection of a published standard rather than a survey of candidates.

Source: https://csrc.nist.gov/pubs/fips/204/final

### 4. Migration path: 8/10

The transition is designed to be backward compatible: existing Ed25519 and ECDSA keys keep working while a new post-quantum key type is added alongside them. A migration that does not invalidate existing holders is the hard part, and Hedera has designed for it explicitly.

Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/

### 5. Exposure: 2/10

Hedera is an account-model network where an account's public key is recorded in state and readable from the mirror nodes, so keys are effectively public rather than revealed only on spend. Classical balances are harvestable today.

Source: https://hedera.com/blog/are-ed25519-keys-quantum-resistant-exploring-the-future-of-cryptography/

### 6. Verification: 7/10

Hedera published its own analysis of the vulnerability of its current keys and a dated migration roadmap under its own name, which is checkable against the dates as they pass. The network is governed by a named council rather than being anonymous.

Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/

## Signature scheme

- **On mainnet today:** Ed25519 or ECDSA on secp256k1, selectable per account
- **Post-quantum scheme:** A new post-quantum key type targeted for 2027, using Falcon or ML-DSA if the Falcon standard is delayed
- **NIST standard:** FIPS 204 (ML-DSA); Falcon pending final publication
- **Readiness tier:** Tier 3: Committed. A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.

## Roadmap

- **April 2026** (shipped): Hedera publishes a phased post-quantum migration roadmap moving from Ed25519 and ECDSA to NIST-standardised algorithms.
  Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/
- **2026** (in-progress): Testnet trials of the post-quantum key type.
  Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/
- **2027** (planned): A new post-quantum key type for users, with existing Ed25519 and ECDSA keys continuing to work alongside it.
  Source: https://hedera.com/blog/post-quantum-cryptography-and-blockchain/

## Exposure

Hedera records account keys in network state, and mirror nodes expose that state publicly. That means an account's public key is generally readable without the account ever having spent, which removes the protection that hash-based addressing gives chains like Bitcoin and Cardano. Any balance held under a classical Ed25519 or ECDSA key is therefore harvestable today against a future quantum computer, which is the gap the 2027 key type is meant to close.

## Frequently asked questions

### Is Hedera quantum-safe?

No, not today. Hedera accounts are secured by Ed25519 or ECDSA on secp256k1, and a sufficiently large quantum computer breaks both. Hedera has said so itself, in its own words: Ed25519 and ECDSA remain secure today but are vulnerable in the face of future quantum advances. In April 2026 Hedera published a phased migration roadmap moving to NIST-standardised algorithms, with a new post-quantum key type for users targeted for a 2027 release and testnet trials before that. The plan is explicitly backward compatible, so existing Ed25519 and ECDSA keys keep working through the transition rather than being invalidated. That combination, a named standard and a dated release window with no break for existing holders, is why Hedera scores well on migration despite having nothing post-quantum live on mainnet.

### Is Hedera quantum-safe?

Not today. Hedera accounts use Ed25519 or ECDSA on secp256k1, both of which a sufficiently large quantum computer would break. Hedera published a migration roadmap in April 2026 targeting a post-quantum key type for users in 2027, but nothing post-quantum protects HBAR on mainnet at present.

### Does Hedera already use Dilithium?

No. Claims that Hedera uses Dilithium today are premature. Hedera's published roadmap places a post-quantum key type in a 2027 release window and names ML-DSA, which is the standardised form of Dilithium, as the algorithm it would use if the Falcon standard is delayed. That is a plan, not a deployment.

### Will existing Hedera accounts stop working?

No, according to the published roadmap. Hedera's transition is designed to be backward compatible, with existing Ed25519 and ECDSA keys continuing to work while the new post-quantum key type is introduced alongside them. That is a materially easier position than chains proposing to sunset legacy signatures.

### Why does Hedera score badly on exposure?

Because account public keys are held in network state and are readable through public mirror nodes. On chains where an address is a hash of a key, an account that has never spent keeps its key private. Hedera does not get that protection, so classical balances are exposed to harvest-now-decrypt-later collection today.

## What this rating means if you hold Hedera

Plain-language guidance from the same publication, with no product recommendation attached.

- [Is my crypto safe from quantum computers?](https://hardyindex.com/guides/is-my-crypto-safe-from-quantum-computers.md)
- [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers.md)
- [All guides](https://hardyindex.com/guides.md)

Nothing on this profile is sponsored and nothing on it is an affiliate link. See https://hardyindex.com/how-we-make-money.md.

## Sources

1. [Post-Quantum Cryptography and Blockchain](https://hedera.com/blog/post-quantum-cryptography-and-blockchain/): Hedera (primary, checked 12 August 2026)
2. [Are Ed25519 Keys Quantum-Resistant? Exploring the Future of Cryptography](https://hedera.com/blog/are-ed25519-keys-quantum-resistant-exploring-the-future-of-cryptography/): Hedera (primary, checked 12 August 2026)
3. [FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA)](https://csrc.nist.gov/pubs/fips/204/final): NIST (primary, checked 12 August 2026)

---

Methodology: https://hardyindex.com/methodology (v1.1).
Cite as: The Hardy Index, "Hedera", https://hardyindex.com/chains/hedera, as of 12 August 2026.
