Is HBAR quantum resistant?
Hedera's SHA-384 hashing already holds up against quantum computers. Its signatures do not yet, but any account can swap its key without moving its HBAR.
Content reviewed on

What a quantum computer could break
Hedera's cryptography, layer by layer
| Layer | What Hedera uses | Quantum outlook |
|---|---|---|
0.0.12345 |
Why SHA-384 matters
Consensus without a mining race
The Hedera advantage: change the key, keep the account
0.0.12345 with a key attached. An account update transaction, signed by both the current key and the new one, replaces that key. The account ID, the HBAR balance, the NFTs, the token associations and the allowances all stay where they are.
| Bitcoin and Ethereum | Hedera | |
|---|---|---|
The path to post-quantum signatures
Post-quantum TLS between consensus nodes. Post-quantum TLS for connections from applications and wallets. Hybrid signing of consensus events, pairing a classical signature with FN-DSA. A new post-quantum key type for user accounts, with FN-DSA preferred and ML-DSA as the fallback. Hedera has pointed to 2027 for this stage.
What you can do today
Keep your recovery phrase and private keys offline and private. Quantum or not, a leaked key is the most common way accounts are emptied. Protect large holdings with a threshold key, such as two of three keys, so one exposed key is not enough to move funds. If you think a key was exposed, replace it with an account update. Your account ID and your NFTs stay the same. When your wallet supports a post-quantum key type, rotate to it. On Hedera that is one update per account, not a migration.


