Is HBAR quantum resistant?

Hedera's SHA-384 hashing already holds up against quantum computers. Its signatures do not yet, but any account can swap its key without moving its HBAR.

Content reviewed on

A quantum computer hangs in a dark lab while a person holds a new key up to a vault, SentX pixel art

Short answer: the parts of Hedera built on hashing are already strong against quantum attacks, and the part that is not, account signatures, can be upgraded without moving a single HBAR. That second point is rarer than it sounds.

No public blockchain today is fully post-quantum, Hedera included. A claim that a coin is "quantum proof" should always name the layer it means. Here is Hedera, layer by layer.

What a quantum computer could break

Two quantum algorithms matter for cryptocurrencies. Shor's algorithm would let a large, fault tolerant quantum computer work out a private key from its public key. That breaks RSA, ECDSA and Ed25519, the signature schemes behind nearly every wallet in use today.

Grover's algorithm speeds up brute force search. Against a hash function it roughly halves the security level in bits. It weakens hashes; it does not break them, so a hash with a large output keeps a wide margin.

No quantum computer has yet run Shor's algorithm at the scale needed to break these keys. Standards bodies plan for one anyway: the US National Institute of Standards and Technology (NIST) has proposed retiring today's RSA and elliptic curve signatures by 2035. Read NIST's post-quantum transition plan.

Hedera's cryptography, layer by layer

LayerWhat Hedera usesQuantum outlook
Record stream and event hashingSHA-384Strong. Grover leaves about 192 bits of security.
Consensus topic running hashesSHA-384Strong, for the same reason.
Consensus orderingHashgraph gossip and virtual votingNo mining race to speed up. Safety rests on node signatures.
Node event signaturesRSA-3072Breakable by a future large quantum computer. Hybrid post-quantum signing is on Hedera's roadmap.
Node to node encryptionTLS with AES-256 and an elliptic curve key exchangeAES-256 holds. The key exchange is the first layer Hedera plans to upgrade.
Account signaturesEd25519 or ECDSA secp256k1Breakable by a future large quantum computer, as on Bitcoin and Ethereum.
Account identityAccount ID such as 0.0.12345Not derived from the key, so the key can be replaced in place.

A check marks a layer that holds today; a stopwatch marks one Hedera plans to upgrade. The table is the whole story in brief: hashing and symmetric encryption are ready, public key signatures and key exchange are the layers to upgrade, and Hedera's account model makes the account side of that upgrade simpler than it is on most chains. Hedera says the same of itself: its hashing and encryption are post-quantum secure, its signatures are not yet.

Why SHA-384 matters

Hedera hashes consensus events with SHA-384 and links its record files and consensus topic messages with SHA-384 running hashes. Changing any past transaction would change every hash after it, which is how a mirror node or an auditor can prove the history is intact.

SHA-384 produces a 384 bit output. Even with Grover's speedup, finding an input that matches a given hash would take on the order of 2^192 operations, far beyond any computer, classical or quantum. Bitcoin and Ethereum use 256 bit hashes, which also remain strong; SHA-384 simply keeps a larger margin.

Consensus without a mining race

Proof of work chains secure their history with a race to solve hash puzzles. Hashgraph works differently: nodes gossip transactions and a record of who heard what from whom, then compute the order by virtual voting on that shared history. No puzzles are solved and no energy race is involved.

The algorithm is asynchronous Byzantine fault tolerant, and that property has been checked with a machine verified proof. Its guarantees hold as long as more than two thirds of the stake is honest and node signatures cannot be forged. Every event a node gossips is signed and hash linked, which is why signatures, not the consensus logic, are the part a post-quantum upgrade has to address.

The Hedera advantage: change the key, keep the account

On Bitcoin and Ethereum, an address is derived from a public key. An ordinary Ethereum account cannot change its key at all, and its public key can be recovered from any transaction it has signed. Most Bitcoin addresses hide the key until the coins are spent, but reused addresses and Taproot outputs reveal it. Moving to a quantum safe key means moving every coin and token to a new address, one holding at a time, and anything left behind stays exposed.

On Hedera, an account is a ledger entry such as 0.0.12345 with a key attached. An account update transaction, signed by both the current key and the new one, replaces that key. The account ID, the HBAR balance, the NFTs, the token associations and the allowances all stay where they are.

Bitcoin and EthereumHedera
Account identifierDerived from the public keyAssigned by the network, separate from the key
Changing the keyMove funds to a new addressUpdate the key in place
Assets during a migrationMoved holding by holdingStay in the same account
Multi key controlScripts or smart contract walletsNative key lists and threshold keys

The path to post-quantum signatures

In August 2024 NIST published its first post-quantum standards: FIPS 203 (ML-KEM) for key exchange, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. A fourth, FN-DSA (the Falcon algorithm), is being standardized as FIPS 206. These are the algorithms networks and wallets are expected to adopt.

Size is the practical trade-off. An Ed25519 signature is 64 bytes. An ML-DSA signature is about 2,400 bytes and an FN-DSA signature about 670, so a network that moves thousands of transactions per second has good reason to prefer the smaller one.

In April 2026 Hedera published a staged plan along those lines. It starts with the connections that carry data today, then moves to the signatures:

  1. Post-quantum TLS between consensus nodes.
  2. Post-quantum TLS for connections from applications and wallets.
  3. Hybrid signing of consensus events, pairing a classical signature with FN-DSA.
  4. A new post-quantum key type for user accounts, with FN-DSA preferred and ML-DSA as the fallback. Hedera has pointed to 2027 for this stage.

Network changes are proposed and discussed in public as Hedera Improvement Proposals. At the time of review no post-quantum key type has been accepted there yet, so that is the place to watch.

What you can do today

  • Keep your recovery phrase and private keys offline and private. Quantum or not, a leaked key is the most common way accounts are emptied.
  • Protect large holdings with a threshold key, such as two of three keys, so one exposed key is not enough to move funds.
  • If you think a key was exposed, replace it with an account update. Your account ID and your NFTs stay the same.
  • When your wallet supports a post-quantum key type, rotate to it. On Hedera that is one update per account, not a migration.

Common questions

Is Hedera quantum proof?

No network is quantum proof today. Hedera's hashing is already quantum resistant, its signatures are not yet, and its account model lets every account switch keys without moving assets once a post-quantum key type is available.

Can a quantum computer steal HBAR today?

No. No quantum computer today can derive an Ed25519 or ECDSA private key from a public key. The risk is a future machine, which is why the upgrade path matters now.

What cryptography does Hedera use?

SHA-384 for hashing events, records and consensus topics; Ed25519 or ECDSA secp256k1 for account signatures; RSA-3072 for the signatures nodes put on consensus events; and TLS with AES-256 between nodes. Accounts can also use key lists and threshold keys that combine several keys.

Do I need to move my NFTs to stay safe?

No. On Hedera your NFTs stay in your account when you change its key. Keep your keys private and follow your wallet's updates.