Hardy Index Quantum readiness benchmark

Chain profile

NEAR Protocol

NEAR Shipping

NEAR stabilised ML-DSA-65 as a first-class account signature scheme on mainnet in the 2.13 release of July 2026, and any account holder can rotate to it in a single transaction without changing their address.

Is NEAR Protocol quantum-safe?

Not yet, but NEAR is closer than any chain in this index that was not built post-quantum from genesis. The 2.13 protocol release, which mainnet voted in on 20 July 2026, stabilised FIPS 204 ML-DSA-65 as a third transaction-signature and access-key scheme alongside Ed25519 and secp256k1. That is a NIST-standardised post-quantum signature working as a first-class account credential on a live mainnet, not a testnet pilot and not a scheme protecting only the network's own bookkeeping. Because NEAR accounts are human-readable identifiers controlled by rotatable access keys rather than being derived from a keypair, a holder can rotate to an ML-DSA-65 key in one on-chain transaction, keeping both their balance and their account name. What stops NEAR reaching the top of this index is that the rotation is opt-in and new: Ed25519 and secp256k1 remain fully valid, no sunset for them has been proposed or dated, and effectively every account on the network still has a quantum-vulnerable public key sitting in plain sight on-chain until its owner acts.

Where we are making a judgement call NEAR's placement rests on the rotation path being genuinely available to ordinary holders rather than only to builders running the CLI. We have confirmed the protocol support and the mechanism from the release notes and the protocol documentation, and we have not independently measured how many accounts have actually rotated. If wallet support turns out to be materially behind the protocol, the migration score is the one that should move.

At a glance

On mainnet today

Ed25519 and secp256k1, with ML-DSA-65 available as a third first-class access-key scheme

Post-quantum scheme

ML-DSA-65, stabilised on mainnet in release 2.13.0 and reachable by any account through key rotation

NIST standard

FIPS 204 (ML-DSA), final since August 2024

Readiness tier

Tier 2: Shipping. Post-quantum signature features are live on mainnet and a migration for existing holders is underway.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
NEAR Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 9 30% 27.0
2 Deployment stage 8 25% 20.0
3 NIST alignment 10 15% 15.0
4 Migration path 9 15% 13.5
5 Exposure 2 10% 2.0
6 Verification 8 5% 4.0
Hardy Score 81.5

1 Signature scheme 9/10, weighted 30%

Band 7 to 9: A post-quantum signature is available on mainnet at the protocol level as a first-class account type.

The 2.13.0 release notes state that it "stabilized the FIPS 204 ML-DSA-65 post-quantum signature scheme as a third transaction-signature and access-key scheme alongside ed25519 and secp256k1". Protocol version 86 carrying it was voted in on mainnet from 20 July 2026. This is a post-quantum signature usable as a full account credential by any holder. source

Placement in the band Not a 10, which this rubric reserves for a post-quantum signature that is mandatory for all accounts. ML-DSA-65 is stabilised and first-class but entirely optional: Ed25519 and secp256k1 remain valid signing schemes with no proposed sunset.

2 Deployment stage 8/10, weighted 25%

Band 8: Tier 2: Shipping.

Tier 2: Shipping. A post-quantum signature scheme is live on mainnet as a first-class account type, and the migration route for existing holders is open and usable today rather than planned. source

3 NIST alignment 10/10, weighted 15%

Band 9 to 10: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).

ML-DSA-65 is a parameter set of ML-DSA, standardised in FIPS 204, which NIST finalised in August 2024. The release notes name the standard and the parameter set explicitly rather than referring to a family or a candidate. source

Placement in the band A 10 rather than a 9 because the standard is final, the scheme is deployed under it, and the parameter set is named. A 9 in this band would fit a chain naming a FIPS-covered scheme it has not yet shipped, which is not the case here.

4 Migration path 9/10, weighted 15%

Band 9 to 10: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.

Holders can migrate today. NEAR accounts are human-readable identifiers controlled through rotatable access keys rather than addresses derived from a keypair, so rotating to ML-DSA-65 is a single on-chain transaction that changes neither the account name nor the balance. No holder has to move funds and no address changes hands. source

Placement in the band A 9 rather than a 10 because migrating is possible but not required, and nothing obliges anyone to do it. No sunset for Ed25519 or secp256k1 has been proposed or dated, so a holder who never acts stays quantum-vulnerable indefinitely and the chain has published no plan to change that.

5 Exposure 2/10, weighted 10%

Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

Every NEAR account publishes its access keys on-chain by construction, so the public key protecting a classically-keyed account is readable by anyone before that account ever spends. Rotation improves this materially: NEAR stores an ML-DSA-65 key as a 32-byte SHA3-256 hash rather than the 1952-byte key itself, so a rotated account exposes a hash and not a public key. source

Placement in the band A 2 rather than a 1 because the hash-based storage of ML-DSA-65 keys means exposure here is now remediable by the holder in a single transaction, which is not true of a chain whose address format publishes keys with no alternative. It cannot rise out of this band while effectively every account still carries a classical key in the clear.

6 Verification 8/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

nearcore is open source and the change is traceable to a public release with published notes, a stated protocol version and a named gas cost for the new verification path. The scheme itself is a NIST standard rather than a bespoke construction, so the cryptography carries external review that NEAR did not commission. source

Placement in the band An 8 rather than a 9 because no independent audit of NEAR's own ML-DSA-65 integration has been published. Using a standardised primitive is not the same as having the integration reviewed, and this band's ceiling belongs to chains that have both.

The deployment dimension is not a separate judgement. It is Tier 2 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. NEAR Protocol is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains NEAR sits among, out of 31 rated. The last column is the gap in Hardy points from NEAR.

Chains ranked immediately around NEAR Protocol, with tier, Hardy Score and the gap to NEAR Protocol
Rank Chain Tier Hardy vs NEAR
1 Quantum Resistant Ledger 1: Native 92.0 +10.5
2 Mochimo 1: Native 90.0 +8.5
3 Abelian 1: Native 84.5 +3.0
4 NEAR Protocol this chain 2: Shipping 81.5
5 Algorand 2: Shipping 77.5 -4.0
6 Nervos CKB 2: Shipping 75.5 -6.0
7 Bitcoin Cash 2: Shipping 66.0 -15.5
8 Solana 2: Shipping 54.5 -27.0
9 XRP Ledger 3: Committed 46.5 -35.0

Roadmap

  1. 5 May 2026 shipped

    NearOne publishes its plan to bring post-quantum safe signing to testnet by the end of Q2 2026, naming NIST-approved ML-DSA as the scheme. source

  2. 9 July 2026 shipped

    nearcore 2.13.0 is released, stabilising FIPS 204 ML-DSA-65 as a third transaction-signature and access-key scheme and moving the protocol from version 84 to 86. source

  3. 20 July 2026 shipped

    Voting for protocol version 86 opens on mainnet and the upgrade goes live, making ML-DSA-65 key rotation available to every account holder. source

  4. No date published proposed

    No sunset for Ed25519 or secp256k1 account keys has been proposed, and no target has been published for what share of accounts should hold an ML-DSA-65 key by when. source

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

NEAR's exposure is structural and, unusually, partly self-correcting. Every account's access keys are stored on-chain and readable by anyone, so a classically-keyed NEAR account reveals the public key protecting it from the moment it exists, with no need to spend first. That is the worst version of the exposure problem, and it applies to effectively the entire account set today. The rotation path is what makes NEAR's case different from the other chains scored at this level: ML-DSA-65 keys are stored as a 32-byte SHA3-256 hash rather than as the full 1952-byte key, and query responses return them with an ml-dsa-65-hash prefix. An account that rotates therefore stops publishing a usable public key at all. The exposure that remains is the exposure of accounts whose owners have not acted, which is a very large number weeks after the upgrade and is a problem of adoption rather than of design.

What this rating means for you

If you hold NEAR

NEAR has post-quantum signatures live on mainnet, but they are not the default, so holders have to opt in. That makes this one of the few chains where you can act today rather than wait.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show NEAR Protocol's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/near"><img src="https://hardyindex.com/badge/near.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/near.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is NEAR quantum-safe?

Not yet, but it is further along than any chain in this index that was not post-quantum from genesis. ML-DSA-65, a NIST-standardised post-quantum signature, has been a first-class account key scheme on NEAR mainnet since the 2.13 upgrade went live on 20 July 2026. It is opt-in, so an account is only quantum-safe once its holder has rotated to it, and Ed25519 and secp256k1 keys remain valid.

How do I make my NEAR account quantum-safe?

Rotate your account's access key to an ML-DSA-65 key. Because NEAR accounts are human-readable identifiers controlled by rotatable access keys rather than addresses derived from a keypair, this is a single on-chain transaction that leaves both your balance and your account name untouched. NEAR has documented the rotation through its CLI. This is a security-readiness assessment and not advice on how to manage your own keys.

What is ML-DSA-65 and is it a real standard?

ML-DSA is the Module-Lattice-Based Digital Signature Algorithm, standardised by NIST as FIPS 204 in August 2024, and ML-DSA-65 is one of its parameter sets. It is one of the first post-quantum signature standards NIST finalised. NEAR names both the standard and the parameter set in its release notes rather than referring to a family, which is what lets this profile score the NIST alignment dimension at the top.

Why is NEAR's exposure score still low if it has shipped a post-quantum signature?

Because exposure measures what is visible on-chain today, not what is available. Every NEAR account publishes its access keys, so an account still holding an Ed25519 or secp256k1 key has that key readable by anyone right now, whether or not it has ever spent. Rotation fixes this per account, and rotated accounts publish only a SHA3-256 hash of the ML-DSA-65 key rather than the key itself, but the great majority of accounts have not rotated.

Will NEAR force accounts to move to post-quantum keys?

Nothing published says so. Ed25519 and secp256k1 remain valid signing schemes, no sunset for them has been proposed or dated, and no target has been published for how much of the account set should be holding post-quantum keys by when. That absence is the main thing keeping NEAR's migration score below the top of its band.

Sources

  1. nearcore 2.13.0 release notes NEAR (nearcore) · primary · checked 16 August 2026
  2. NEAR Protocol Brings Quantum-Safe Signing to Mainnet NEAR Protocol, via PR Newswire · primary · checked 16 August 2026
  3. Access keys NEAR Protocol documentation · primary · checked 16 August 2026
  4. FIPS 204: Module-Lattice-Based Digital Signature Standard NIST · primary · checked 16 August 2026
  5. NEAR Plans Post Quantum Safe Signing for Q2 2026 Testnet The Crypto Times · secondary · checked 16 August 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). NEAR Protocol: quantum readiness assessment. Hardy Score 81.5 of 100, Tier 2: Shipping. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/near

BibTeX
@misc{hardyindex_near_2026,
  author       = {{The Hardy Index}},
  title        = {NEAR Protocol: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/near}},
  note         = {Hardy Score 81.5 of 100, Tier 2: Shipping. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/near.md.

This is a security-readiness assessment, not investment advice.