1 Signature scheme 9/10, weighted 30%
Band 7 to 9: A post-quantum signature is available on mainnet at the protocol level as a first-class account type.
The 2.13.0 release notes state that it "stabilized the FIPS 204 ML-DSA-65 post-quantum signature scheme as a third transaction-signature and access-key scheme alongside ed25519 and secp256k1". Protocol version 86 carrying it was voted in on mainnet from 20 July 2026. This is a post-quantum signature usable as a full account credential by any holder.
source
Placement in the band Not a 10, which this rubric reserves for a post-quantum signature that is mandatory for all accounts. ML-DSA-65 is stabilised and first-class but entirely optional: Ed25519 and secp256k1 remain valid signing schemes with no proposed sunset.
2 Deployment stage 8/10, weighted 25%
Band 8: Tier 2: Shipping.
Tier 2: Shipping. A post-quantum signature scheme is live on mainnet as a first-class account type, and the migration route for existing holders is open and usable today rather than planned.
source
3 NIST alignment 10/10, weighted 15%
Band 9 to 10: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).
ML-DSA-65 is a parameter set of ML-DSA, standardised in FIPS 204, which NIST finalised in August 2024. The release notes name the standard and the parameter set explicitly rather than referring to a family or a candidate.
source
Placement in the band A 10 rather than a 9 because the standard is final, the scheme is deployed under it, and the parameter set is named. A 9 in this band would fit a chain naming a FIPS-covered scheme it has not yet shipped, which is not the case here.
4 Migration path 9/10, weighted 15%
Band 9 to 10: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.
Holders can migrate today. NEAR accounts are human-readable identifiers controlled through rotatable access keys rather than addresses derived from a keypair, so rotating to ML-DSA-65 is a single on-chain transaction that changes neither the account name nor the balance. No holder has to move funds and no address changes hands.
source
Placement in the band A 9 rather than a 10 because migrating is possible but not required, and nothing obliges anyone to do it. No sunset for Ed25519 or secp256k1 has been proposed or dated, so a holder who never acts stays quantum-vulnerable indefinitely and the chain has published no plan to change that.
5 Exposure 2/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
Every NEAR account publishes its access keys on-chain by construction, so the public key protecting a classically-keyed account is readable by anyone before that account ever spends. Rotation improves this materially: NEAR stores an ML-DSA-65 key as a 32-byte SHA3-256 hash rather than the 1952-byte key itself, so a rotated account exposes a hash and not a public key.
source
Placement in the band A 2 rather than a 1 because the hash-based storage of ML-DSA-65 keys means exposure here is now remediable by the holder in a single transaction, which is not true of a chain whose address format publishes keys with no alternative. It cannot rise out of this band while effectively every account still carries a classical key in the clear.
6 Verification 8/10, weighted 5%
Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.
nearcore is open source and the change is traceable to a public release with published notes, a stated protocol version and a named gas cost for the new verification path. The scheme itself is a NIST standard rather than a bespoke construction, so the cryptography carries external review that NEAR did not commission.
source
Placement in the band An 8 rather than a 9 because no independent audit of NEAR's own ML-DSA-65 integration has been published. Using a standardised primitive is not the same as having the integration reviewed, and this band's ceiling belongs to chains that have both.