Watchlist 0
HEDERA · L1 · STAGE 2 ACKNOWLEDGED-PLANNING · QRI 38 v3.1.0 methodology
In plain terms

What it is. Hedera is a network run by a council of about 31 large companies, and your account here is a plain number rather than something built from your public key.

What we found. That account-number design hides your public key until the moment you first sign, so a future quantum attacker has less to work with, but no quantum-safe protection is actually running yet and the first protected accounts are only targeted for 2027.

Why it matters. Accounts that have never been used stay better shielded, yet anyone holding or building today is still relying on a plan rather than live defenses, and the council that can push the fix through has not committed to one.

The April 2026 foundation PQ blog publishes a sequenced migration plan with named primitives (FN-DSA primary, ML-DSA fallback, ML-KEM for KEM) and a documented hybrid AND-composition for event signing, architecture is documented in unusual depth for a chain at zero deployment. All planned PQ primitives are lattice; the Diversity Cap is conditional and fires once any PQ ships without a hash-based or code-based fallback.

inLinkedIn Audit access Compare Verified 2026-05-01

Summary

Hedera scores QRI 38, Band 4 Architected by raw arithmetic / Migration Stage 2 after caps. Mainnet runs Ed25519 and ECDSA secp256k1 (account/transaction signatures), SHA-384 (hashgraph history hashing, CNSA-aligned and distinct from SHA-256/Keccak chains), and AES-256 within TLS for encrypted transport. Account IDs are protocol-assigned numeric tuples (e.g., 0.0.123) NOT derived from the public key, the public key is exposed only when a transaction is signed. This is structurally favourable vs Bitcoin/Ethereum: address ≠ pubkey hash. The April 2026 foundation post explicitly names FN-DSA (FIPS 206) as primary and ML-DSA as fallback if FIPS 206 is delayed, both lattice. Foundation states intent to deploy hybrid Ed25519 + FN-DSA event signing and PQ-TLS for nodes/clients. New PQ key type targeted for 2027. Hashgraph consensus uses virtual voting; the roadmap lists TSS signatures (in progress), implementation candidate not yet named. mainnet-traffic cap binds at 5a=0%, Architecture-Execution Gap is 46. Council coordination structure (31-member Governing Council including FedEx and Accenture) plausibly compresses Y in X+Y vs Z. SEALSQ QS7001 chip integration is the most-developed hardware-PQ partnership of any chain in this batch.

What the gates say

  • Gate 1a, Hybrid signature: FAIL , Foundation declares hybrid AND-composition (classical Ed25519 + FN-DSA) for event signing in the April 2026 plan, but it is not deployed, not specced beyond a paragraph, and no testnet is live
  • Gate 1a, Hybrid KEM: FAIL , PQ-TLS for nodes and clients is sequenced as steps 1-2 in the migration plan, but no KEM combiner is named, no spec is published
  • Gate 1b, Commit-to-hash: COND , declared composition is AND, not OR
  • Gate 2, Evidence reconstruction: PASS , every sub-score has ≥1 public artifact; Dims 1, 4, 5, 6, 7 carry ≥4 artifacts
  • Gate 3, Primitive naming: PASS , every primitive named with mechanism, Ed25519, ECDSA secp256k1, SHA-384, AES-256, FN-DSA/Falcon, ML-DSA/Dilithium, ML-KEM/Kyber

Burn-vs-rescue policy on file

Declared option f, Undeclared. Council governance structure makes coordinated rescue feasible (option b/c analogues), but no formal policy is published. Migration plan addresses prospective protection (new PQ key type, hybrid event signing) but does not address legacy-key dormant-fund disposition.

Seven dimensions

Each dimension scores 0–100 internally; the weighted roll-up produces the QRI.

1 Cryptographic Exposure weight 15% 62 / 100
1a · primitive inventory 17 / 20

Foundation blog (April 2026) names current primitives explicitly. Three points withheld: stateful/stateless distinction not declared at protocol level; the random-beacon / TSS path (in active development per roadmap) does not yet name its candidate signature scheme.

Primitives: Ed25519 (account/transaction signing) · ECDSA secp256k1 (account/transaction signing) · SHA-384 (hashgraph history linking, CNSA-aligned) · AES-256 within TLS (encrypted transport) · Threshold/multi-key supported per account-properties
1b · shor grover pq tag 18 / 20

Foundation explicitly acknowledges that an attacker with a CRQC could derive a private key from a public key. SHA-384 and AES-256 are CNSA-tier choices that retain ≥128-bit security under Grover.

Tags:
  • Ed25519 Shor-break-via-DL-without-pairings
  • ECDSA secp256k1 Shor-break-via-DL-without-pairings
  • SHA-384 Grover-weaken (192-bit residual security, distinct from SHA-256/Keccak 128-bit residual)
  • AES-256 Grover-weaken (128-bit residual)
1c · family diversity 5 / 20

Families currently: 0; planned families: lattice (Falcon/FN-DSA primary, ML-DSA fallback, ML-KEM for KEM). All planned PQ migration is lattice-only. Diversity Cap (v3.1 → 60) will apply once any PQ family ships. Foundation post explicitly names FN-DSA (FIPS 206) as primary and Dilithium (ML-DSA) as fallback if FIPS 206 is delayed, both lattice. No hash-based or code-based fallback declared.

1d · nist security category 12 / 20

SHA-384 (FIPS 180-4, CNSA-aligned, 192-bit residual under Grover); AES-256 (CNSA-aligned, 128-bit residual under Grover); planned FN-DSA = NIST cat 1 or higher (parameter set unstated); planned ML-DSA = cat per parameter (unstated); planned ML-KEM = cat per parameter (unstated). Foundation states intent to follow CNSA but does not name PQC parameter sets.

1e · implementation quality 10 / 20

Hashgraph consensus aBFT proven in Coq (consensus correctness, not crypto-primitive proofs). Standard Ed25519/ECDSA implementations expected. Hedera SDKs (Java/JS/Go/Rust). Planned Falcon/Dilithium are stateless. Tier 1 (ECDSA/Ed25519/SHA-2 classical) shipped, tier 3 (NIST PQC standardized) targeted, not yet shipped.

2 Quantum Recovery Exposure weight 10% 48 / 100
Forge subtotal: 36/75 Decrypt subtotal: 12/25
2a · active key exposure 16 / 25

Hedera account IDs are protocol-assigned numeric tuples shard.realm.account (e.g., 0.0.123), they are NOT derived from the public key. The public key is exposed only when a transaction is signed (or when an alias is used). This is structurally favourable vs Bitcoin/Ethereum: address ≠ pubkey hash. Live cumulative TVL/circulating-HBAR sits behind keys revealed at first signature; once revealed, future Shor-derived forgery is possible against any active account.

2b · cold key exposure 14 / 25

Treasury/Council allocations and dormant retail accounts that have never transacted retain pubkey-not-revealed status (assuming no aliases), reducing cold exposure relative to chains where the address IS the pubkey hash. Concentration in Council-allocated tranches is documented in HBAR tokenomics.

2c · sig long term validity 6 / 25

Every historical Ed25519 / ECDSA secp256k1 signature on the network ledger remains forgeable post-Shor with respect to the public key it was made under. Hashgraph history is hashed with SHA-384 (Grover-resistant chaining) but signature non-forgeability collapses with Shor.

2d · encryption confidentiality hndl 12 / 25

Foundation states intent to migrate Post-quantum TLS for nodes as step 1 and Post-quantum TLS for client connections as step 2 of its PQ sequence, indicating awareness that current AES-256-in-TLS handshakes use classical KEM (ECDHE / X25519). Until ML-KEM hybrid TLS is deployed at consensus and client surfaces, validator-gossip and gRPC transport remain HNDL-vulnerable. SHA-384 + AES-256 reduce symmetric-side Grover exposure.

3 Metadata, Anonymity & Confidentiality weight 13% 37 / 100
3a · tx graph visibility 8 / 20

Pseudonymous transparent ledger; account IDs visible in Mirror Node. Account-ID model decouples address from pubkey but does not hide the transaction graph itself.

3b · rpc mempool concentration 9 / 20

Mirror Node operators include the foundation, several Council members, and third parties (Arkhia, Hashio JSON-RPC Relay). gRPC endpoints concentrated among Council-run nodes. No published validator-metadata retention policy.

3c · cross chain bridge correlation 8 / 20

HashPort bridge live; Chainlink CCIP supported for select assets. Passive observer can correlate source-to-dest flows across these surfaces.

3d · retroactive de anonymization 12 / 20

Lower retroactive de-anon surface than chains heavy in DL-curve-based privacy primitives (Hedera does not deploy ElGamal ring sigs / EC-curve-based zk). Historical Ed25519/ECDSA pubkeys remain Shor-vulnerable but disclosure was already pseudonymous, not anonymity-protected. SHA-384 hashing limits chain-state hash inversion.

3e · mixnet shuffle 0 / 20

No protocol-level mixnet, shuffle, or commit-reveal mixing.

4 Migration Architecture weight 10% 64 / 100
4a · crypto agility 11 / 15

Account model decouples address from key, new key types can be added at the HAPI level without breaking existing accounts. Foundation explicitly states a new post-quantum key type can be added to the Hedera API once FIPS 206 finalizes. ECDSA secp256k1 was added alongside Ed25519, that is one prior algorithm-addition precedent.

4b · aa key rotation 13 / 20

Native key rotation supported via account-update transactions (account keys can be replaced without changing account ID). Threshold keys and key lists native. Client-layer PQC path documented in the April 2026 blog (PQ TLS for clients) but not yet deployed. AA-equivalent capability via native multi-key, not ERC-4337-style smart-account-AA.

4c · hard fork track record 12 / 15

Council-coordinated network upgrades have shipped at consistent cadence. No contested forks. Coordination authority is centralized in the Council, which is both an asset and a single-point-of-coordination.

4d · hybrid deployment readiness 13 / 15

Foundation explicitly states the event signing will be updated to a hybrid signature (classical Ed25519 + FN-DSA together), this is a documented hybrid AND-composition path for consensus event signing. Architecturally feasible via account-key model. Not yet deployed.

4e · stateful hash state management 15 / 15

Planned PQ schemes (FN-DSA, ML-DSA) are stateless. Stateful-hash signature schemes (XMSS/LMS) are not in the announced migration. Default full credit per v3.1 rule.

4f · bft aggregation path 0 / 20

Hashgraph consensus uses virtual voting with gossip-about-gossip, votes are calculated locally rather than transmitted, so the consensus does not aggregate per-node signatures over a per-block message in a BLS-style scheme. Per-event signing uses Ed25519. The roadmap lists TSS signatures (threshold signature scheme for aggregating node signatures, in progress), TSS implementation candidate algorithm not yet named, no spec or testnet yet.

5 Deployment Execution weight 22% 18 / 100
5a · mainnet pqc traffic pct 0 / 25

No PQC primitive shipped on mainnet as of 2026-05-01. April 2026 blog describes the migration sequence in future tense; no deployed PQ event-signing or PQ-TLS.

5b · pqc code in consensus client 2 / 15

No PQC code merged into Hiero / hedera-services consensus client surface as of evidence cutoff. WECAN grant (Dec 2025) and SEALSQ partnership (Dec 2024) fund off-chain quantum-safe identity / hardware tooling; chain-client PQC code is research-stage.

5c · validator pqc key adoption 0 / 15

Council nodes operate under Ed25519. No validator-side PQC key adoption.

5d · published dated milestones 0 / 10

VOIDED to 0 per v3.1 rule (5a = 0). The April 2026 blog publishes a sequenced plan (PQ-TLS nodes → PQ-TLS clients → hybrid event signing → new PQ key type targeted for 2027), but only one of those is dated, and 5d is voided when 5a = 0.

5e · pqc washing delta 6 / 15

Announced PQC items in trailing 12mo (foundation blog April 2026, SEALSQ partnership Dec 2024, WECAN grant Dec 2025, multiple press echo): ~6-8 distinct announcements. Shipped PQ on mainnet: 0. The April 2026 blog is the substantive technical artifact (specific primitives + migration sequence). Tag: announcement overhang, not narrative-only. 9 points deducted.

5f · signature footprint multiplier 10 / 20

Hybrid Ed25519 + FN-DSA event signing. FN-DSA (Falcon-512) reference: ~10-11× raw signature size vs Ed25519 (Falcon-512 sig ≈ 666 bytes vs Ed25519 64 bytes ≈ 10×). Falls in 5-10× scoring band.

6 Supply Chain Vendor Readiness weight 22% 23 / 100
6a · wallet 5 / 25

Top-3: HashPack, Blade Wallet, Ledger HW. PQC-roadmap count: 0 published roadmaps for HashPack or Blade. Ledger HW carries the same general PQC posture as Ledger across all chains.

6b · bridge 6 / 25

Top-3: HashPort, Chainlink CCIP, LayerZero. PQC-roadmap count: 0 with deployed PQC. Chainlink CCIP has architecture discussions of PQ but no shipped path.

6c · custodian 8 / 25

Top-3: Fireblocks, BitGo, Anchorage Digital. PQC-roadmap count: 1 partial (Fireblocks-Hedera + SEALSQ QS7001 chip integration roadmap; Anchorage and BitGo have published PQC research, no Hedera-specific deployment).

6d · rpc hsm tee infra 4 / 25

Top-3 RPC: Hedera Mirror Node (foundation), Hashio JSON-RPC Relay, Arkhia. HSM: SEALSQ QS7001 chip with Dilithium-key embedding is a SEALSQ-side product announcement (Dec 2024) with partner mention of Hedera; no Hedera-side confirmation of deployed PQ HSMs at validator nodes is publicly available.

7 Governance & Coordination weight 8% 50 / 100
7a · validator stake distribution 8 / 20

Permissioned 31-member Governing Council (FedEx joined Feb 2026; Accenture announced 2026-04-30). Members include Google, IBM, Boeing, Standard Bank, NVIDIA, ServiceNow, FIS, abrdn, Nomura, DBS Bank, Arrow Electronics, Repsol, FedEx. Low Nakamoto coefficient by design; institutional permissioned governance.

7b · upgrade cadence under pressure 16 / 20

Consistent release cadence (recent versions 0.70 / 0.71). Council coordination is structurally fast vs anonymous-validator chains. No coordinated upgrade under live attack on record.

7c · named coordination lead 14 / 20

Hashgraph algorithm authored by a named individual; Hashgraph as a company / Council provides published mandate via Council documents. No standalone PQ working group with a named technical lead and public charter (April 2026 blog is foundation-authored without a named PQ-WG lead).

7d · adversarial coordination precedent 12 / 20

Council structure designed for coordinated decision-making; multiple Council additions and Council-driven HIP enactments document coordination capability. No precedent of coordinated cryptographic change under active attacker.

7e · canary tripwire mechanism 0 / 20

No published canary, honeypot, or rate-limited tripwire embedded in consensus.

X + Y vs Z, when does the math turn against you?

v3.1 demotes the X+Y vs Z timing test to a secondary signal, the headline output is Migration Stage. The timing test still answers the question: can this chain finish migrating before the threat lands?

X, signature shelf life
5–15 years. Account-ID model decouples address from pubkey, so shelf-life starts at first signature (not at fund-receipt). Active accounts ~5; long-dormant accounts that never signed → indefinite (key never revealed)
Y, migration time
4–7 years. Foundation-stated target for new PQ key type is 2027 (~1.5 years). Council coordination accelerates Y; no live PQ code today extends it
Z10 (10% CRQC year)
2030
Z25 (25% CRQC year)
2035

Verdict

X+Y = 2031–2038, Outside risk window vs Z25 in slow-migration scenario; Crisis Zone vs Z10 in nearly all paths

Z-compliance

Inside CNSA 2.0 2030 compliance window if delivered on schedule; outside CNSA 2027 advisory window for new contracts

Source-disagreement disclosure

v3.1 requires every chain card to publish material divergences among authoritative sources, plus the delta-QRI under alternative weighting.

Lattice family preference

Foundation blog (April 2026) presents FN-DSA as primary PQ signature; CNSA 2.0 (NSA, US gov) prefers ML-DSA. Hedera's stated fallback (ML-DSA if FIPS 206 delayed) reduces this divergence.

Architecture-vs-execution stage

Architecture is documented at Stage 3 (Architected) quality; caps from Milestone-Discipline (5d voided) and Supply-Chain pull operational stage to 2. The chain card surfaces Stage 2 as the cap-binding output.

Delta-QRI under alternative weighting

If a reader weights US-federal-aligned families higher, Dim 1d would rise ~2 pts; QRI shifts from 38 to ~40, within CI.

Announcement-to-shipped ratio

Announced: 6. Shipped: 0. Ratio: 6.

Tag: >1.5 deduction

Peers in the L1 profile

9 chains closest to Hedera by Stage then QRI.