NEAR Protocol activated v2.13.0 on mainnet on July 10, 2026, becoming the first major Layer 1 blockchain to ship NIST-finalized post-quantum signatures (FIPS-204 / ML-DSA-65) in production. The upgrade also introduced dynamic resharding at epoch boundaries and a new gas-key system (NEP-611) that ...
"With quantum-safe signing standards, we've ensured that NEAR users have the tools to protect their assets in a future where quantum threats are real." — Illia Polosukhin, Co-founder, NEAR Protocol
NEAR Protocol activated v2.13.0 on mainnet on July 10, 2026, becoming the first major Layer 1 blockchain to ship NIST-finalized post-quantum signatures (FIPS-204 / ML-DSA-65) in production. The upgrade also introduced dynamic resharding at epoch boundaries and a new gas-key system (NEP-611) that lets applications subsidize user transaction fees.
The deployment arrives three months after Google Quantum AI published a paper (arXiv: 2603.28846) demonstrating that Shor's algorithm could break 256-bit elliptic-curve cryptography with fewer than 1,200 logical qubits — roughly a 20-fold reduction from prior estimates. That paper compressed the industry's timeline assumptions and triggered post-quantum work across multiple chains. Project Eleven's 2026 report estimates "Q-Day" — the date a quantum computer can break ECDSA-256 — at 2033 in its baseline scenario, 2030 in its optimistic case, and 2042 in its pessimistic case.
The stakes are material. An estimated 6.9 million BTC (approximately $440 billion at current prices) sit in addresses with exposed public keys, directly vulnerable to Shor's algorithm. Across the broader cryptocurrency market, more than $2 trillion in assets rely on elliptic-curve cryptography that quantum machines could eventually compromise. NEAR's v2.13 is one data point in a larger migration that most chains have barely started.
On March 31, 2026, Google Quantum AI researchers Ryan Babbush and Hartmut Neven published "Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly," co-authored with researchers from the Ethereum Foundation and Stanford University. The 57-page paper presented two optimized quantum circuits implementing Shor's algorithm against ECDLP-256:
The physical qubit estimate: fewer than 500,000 on superconducting hardware, executable within minutes. Google's own 2019 estimate had required roughly 20 million physical qubits. The paper reduced the requirement by approximately 20x.
In a notable disclosure decision, Google verified its circuit designs using zero-knowledge proofs rather than publishing full implementations — a responsible-disclosure approach intended to substantiate the findings without handing a blueprint to potential attackers.
Google itself set a 2029 internal deadline for migrating all its own systems to post-quantum cryptography. The paper recommended that blockchain networks begin migration planning immediately.
NEAR's v2.13.0 mainnet upgrade, activated July 10, 2026, bundled three significant protocol changes:
The upgrade added ML-DSA-65 as a third key type alongside NEAR's existing Ed25519 and SECP256K1 options. ML-DSA-65 (formerly CRYSTALS-Dilithium) is a module-lattice-based digital signature algorithm finalized by NIST in August 2024 as FIPS-204 after an eight-year evaluation process. It produces signatures of approximately 3,309 bytes with public keys of 1,952 bytes — substantially larger than Ed25519's 64-byte signatures and 32-byte keys, but resistant to known quantum attacks.
NEAR's account model provides a structural advantage. Unlike Bitcoin and Ethereum, where wallet addresses are cryptographically derived from public keys, NEAR uses human-readable account names with rotatable "access keys." A user can rotate to a quantum-safe key type in a single transaction without changing their account address or migrating funds. According to NEAR, this contrasts with Solana's approach, which requires coordinated user migrations.
The upgrade also extended quantum-safe Chain Signatures to over 35 external chains, including Bitcoin, Ethereum, and Solana — meaning NEAR-based cross-chain transactions can use post-quantum signing even when interacting with chains that have not yet migrated.
NEAR's Nightshade sharding system gained automatic shard splitting at epoch boundaries. The protocol monitors the state size of each shard in real time. When a shard crosses a predetermined capacity threshold, the protocol splits it without governance votes or manual coordination.
NEAR describes this as making network capacity "a runtime property, not a governance event." Before v2.13, shard configurations required protocol-level upgrades. The new system allows the network to scale throughput in response to demand without human intervention.
The new gas-key system lets applications prepay transaction fees on behalf of users. An application registers a "gas key" and deposits NEAR tokens to fund transactions. When users transact through that application, the gas cost draws from the application's deposit rather than the user's balance.
The intended use case is onboarding: new users can interact with a dApp without first acquiring NEAR tokens. The mechanism is similar in concept to Ethereum's ERC-4337 paymasters but implemented at the protocol level rather than as a smart-contract abstraction.
The blockchain industry's post-quantum preparedness varies significantly. CryptoTimes categorizes chains into three tiers:
Ethereum has the most structured preparation. The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026 and published a four-year "Strawmap" roadmap in February 2026 targeting approximately 2029 completion. Ethereum faces a more complex challenge than most chains: it must replace four distinct vulnerable cryptographic layers — consensus BLS signatures, KZG data-availability commitments, ECDSA account signatures, and zero-knowledge proof systems. The Foundation allocated a $1 million "Poseidon Prize" for research and runs weekly interoperability devnets across more than 10 client teams. Account abstraction via EIP-8141, under consideration for the Hegotá fork in H2 2026, would allow individual accounts to select post-quantum signature schemes without a protocol-wide migration.
Solana deployed a testnet with quantum-resistant signatures using Falcon (FN-DSA), a NIST-approved lattice-based scheme selected for its compact design. However, early tests revealed severe tradeoffs: quantum-safe signatures are up to 40x larger than current signatures and reduced network throughput by roughly 90% in testing. Solana faces a structural vulnerability unique among major chains — 100% of its addresses expose public keys directly, compared to Bitcoin and Ethereum where many addresses are derived from hashed keys. The Solana Foundation published a phased migration plan in April 2026, with full wallet migration triggered only when at least 10% of staked value votes with post-quantum keys.
NEAR Protocol, as described above, has shipped FIPS-204 signing on mainnet — the furthest along in production deployment among major chains.
Bitcoin has BIP-360 (Pay-to-Merkle-Root) in its official repository as of February 2026, with a testnet deployed in March 2026 using more than 50 miners. Co-author Ethan Heilman estimates seven years for full migration — comparable to SegWit (8.5 years) and Taproot (7.5 years). Given Bitcoin's conservative governance model, this timeline appears realistic but leaves the network exposed during the transition.
Cardano and Tron have published research papers but no implementation plans.
BNB Chain and Monero have no publicly disclosed post-quantum cryptography programs, according to available documentation.
Deploying post-quantum algorithms is the easier half of the problem. The harder half is migrating existing keys and addresses.
Bitcoin's challenge is illustrative. An estimated 6.9 million BTC — roughly 33% of circulating supply — sits in addresses whose public keys have been exposed on-chain. These coins are directly vulnerable to a quantum attacker running Shor's algorithm. Approximately 1 million BTC attributed to Satoshi Nakamoto fall into this category. These coins cannot be migrated because no one holds the private keys, raising what CoinDesk termed the "freeze or not freeze" governance question.
Ethereum faces a different version of the same problem: more than $200 billion in locked DeFi value depends on smart contracts that reference specific cryptographic primitives. Migrating those contracts requires protocol-level changes and, in many cases, redeployment of contract logic.
NEAR's rotatable access-key model sidesteps the worst of this complexity for individual accounts but does not eliminate it entirely for cross-chain interactions and smart contracts that embed cryptographic assumptions.
The "harvest now, decrypt later" attack vector adds urgency. Adversaries can collect encrypted blockchain data today with the expectation of decrypting it once sufficiently powerful quantum hardware exists. Every year of delayed migration is another year of vulnerable data accumulating.
The total cryptocurrency market capitalization exposed to quantum risk is difficult to quantify precisely, but available estimates converge on several data points:
The economic calculus is straightforward. If Q-Day arrives at Project Eleven's baseline estimate of 2033, and major chains require 5-7 years for full migration, the window for action is narrow. Chains that have not begun active implementation are, by this arithmetic, already behind schedule.
NEAR Protocol's v2.13 mainnet upgrade is a technical milestone, but its broader significance is as a measuring stick. One chain with a $2.5 billion market capitalization has shipped post-quantum signatures in production. The chains securing hundreds of billions or trillions in value have not.
The gap between the Google paper's compressed timeline estimates and the blockchain industry's actual migration pace is the central risk. Post-quantum cryptography standards have been finalized by NIST since August 2024. The algorithms exist. The specifications are published. What remains is engineering execution and governance coordination — historically the slowest variables in decentralized systems.
The question is not whether blockchains will need post-quantum cryptography. It is whether they will have it before they need it.