Keys, Post-Quantum and Everything: Rotating a Live NEAR Account to ML-DSA-65
Fireblocks demonstrated a live NEAR account migration from Ed25519 to the post-quantum ML-DSA-65 signature scheme, completing the rotation in two transactions while preserving the account address and functionality.
Fireblocks successfully rotated a funded NEAR account from the classical Ed25519 signature scheme to the post-quantum ML-DSA-65 algorithm in two transactions, maintaining the same account address throughout. The new key signed the transaction that retired the old key, ensuring the replacement had demonstrated control before revocation. This approach prevented scenarios where a failed replacement could leave the account without a usable signing key.
The experiment highlighted the urgency of post-quantum migration due to the quantum threat posed by Shor’s algorithm to classical public-key cryptography like RSA, ECDSA, and EdDSA. NIST’s proposed transition schedule targets deprecation of vulnerable algorithms after 2030 and disallowal after 2035, though these are planning targets rather than predictions of practical quantum attacks. For blockchain assets, exposure begins when a public key is visible on-chain, as seen with NEAR’s implicit accounts where the address itself encodes the original Ed25519 public key.
NEAR’s mainnet upgrade in July 2026 introduced ML-DSA-65 support, enabling accounts to adopt post-quantum signing alongside existing schemes like Ed25519 and secp256k1. The migration process leverages NEAR’s account model, where an account can hold multiple access keys of different types, allowing in-place key rotation without transferring assets to a new address. This flexibility simplifies institutional adoption but requires careful operational controls to manage key lifecycle and compliance.
Fireblocks generated and secured the ML-DSA-65 key using an open-source PKCS#11 interface with kryoptic, a software HSM, for the mainnet experiment. The rotation process involved registering the new key, using it to remove the original Ed25519 access key, and validating the transition through six transactions covering creation, transfers, and post-rotation operations. The experiment underscored the importance of splitting rotation into two transactions to prevent loss of signing authority and the need to preserve account deletion controls during migration.