Helium built a million-device global wireless network — but every hotspot owner key, maker authority key, and subnetwork DAO governance key runs on secp256k1 or ed25519. Both are Shor-vulnerable. Four years of Proof of Coverage signatures from 1M+ devices are permanently archived on a blockchain that cannot be patched.
Published 2026-09-05 · Independent technical analysis · DYOR · Not investment advice
❌ COMMON MISCONCEPTION: "Helium migrated to Solana in 2023, so the old L1 quantum risk is gone and the network now benefits from Solana's ongoing development."
This is incorrect on two levels. First, the original Helium L1 blockchain and its entire secp256k1 key archive — over four years of Proof of Coverage events, hotspot assertions, and governance votes from 1M+ devices — remains permanently on-chain and permanently harvestable. Migration to Solana does not erase or remediate this archive. Second, Solana itself uses ed25519, which is equally vulnerable to Shor's algorithm via the Elliptic Curve Discrete Logarithm Problem (ECDLP). Helium simply traded one CRQC-vulnerable curve for another.
✅ TECHNICAL REALITY: Helium's Solana migration created a dual-era HNDL surface: the immutable legacy secp256k1 archive (2019–2023) plus an expanding Solana ed25519 archive (2023–present). The migration also introduced a second external blocker — Solana L1 PQC remediation — without removing the first (legacy L1 irremediability). The result is a more complex quantum security posture than any single-chain, single-era protocol.
Helium's wireless DePIN infrastructure distributes cryptographic authority across four distinct key types, each creating an independent HNDL attack surface.
Each of the 1M+ Helium hotspots is controlled by an owner key pair. On the legacy L1, these were secp256k1; post-migration, ed25519 Solana keypairs. Every Proof of Coverage beacon, witness receipt, and reward claim is signed by the owner key — creating a continuous, per-device signing archive since 2019.
Approved hotspot manufacturers (Bobcat, RAK Wireless, Nebra, Freedomfi, and others) hold maker key pairs. Maker keys sign hotspot onboarding transactions and location assertions. CRQC recovery enables phantom device onboarding and fraudulent PoC reward claims at scale without physical hardware.
Helium governance is segmented into the IoT subDAO (LoRaWAN) and Mobile subDAO (5G CBRS/WiFi). Protocol upgrades, reward curve changes, and emergency actions require governance votes signed by HNT and MOBILE token holders — ed25519 Solana keys, all CRQC-vulnerable.
Helium's HNT/DC price oracle system uses signed price feed attestations to determine the HNT-to-Data Credit conversion rate. Signed oracle price updates are on-chain. CRQC recovery of oracle authority keys enables data credit price manipulation — effectively granting free data transmission while imposing losses on DC purchasers.
Four years of Proof of Coverage signatures from 1M+ secp256k1 hotspot owner keys permanently on the original Helium blockchain. No remediation path exists — the legacy L1 cannot be patched, upgraded, or rolled back. This is the largest pre-quantum IoT device signing archive in DePIN history.
Each approved manufacturer's maker key has been used to onboard tens of thousands of real hotspots. Every onboarding transaction is a signed archive entry. CRQC recovery grants the ability to onboard unlimited phantom devices, spoof global coverage maps, and drain PoC reward pools — zero physical hardware required.
Emergency PQC migration requires a governance vote signed by HNT/MOBILE holders — the exact key type a CRQC targets. An adversary recovering high-weight governance keys could block the rescue vote while simultaneously draining subnetwork reward pools. The migration that could prevent the attack requires the very keys the attack compromises.
Post-migration hotspot owner keys are Solana ed25519 keypairs. Every PoC event, reward claim, and assertion on the current Solana infrastructure is a new HNDL corpus entry. The archive grows continuously as the network operates — expanding the attack surface with each passing month.
Helium operates three independent subnetworks: IoT (LoRaWAN), Mobile (5G CBRS), and WiFi (planned). Each maintains separate reward pools distributed by hotspot key signatures. CRQC recovery across multiple subnetwork hotspot keys enables simultaneous reward pool drain across all active network types.
Signed HNT/DC price oracle attestations determine the burn rate for Data Credits — the utility token used to pay for IoT and Mobile data transfer. CRQC recovery of oracle authority keys enables systematic DC underpricing: unlimited near-free data transmission for an adversary while DC purchasers face artificial scarcity.
The original Helium L1 blockchain is permanently archived and cannot receive protocol upgrades. All secp256k1 signatures from 2019–2023 are irremediably harvestable — no migration, no protocol upgrade, and no governance vote can alter this. It is a permanent structural blocker unique to Helium among major DePIN networks.
Helium's current infrastructure depends entirely on Solana's ed25519 PQC remediation path. A Solana Improvement Document (SIMD) proposing ed25519 key replacement had not been published as of September 2026. Helium cannot migrate to post-quantum cryptography unilaterally — it must wait for Solana L1 to provide a compliant key scheme.
A CRQC operator targeting Helium would likely follow a staged attack sequence, exploiting both the legacy L1 archive and the current Solana infrastructure simultaneously.
This analysis focuses on cryptographic security architecture. Helium has significant non-cryptographic strengths that are unaffected by this analysis.
Helium launched in 2019 and is the oldest and largest decentralised wireless infrastructure network, with over five years of production operation and real-world coverage data.
Over one million hotspot devices deployed globally across LoRaWAN, 5G CBRS, and expanding WiFi coverage — the largest peer-deployed wireless network in the world by device count.
Helium Mobile has established carrier partnerships and real-world cellular offload agreements, giving HNT genuine utility beyond speculative demand.
Successfully migrated from a custom L1 to Solana in 2023, demonstrating the ability to execute a large-scale protocol migration across 1M+ devices and token holders.
Operating three independent subnetworks (IoT, Mobile, WiFi) diversifies revenue streams and reduces single-network dependence — a structural advantage over single-use-case DePIN competitors.
Nova Labs (formerly Helium Inc.) has secured significant institutional backing and maintains active protocol development, ongoing carrier partnership negotiations, and an expanding global coverage map.
| Criterion | Helium (HNT) | BMIC |
|---|---|---|
| Signature Algorithm | secp256k1 (legacy L1) + ed25519 (Solana) — both ECDLP/Shor-vulnerable | NIST FIPS 204 ML-DSA (CRYSTALS-Dilithium) — post-quantum native |
| Key Encapsulation | None — EVM/Solana token transfers use ECDLP-based key derivation | NIST FIPS 203 ML-KEM (CRYSTALS-Kyber) |
| Hash-Based Fallback | Not implemented | NIST FIPS 205 SLH-DSA |
| HNDL Surface | Critical — 1M+ hotspot keys archived since 2019 across two blockchain eras | None — no pre-quantum signing archive |
| Legacy Archive Remediability | Irremediable — Helium L1 (2019–2023) cannot be patched | N/A — post-quantum from genesis |
| Key Rotation Without Address Change | Not supported — key change = new account identity | Supported via ERC-4337 account abstraction |
| PQC Migration External Blockers | 3 blockers — Solana SIMD, governance circular paradox (×2 subDAOs), legacy irremediability | None — PQC is the current live architecture |
| Maker Authority Key Risk | High — all manufacturer onboarding authority archived and CRQC-targetable | N/A — no equivalent legacy maker key system |
| Governance Key Risk | Circular paradox — governance vote required to fix the governance key vulnerability | Governance architecture post-quantum by design |
| Oracle Authority Key Risk | Medium — DC pricing authority keys on-chain and CRQC-targetable | N/A |
| Smart Account Standard | Not supported | ERC-4337 native |
| Presale Stage | Not in presale | Live presale — bmic.ai |
Yes. Helium used secp256k1 keys on its original L1 blockchain from 2019 to 2023, with over one million hotspot owners signing Proof of Coverage events on-chain. After the 2023 Solana migration, hotspot and governance keys became ed25519 Solana keypairs. Both secp256k1 and ed25519 are vulnerable to Shor's algorithm via ECDLP. A CRQC can recover private keys from all archived signed transactions across both eras.
From 2019 to 2023, the original Helium L1 recorded over one million hotspot owner keys signing Proof of Coverage challenges, beacons, and witness receipts continuously — the largest per-device cryptographic signing archive in DePIN history. These secp256k1 keys and archived signatures are permanently stored on an immutable blockchain that cannot be patched or rolled back.
Helium governance is divided into the IoT subDAO and Mobile subDAO, both requiring token-holder governance votes for protocol upgrades. Every governance vote is signed by an ed25519 Solana key — the same key type a CRQC targets. An emergency PQC migration requires a governance vote signed by the very keys an adversary could recover. A capable adversary could block the rescue vote while simultaneously draining HNT and MOBILE reward pools.
Each approved hotspot manufacturer holds a cryptographic key used to onboard new devices and assert their locations on-chain. CRQC recovery of a maker key enables unlimited phantom hotspot onboarding, fraudulent location assertions, and PoC reward theft without any physical hardware. Every onboarding transaction expands the HNDL corpus.
No. The migration moved Helium from secp256k1 (legacy L1) to ed25519 (Solana) — both are ECDLP-vulnerable curves that Shor's algorithm can break. The migration did not remediate the legacy L1 archive (which is permanently irremediable), and it introduced a new external blocker: Solana's own ed25519 PQC migration, which depends on a SIMD not published as of September 2026.
BMIC is built on NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — all three NIST-standardised post-quantum primitives. ERC-4337 account abstraction enables key rotation without address changes, eliminating the irremediability problem. BMIC carries no legacy pre-quantum signing archive and faces zero external migration blockers.
BMIC is currently in presale. Visit bmic.ai for the live presale price and raise total. DYOR before making any financial decision.
No. This page is an independent technical analysis of cryptographic security architectures. It is not financial or investment advice. Crypto presales and tokens carry significant risk. Always do your own research (DYOR) before making any financial decision.
While Helium manages a dual-era HNDL surface, a legacy irremediable archive, and three PQC migration blockers, BMIC ships NIST FIPS 203/204/205 post-quantum cryptography as its core product — from day one, with no pre-quantum debt.
Explore BMIC Presale →DYOR. Not financial advice. Crypto presales carry significant risk. Past performance is not indicative of future results.