PQ1 vs Ledger Nano X: post-quantum vs legacy (2026)
The PQ1 vs Ledger Nano X question is not a spec-sheet duel. It is a question about what a hardware wallet has to look like once a cryptographically relevant quantum computer sits inside a five-to-ten year horizon - and once the industry has watched Ledger ship a firmware update capable of sharding a user’s seed to third parties. The Nano X was designed for the ECDSA world of 2019. PQ1™ is designed for the post-quantum world NIST formalized in August 2024, when SPHINCS+ became SLH-DSA in FIPS-205.
This comparison is written for Ethereum and EVM users. If your assets live on Ethereum, an L2, or any EVM chain, keep reading. (For the wider Ledger line - Nano S Plus and Stax included - see PQ1 vs Ledger.)
TL;DR
- PQ1™ signs with SPHINCS+ (FIPS-205 design) and has no ECDSA fallback. The Nano X signs with ECDSA on secp256k1, which is quantum-vulnerable.
- PQ1™ ships dual CC EAL6+ secure elements with an XOR-split seed. The Nano X uses a single ST33-series element rated EAL5+.
- PQ1™ firmware and hardware schematics are published on GitHub. Ledger’s BOLOS operating system remains closed.
- PQ1™ has no Bluetooth and no wireless radios at all. The Nano X advertises Bluetooth 5.0 as a headline feature.
- PQ1™ is $179 and ships Q4 2026. The Nano X is $149 and available today.
At a glance
| Spec | PQ1™ | Ledger Nano X |
|---|---|---|
| Price (USD) | $179 | $149 |
| Post-quantum signatures | SPHINCS+ (FIPS-205 design), no ECDSA fallback | No - ECDSA only |
| Secure element | Dual CC EAL6+ (Infineon OPTIGA Trust M V3 + NXP SE050), seed XOR-split | Single STMicro ST33-series, EAL5+ |
| Open-source firmware | Yes (GPLv3, reproducible builds) | No - closed BOLOS OS |
| Open-source hardware | Yes - schematics and BOM published | No |
| ERC-4337 native | Yes (v0.6 smart account) | No |
| Radios | None | Bluetooth 5.0 |
| Connectivity | USB-C only | Bluetooth + USB-C |
| Blind-signing risk | Removed - transactions decoded on device | Present; a historical exploit vector |
| Supported chains | Ethereum + every EVM L2 | Multi-chain (5,500+ assets) |
| Availability | Pre-order, ships Q4 2026 | Shipping today |
Where PQ1™ wins
Post-quantum signing by default
Roughly $3.7 trillion of crypto market cap sits behind ECDSA today. Every address that has ever broadcast a transaction has exposed its public key, which makes it a harvest-now-decrypt-later target; estimates put around 25% of BTC and a comparable share of ETH in that category.
The Nano X signs everything with ECDSA on secp256k1. PQ1™ signs with SPHINCS+, the hash-based scheme NIST standardized as SLH-DSA in FIPS-205, and offers no ECDSA fallback path. Those signatures are verified on Ethereum inside an ERC-4337 account contract, so no L1 upgrade is required for a PQ1™ to work today. See the math behind the C10 parameter set.
Dual EAL6+ secure elements with an XOR-split seed
The Nano X uses a single STMicroelectronics ST33-series element certified to Common Criteria EAL5+. That is a solid chip, but it is one chip, from one vendor, under NDA.
PQ1™ uses two independent CC EAL6+ elements from different vendors - an Infineon OPTIGA Trust M V3 and an NXP SE050 - and XOR-splits the recovery seed across them, so neither chip alone reveals a single bit of the seed and a single-chip compromise recovers nothing. EAL6+ is the tier used by government identity documents and defense-grade smart cards: a category above the Nano X, and above most consumer competitors. More on the dual secure-element architecture.
Fully open source - firmware and hardware
Ledger’s operating system, BOLOS, is proprietary. Users cannot audit the code that signs their transactions and must trust that closed firmware behaves as advertised.
That assumption took direct damage in May 2023, when Ledger revealed the Recover firmware update - a capability to shard an encrypted seed backup to three third-party custodians. Even after a partial walk-back, the episode confirmed that a closed-firmware vendor can ship a capability the community had believed was cryptographically impossible.
PQ1™ publishes full firmware source and hardware schematics at EthereumPhone/PQ1, under GPLv3 and with reproducible builds. Every change is public and diffable before it reaches your device.
No radios, true air-gap
Bluetooth is the Nano X’s headline feature. It is also an attack surface that Coldcard, Keystone, and now PQ1™ have deliberately removed. PQ1™ has no Bluetooth, no NFC, and no radio of any kind - communication is USB-C HID only, and every signature is a physical, deliberate act. The Nano X can be run in USB-only mode, but the radio is still present in the hardware, and Bluetooth SoC stacks have a steady CVE history.
ERC-4337 native
Because PQ1™ signatures are verified inside an ERC-4337 account contract, users get social recovery, transaction batching, gas sponsorship, session keys, and per-key spending limits as first-class features. The Nano X targets externally owned accounts and depends on external wallet software for any account-abstraction workflow.
Verifiable firmware, checkable by a non-specialist
At boot, PQ1™ measures its own secure-world image and renders the hash as eight BIP-39 words on screen, which you compare against the words a build you produced yourself prints. The firmware image is also structured so a non-specialist can paste it into an LLM and get a coherent audit.
That does not replace formal review. It does close the trust gap between a security engineer and an everyday user - which is exactly where real-world hardware-wallet failures happen. December 2023’s Ledger Connect Kit supply-chain attack drained more than $600,000 from users who trusted a signed frontend library from Ledger itself. Verifiable, open code narrows that class of failure.
The gap, visualized
Post-quantum readiness 0 = ECDSA only, 10 = fully post-quantum
PQ1 ██████████ 10
Ledger Nano X ░░░░░░░░░░ 0
Openness (firmware + hardware)
PQ1 ██████████ 10
Ledger Nano X ██░░░░░░░░ 2
Wireless attack surface 0 = air-gapped, 10 = always-on radios
PQ1 █░░░░░░░░░ 1
Ledger Nano X ██████░░░░ 6
Where the Ledger Nano X still wins
The Nano X is not a bad device for its era, and it beats PQ1™ on real axes:
- Multi-chain breadth. If your portfolio spans Bitcoin, Solana, XRP, Cardano, Cosmos, and a long tail of L1s, the Nano X supports more than 5,500 assets natively. PQ1™ v1 is Ethereum and EVM only - by design, since shipping Bitcoin or Solana would require a classical-signer fallback that defeats the post-quantum promise.
- Availability. If you need a wallet this week and cannot wait for Q4 2026, the Nano X is on shelves.
- Ecosystem maturity. Six years of exchanges, custody providers, and dApps testing against Ledger Live is worth something.
- Price. $149 versus $179 - for a quantum-vulnerable wallet. For a quantum-secure one, PQ1™ is the only option.
If you already own a Nano X and use it only for cold, low-value ETH you plan to rotate to a post-quantum address before a CRQC arrives, keeping it is defensible.
Bottom line
For Ethereum and EVM users who plan to hold assets through the 2030s, PQ1™ is the more honest bet. Post-quantum signatures, dual EAL6+ chips, an XOR-split seed, open firmware, and no radios add up to a device built for the threat model the industry faces next - not the one it faced in 2019. Read the PQ1™ whitepaper for the full air-gap and signing threat model.
For a multi-chain generalist who needs Bitcoin and Solana on the same device this week, the Nano X remains the practical pick until a PQ1-class multi-chain successor exists.
FAQ
Is the Ledger Nano X quantum-safe?
No. The Nano X signs with ECDSA on secp256k1, the same elliptic-curve scheme Shor’s algorithm is designed to break on a sufficiently large quantum computer. It has no post-quantum signature option and no announced upgrade path to one. Any ETH or BTC address that has ever spent from itself already has its public key on-chain, making it a harvest-now-decrypt-later target.
What is post-quantum cryptography in a hardware wallet?
Post-quantum cryptography is a family of signature and encryption schemes designed to resist attacks from large-scale quantum computers. In a hardware wallet it means the device signs transactions with a scheme like SPHINCS+ (SLH-DSA, FIPS-205) or ML-DSA rather than ECDSA. PQ1™ uses SPHINCS+ and verifies those signatures on Ethereum inside an ERC-4337 account contract, so no L1 protocol upgrade is required.
Is PQ1 open source?
Yes. Both the PQ1™ firmware and the hardware schematics are published under EthereumPhone/PQ1 on GitHub, with reproducible builds - so independent auditors, and any user willing to run a diff, can verify what the device is actually running before signing a transaction. Ledger’s BOLOS operating system remains closed source.
Can PQ1 replace my Ledger for ETH?
For Ethereum and EVM chains, yes. PQ1™ is Ethereum-native by design and covers the assets a Nano X holds on Ethereum, Arbitrum, Base, Optimism, Polygon, and other EVM networks, with ERC-4337 features like social recovery and batching on top. It cannot replace a Nano X for Bitcoin, Solana, XRP, or other non-EVM chains.
When does the PQ1 ship?
Pre-orders are open now, with worldwide shipping scheduled for Q4 2026. Payment is accepted in crypto (USDC) and in fiat by card. Pricing is $179.
Is the Ledger Nano X still safe to use in 2026?
For short-horizon, non-quantum-critical holdings, the Nano X still provides EAL5+ secure-element protection and remains functional. The larger caveats are the closed firmware, the 2023 Ledger Recover episode that showed a firmware update could shard a seed to third parties, the December 2023 Connect Kit supply-chain attack that drained more than $600,000, and the fact that every signature it produces is quantum-vulnerable ECDSA. Anyone planning to hold ETH through the late 2020s should treat it as legacy hardware.
Get the device
PQ1™ is available now for $179. Hash-based post-quantum signing (SPHINCS+, per the NIST FIPS-205 design), open firmware, air-gapped by default.
Reserve PQ1™