Why we built the first quantum-safe hardware wallet
Four years ago we were building mobile operating systems. A bet we took on where the crypto market was headed.
The specific architectural decisions we made with the dGEN1 revealed a way to make smart accounts more prolific than we’d originally thought. We knew they were useful, but after Google released its recent 2029 Q-day deadline, ERC-4337 became the architecture that would unlock post-quantum security for the foreseeable future.
Since ethOS paved the way for making smart wallets interoperable, we knew what the next logical step was.
And at the same time, 3 things converged which hadn’t been true just months before:
- Google publicly committed to migration on a near-term timeline.
- Vitalik publicly stated that the emergency plan exists and is something we want to avoid having to use.
- SPHINCS emerged as the dominant algorithm for post-quantum cryptography.
The pieces just revealed themselves, but had not been assembled in a device a user could hold. Until now.
That is why we built the PQ1™.

What we believe
We believe Q-Day is closer than the consensus market thinks. The work on Quantum computers is growing exponentially, and quantum algorithms are becoming exponentially more efficient, meaning when those two lines meet, Q-day has arrived. And they’re each accelerating.
Put another way, Mosca’s inequality, the framework most policy bodies use to reason about migration windows, gives you the math:
| if the time your secret must remain confidential (X) plus the time your migration takes (Y) is greater than the time until a cryptographically relevant quantum computer arrives (Z), you are already in trouble**.**
In short, if X + Y > Z (Q-Day arrives), you’re fucked.
Because many think Ethereum has plans to upgrade, they assume they are safe. This is wrong.
The EVM itself will be quantum secure, but all EOA (externally owned accounts), the wallets everyone uses today, can be compromised. Even if you’ve signed even a single transaction, a quantum computer can derive your private key from the public one.
That means every wallet, hot, cold, hardware, software, multi-sigs, custodial accounts, etc…will need to migrate.
The migration is then asymmetric: if you migrate early, you pay a small gas cost and lose nothing. If you wait until an emergency, you depend on a hard fork that cannot make your assets secure without you migrating.
But ethereum users can do better, if they start now.
And most importantly, we believe that the device a user trusts with their assets should be a device the user can verify, not a device the user is asked to trust.
This is what made the architectural decisions for PQ1™ easy.
What we built
PQ1™ is the first consumer hardware wallet that:
- Signs transactions using Post-Quantum verified SPHINCS-C10 algorithm, with verification handled inside an ERC-4337 smart wallet. This is the exact architecture Vitalik specifically named as the practical migration path in his February 2026 Ethereum quantum-resistance roadmap.
- Ships with fully open hardware schematics, fully open firmware (GPLv3), fully open smart contracts (AGPL), and fully public reproducible-builds. Anyone can compile the firmware from source and produce a bit-for-bit identical binary to what we ship.
- Splits the user’s seed across two EAL6+ secure enclaves from two different vendors, with two different supply chains, using an XOR construction that is information-theoretically secure: knowledge of one half provides zero information about the other.
- Replaces blind signing with local clear-signing (On device tx decoding). Every cowswap and most safe transactions read as a human-readable trade intent (“Sell 100 USDC for at least 0.4 WETH on CoW Swap”) rather than a hex hash. PQ1™ will end blind-signing for good.
Each of these UX decisions stems from a specific failure that the crypto market has suffered, or will in the coming years.
PQ1™ is the first wallet to solve all of them, at once.
Why now
Existing hardware wallets ask you to take two things on faith simultaneously: that the vendor’s firmware does what the vendor claims it does, and that the firmware running on your specific device is the firmware the vendor says it shipped.
You cannot verify either claim. The only security guarantee you have is the vendor’s reputation.
Hardware wallets are durable goods. The wallet you buy today is the wallet that sits in their drawer for five to ten years. Which means the architectural decisions we ship today will determine how much onchain value is exposed when Q-Day arrives, and how users interact with hardware wallets into the future.
We are not asking anyone to trust us. We are giving you the tools to verify.
Post-quantum. Open source. Yours.
PQ1™.
- The FreedomFactory team
Related reading
Built for what comes next
PQ1™ is the first hardware wallet that protects Ethereum and EVM holdings against quantum computers. Hash-based post-quantum signing (SPHINCS+, per the NIST FIPS-205 design) in an open-firmware, air-gapped device. $179.
Reserve PQ1™