Sui is integrating two NIST-approved post-quantum signature schemes, ML-DSA-65 and SLH-DSA-SHA2-128s, to protect accounts against future quantum computing threats. The upgrade leverages Sui's cryptographic agility, allowing users to transition to quantum-safe keys using existing recovery phrases without core protocol changes. Vaults are slated for mainnet in 2026, with native accounts following in 2027.
Sui post-quantum signature integration
- ▪The Sui blockchain network is integrating two post-quantum signature schemes approved by the National Institute of Standards and Technology to enable quantum-safe accounts
- ▪Sui noted that integrating post-quantum signatures and public keys will inevitably increase transaction sizes because they are substantially larger than Ed25519 keys
- ▪Sui stated that its network was built for cryptographic agility, allowing signature schemes to be added as routine protocol-feature updates without changing consensus or existing state
Quantum computing threat to blockchain
- ▪Sui highlighted the risk of "harvest-now-forge-later" attacks, where attackers collect exposed public keys today to exploit them once quantum hardware becomes available
- ▪Sui warned that a sufficiently capable quantum computer running Shor's algorithm could eventually break the elliptic-curve cryptography securing most onchain accounts
ML-DSA-65 for native accounts
- ▪Sui chose Level 3 security for ML-DSA-65 instead of Level 1 after a July 2026 incident where an AI model halved the effective key strength of another post-quantum candidate
- ▪Sui will add ML-DSA-65, corresponding to the FIPS 204 digital signature standard, as a native protocol signature scheme for everyday accounts at Level 3 security
SLH-DSA-SHA2-128s for smart contracts
- ▪Sui is integrating the hash-based SLH-DSA-SHA2-128s signature scheme, corresponding to FIPS 205, inside Move smart contracts for high-value vaults
- ▪Handling SLH-DSA-SHA2-128s inside Move contracts allows Sui to remain compatible with future industry post-quantum standards without requiring a core protocol upgrade
- ▪The ML-DSA-65 and SLH-DSA-SHA2-128s schemes on the Sui network rest on different mathematics so that a vulnerability in one does not undermine the other
Recovery phrase compatibility
- ▪Sui address aliases will allow existing accounts to update their authorization keys without needing to transfer assets
- ▪Sui users will be able to transition to quantum-safe keys using their existing recovery phrases because Sui keys derive deterministically from a seed
Mainnet deployment timeline
- ▪The post-quantum accounts on the Sui network will arrive as an additive, opt-in capability, meaning no existing applications or user setups require immediate changes
- ▪Sui targets the deployment of quantum-safe vaults on its mainnet in 2026, with native ML-DSA-65 accounts planned for testnet by the end of 2026
- ▪Sui targets the launch of native account authentication on its mainnet for the first quarter of 2027
Story comments
Loading comments…