Sui has added two NIST-approved post-quantum signature schemes to its blockchain roadmap because it prepares optionally available quantum-safe accounts and vaults for future community upgrades.
Abstract
- Sui plans so as to add two NIST authorised publish quantum signature schemes for accounts and good contract vaults.
- Present restoration phrases and pockets addresses could be retained when customers transfer to quantum protected authentication.
- Quantum protected vaults are focused for mainnet this yr, with native accounts deliberate for testnet by the tip of 2026.
- ML DSA 65 and SLH DSA are designed to guard various kinds of belongings utilizing separate cryptographic approaches.
- The announcement follows comparable publish quantum safety work throughout Bitcoin custody, BNB Chain and different blockchain initiatives.
In line with Sui’s newest announcement, the blockchain plans to introduce ML-DSA-65 as a local signature scheme for normal accounts and SLH-DSA-SHA2-128s for high-value good contract vaults, giving customers an optionally available method to defend accounts in opposition to future quantum computing dangers with out changing their restoration phrases or shifting belongings.
The rollout comes as blockchain builders and infrastructure suppliers more and more put together for the chance that future quantum computer systems might break at present’s public-key cryptography.
Not like conventional programs the place public keys typically stay hidden till wanted, Sui stated blockchain accounts expose public keys onchain as soon as transactions happen, permitting attackers to gather them years earlier than sensible quantum computer systems exist.
The community warned that such “harvest-now-forge-later” assaults don’t require quantum {hardware} at present as a result of attackers can merely archive uncovered public keys and wait till sufficiently succesful machines turn into accessible.
Citing analysis from Google Quantum AI printed in March 2026, Sui stated recovering a non-public key from an uncovered public key might finally take minutes on a fault-tolerant quantum pc utilizing fewer than 500,000 bodily qubits.
Sui additionally pointed to altering authorities timelines round quantum safety. The announcement famous that whereas the U.S. Nationwide Institute of Requirements and Know-how beforehand focused 2030 to part out classical cryptographic algorithms and 2035 to ban them, Govt Order 14412, signed in June 2026, requires U.S. federal companies to deploy post-quantum key institution by the tip of 2030 and post-quantum digital signatures by the tip of 2031 for delicate programs.
Sui has chosen two algorithms for various safety wants
As an alternative of counting on one post-quantum algorithm, Sui stated it chosen two standardized signature schemes constructed on completely different mathematical foundations so {that a} weak spot found in a single wouldn’t have an effect on the opposite.
For on a regular basis person accounts, the blockchain will combine ML-DSA-65, the Degree 3 parameter set outlined below NIST’s FIPS 204 customary, immediately into the protocol.
The community stated it deliberately chosen the higher-security Degree 3 possibility as a substitute of Degree 1 following a July 2026 incident through which researchers used an AI mannequin to scale back the efficient safety of the HAWK post-quantum signature candidate after consultants had beforehand reviewed it. In line with Sui, the incident didn’t have an effect on ML-DSA, nevertheless it strengthened the worth of selecting stronger safety margins somewhat than lower-cost parameters.
The announcement added that ML-DSA-65 has already gained help elsewhere. Chrome and Cloudflare use the identical safety stage for post-quantum encryption defending greater than half of human-initiated net visitors, whereas AWS Key Administration Service now helps ML-DSA signing and Android 17’s Keystore generates quantum-safe signatures utilizing ML-DSA-65 inside safe {hardware}.
In the meantime, high-value belongings will depend on SLH-DSA-SHA2-128s, the hash-based signature scheme standardized below FIPS 205. Relatively than embedding it into the protocol itself, Sui will implement it by Transfer good contracts, permitting vaults to stay suitable with future post-quantum requirements with out requiring adjustments to the community’s core protocol.
In line with the announcement, utilizing separate lattice-based and hash-based cryptographic households reduces the prospect {that a} single cryptographic breakthrough would have an effect on each protected asset.
Present restoration phrases will proceed to work
As an alternative of requiring customers to generate utterly new wallets, Sui stated its deterministic key structure permits quantum-safe non-public keys to be derived from the identical restoration phrases customers already retailer at present.
Pockets backup and restoration subsequently proceed to work by present seed phrases, whereas new derivation paths generate ML-DSA-65 keys.
Present accounts will even keep away from transferring belongings to new addresses. Handle aliases, which have already been deployed on Sui, let customers change their authorization keys with post-quantum keys whereas conserving the identical pockets deal with and asset balances.
In line with the community, bigger signatures stay the primary trade-off. Put up-quantum signatures and public keys occupy considerably extra space than Ed25519 keys, rising transaction sizes throughout the community.
Verification prices, nevertheless, stay a lot nearer to present Ed25519 signatures than the bigger key sizes would possibly recommend. Sui stated transaction measurement limits and programmable transaction blocks can accommodate the extra knowledge whereas additional optimization work continues.
Rollout begins with vaults earlier than native accounts
The blockchain stated its core implementation has already been accomplished and benchmarked, though unbiased safety audits are presently underway.
Quantum-safe vaults are scheduled for mainnet deployment later this yr. Native ML-DSA-65 accounts are anticipated to achieve testnet earlier than the tip of 2026, whereas native account authentication on mainnet is focused for the primary quarter of 2027 alongside pockets, software program growth equipment and command-line interface help.
The rollout stays optionally available, following the identical deployment mannequin beforehand used for zkLogin and passkeys. Present accounts, purposes and good contracts proceed working with out modification, and builders don’t have to replace purposes instantly, based on the announcement.
Help for ML-DSA-65 will even lengthen to Sui’s multisignature authenticator, permitting accounts to require each a classical Ed25519 signature and a post-quantum ML-DSA-65 signature earlier than authorizing transactions.
Different blockchain initiatives have additionally accelerated quantum-security work
Sui’s announcement follows a collection of post-quantum safety initiatives introduced throughout the digital asset trade throughout latest months.
In Could, BNB Chain reported profitable testing of ML-DSA-44 transaction signatures and pqSTARK consensus aggregation for BSC. Whereas the blockchain concluded that post-quantum migration might work with present wallets and infrastructure, testing additionally confirmed signature sizes rising from 65 bytes to roughly 2,420 bytes, decreasing transaction throughput by about 40% to 50% due to bigger blocks and elevated community visitors.
Institutional custody suppliers have additionally began specializing in future quantum dangers somewhat than rapid assaults. BitGo launched quantum-risk administration instruments in July that measure public-key publicity, group UTXOs to keep away from leaving uncovered balances behind, and assist establishments transfer belongings into recent addresses after public keys turn into seen onchain.
One other proposal got here from AmericanFortress, which printed its Zero-Information Proof of Seed Provenance design by the Worldwide Affiliation for Cryptologic Analysis’s ePrint archive.
The proposal would permit present Bitcoin, Ethereum, and Solana pockets addresses to show possession utilizing zero-knowledge proofs with out requiring customers to rotate keys or switch funds, though deployment would nonetheless depend upon blockchain protocol upgrades and adoption by pockets suppliers. The proposal additionally cited Google’s latest quantum analysis whereas noting that present quantum computer systems stay incapable of finishing up such assaults at present.


