EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Sui adopts post-quantum signature scheme and moves towards quantum security-ready (August 6)

2026-08-07 00:12:44
Bookmark

Cayman Islands, Grand Cayman, August 6, 2026

Sui is introducing two NIS-approved post-quantum signature schemes that allow accounts to be migrated to quantum security keys generated based on the user's existing recovery phrases.

Sui, a platform that allows funds to flow freely like messages, today announced that it will adopt two post-quantum signature schemes to move towards quantum-ready.

For blockchain, quantum timelines are different because the public key on the chain is essentially different from the public key elsewhere. In most systems, attackers need to break through defenses before they can crack the key. On the chain, once the key is released, it is permanently exposed-once the account is traded, it is disclosed immediately.

Shor algorithm can crack the elliptic curve cryptography that most current chain accounts rely on, and this mathematical principle also supports most of the banking system and the Internet. The "harvest first, crack later" collection method does not require quantum hardware, it only requires a visible key and patience. This exposure risk is accumulating. In March 2026, the Google Quantum Artificial Intelligence team estimated that on fault-tolerant machines, using less than 500,000 physical qubits, an attack to recover a private key from an exposed public key would take only a few minutes to complete.

Because of this, Sui chose to use two signature schemes that work for different risk types rather than betting on a single algorithm.

ML-DSA-65 (FIPS 204) for native accounts

For daily transactions, ML-DSA-65 will become a native protocol signature scheme. Sui chose Level 3 rather than the lower-cost Level 1. This decision stems from an incident in July 2026 when an AI model reduced the effective key strength of a post-quantum signature candidate solution HAWK in about 60 hours, after the solution had passed expert manual review for two years. Other parts of the Internet stack are converging in the same direction: AWS KMS now provides ML-DSA signatures in its hardware-backed key service;Android 17's keybank, starting with ML-DSA-65, generates quantum security signatures within the device's secure hardware, skipping the 44-parameter set completely.

SLH-DSA-SHA2 - 128s (FIPS 205) for smart contract vaults

For high-value assets, hash-based signatures are processed within the Move contract, rather than the protocol core. Hash-based security is easier to understand in both families, and keeping it inside the contract means Sui can remain compatible with any post-quantum standard eventually adopted by the industry without requiring core protocol upgrades. This adaptability is crucial given Sui's bridge to other networks.

The two options are based on different mathematical principles, so when a weakness is discovered in one option, it will not affect the other. Both follow NIST's standardized post-quantum algorithm and the jointly released CISA/NSA/NIST quantum readiness roadmap.

Users keep their recovery phrases and addresses

Sui is designed with cryptographic flexibility, which means signature schemes can be added without interfering with the network foundation. This feature determines whether it is migrated or rebuilt, and as such, the work described here is a regular protocol feature update rather than a change to a consensus or existing state.

The most difficult part of any cryptographic migration is not the new algorithm, but the fact that everyone is already using the old algorithm.

On Sui, the ML-DSA-65 private key is a 32-byte seed, the same size as the current wallet storage, derived from the same recovery phrase through a new standard derivation path. The wallet backup and recovery method is exactly the same as it is now.

Existing accounts have a path without transferring funds. The address alias feature already deployed on Sui allows accounts to update their authorization key to a post-quantum key while keeping their address and assets unchanged. There is no need to force relocation, and there is no need to expensively transfer all assets held in the account.

The real cost lies in volume. The post-quantum signature and public key are much larger than the Ed25519 pair, which increases the transaction size. This is the price the entire industry pays for quantum resistance. The verification part could have caused problems, but it didn't: ML-DSA-65 on Sui has similar verification speeds to Ed25519, so the network cost per signature has not increased. Sui's transaction size limits and support for programmable transaction blocks absorb the rest, and further optimization work is underway.

Post-quantum deployment timeline

The core implementation has been built and benchmarked. Quantum Security Vault is expected to be launched on the main network this year; native ML-DSA-65 accounts will be logged on to the test network before the end of the year, and native account authentication is planned to be launched on the main network in the first quarter of 2027. Wallet, SDK and CLI support will be launched simultaneously. An independent audit is underway and the timeline remains open until feedback from the Review and Test Network is complete. This reflects the current direction and is not a final, fully audited release.

Post-quantum accounts are launched as an optional additional feature via the same deployment path that zkLogin and passkey were used. Nothing that exists will change, and the application does not need to take any action at the moment.

For background information on how each original component of Sui transitioned to backward quantum cryptography, users can consult relevant documentation.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP