Cryptocurrency August 6, 2026 09:00 AM

Sui Integrates Two NIST-Approved Post-Quantum Signature Schemes to Protect Accounts

Network adds ML-DSA-65 for native accounts and hash-based SLH-DSA-SHA2-128s for high-value contract vaults, preserving user recovery phrases and addresses

By Sofia Navarro
Share
Twitter Reddit Facebook LinkedIn

Sui announced the adoption of two NIST-standardized post-quantum signature algorithms to enable accounts to migrate to quantum-resistant keys derived from existing recovery phrases. The platform will use ML-DSA-65 for native account authentication and SLH-DSA-SHA2-128s inside Move smart contracts for vaults. The migration is designed to be additive and opt-in, preserving addresses and stored assets while addressing onchain exposure to future quantum attacks. Implementation benchmarks are complete, audits and Testnet feedback remain ongoing, and Mainnet deployment targets extend into early 2027.

Sui Integrates Two NIST-Approved Post-Quantum Signature Schemes to Protect Accounts
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Sui will support two NIST-standardized post-quantum signature schemes: ML-DSA-65 for native accounts and SLH-DSA-SHA2-128s for smart contract vaults.
  • Users retain their existing recovery phrase and addresses; ML-DSA-65 private keys derive from the same 32-byte seed size via a new derivation path and address aliases enable key updates without moving assets.
  • Deployment is staged and opt-in: quantum-safe vaults targeted for Mainnet this year, native ML-DSA-65 accounts on Testnet by year-end, and Mainnet native authentication targeted for Q1 2027, pending audits and Testnet feedback.

Grand Cayman, Cayman Islands, August 6th, 2026 - Sui is moving to make account keys resilient to future quantum attacks by adding two NIST-approved post-quantum signature schemes to its protocol, enabling users to derive quantum-safe keys from the recovery phrases they already hold.

The decision reflects the distinct threat model blockchains face when compared with other systems: an account's public key is published onchain the moment it transacts, making it permanently exposed. That onchain visibility allows an attack strategy often described as "harvest-now, forge-later," where adversaries collect public keys today to attempt private-key recovery later when capable quantum hardware or algorithms are available.

Shor's algorithm undermines the elliptic-curve cryptography that secures most blockchain accounts today, the same mathematics that underpins many banking systems and internet security. The exposure is already accumulating: in March 2026, Google Quantum AI estimated that recovering a private key from a visible public key would run in minutes on a fault-tolerant quantum machine with fewer than half a million physical qubits.


Two-algorithm strategy, tailored to risk profiles

Rather than placing its future security on a single post-quantum primitive, Sui will support two schemes that are mathematically distinct and matched to different use cases.

  • ML-DSA-65 (FIPS 204) - This lattice-based scheme is being adopted as the native protocol signature for everyday account authentication. Sui is implementing the Level 3 parameter set rather than Level 1. That choice follows a July 2026 incident in which an AI model effectively halved the strength of HAWK, a post-quantum candidate, in roughly 60 hours after two years of prior human review had cleared it. The broader technology stack is converging on ML-DSA-65 at Level 3: AWS KMS has added ML-DSA signing in its hardware-backed key service, and Android 17's Keystore generates quantum-safe signatures inside secure hardware starting at ML-DSA-65, skipping the smaller 44-parameter set entirely.
  • SLH-DSA-SHA2-128s (FIPS 205) - For high-value custody and vaults, Sui will employ a hash-based signature scheme inside Move smart contracts. Hash-based signatures are a well-understood family of post-quantum primitives, and keeping them in-contract allows Sui to maintain compatibility with whatever post-quantum standards the wider industry eventually adopts, without requiring a core protocol upgrade. Given Sui's bridges to other networks, this contractual flexibility is an important design consideration.

Because the two schemes rely on different mathematics, a weakness discovered in one does not automatically undermine the other. Both implementations follow NIST's standardized post-quantum algorithms and align with the joint CISA/NSA/NIST quantum-readiness roadmap.


User continuity: same recovery phrase and address

Sui was designed with cryptographic agility in mind, which permits new signature schemes to be added without changing the network's fundamental structures. That capability determines whether a migration becomes a subtle upgrade or a full rebuild. According to the network's implementation notes, this work is a protocol-feature update rather than a modification of consensus rules or existing onchain state.

The principal challenge in cryptographic migrations is not engineering the new algorithms, but shifting an ecosystem already operating under the old primitives. Sui's approach aims to minimize friction:

  • An ML-DSA-65 private key on Sui is derived as a 32-byte seed, the same size as current wallets store, produced from the same recovery phrase using a new derivation path. Wallet backup and restore processes remain unchanged.
  • Existing accounts have an upgrade path that does not require transferring funds. Address aliases, an existing Sui feature, permit an account to update its authorization key to a post-quantum key while preserving the same address and retaining assets in place. There is no mandatory migration and no need for account holders to move holdings simply to adopt quantum-safe keys.

The honest tradeoff is data size: post-quantum public keys and signatures are substantially larger than Ed25519 pairs, increasing transaction size. Sui's design limits and programmable transaction blocks absorb much of that burden, and benchmark results indicate ML-DSA-65 verification on Sui is close enough in cost to Ed25519 that the per-signature network expense does not rise materially. Additional optimization work is underway to reduce overhead further.


Rollout plan and timeline

According to the network update, the core implementation is built and benchmarked. The immediate targets are:

  • Quantum-safe vaults implemented in Move are targeted for Mainnet deployment this year.
  • Native ML-DSA-65 accounts are planned to reach Testnet by the end of the year.
  • Full native account authentication on Mainnet is targeted for Q1 2027.

Wallet, SDK, and CLI support will accompany these phases. Independent security audits are in progress, and timelines remain conditional on audit outcomes and Testnet feedback. The network emphasizes that the stated schedule reflects current direction rather than a finalized, fully audited release.

Post-quantum accounts will be offered as an additive, opt-in capability and will follow the same rollout path used previously for zkLogin and passkeys. Existing applications and accounts will continue to function unchanged; no action is required by applications today.


Documentation and contacts

Users seeking technical detail on how specific Sui primitives transition to post-quantum cryptography are directed to the network's technical note titled "Securing Sui in the Quantum Computing Era."

About Sui

Sui is a next-generation Layer 1 blockchain focused on scalable finance and global payments. Founded by the team behind Meta's stablecoin initiative and built on an object-centric model, Sui positions assets, permissions, and user data as programmable and ownable primitives. The platform offers tools intended for high-performance payments and financial applications, including instant agentic payments. More information is available at sui.io.

Contact: [email protected]

Risks

  • Post-quantum primitives produce larger public keys and signatures, increasing transaction sizes and placing additional demand on network transaction capacity; this affects throughput and costs for payment and financial applications.
  • The rollout timeline is contingent on independent audits and Testnet feedback; delays or audit findings could change deployment dates or implementation details, impacting integrations and enterprise adoption plans.
  • Cryptographic primitives can be weakened by new analysis or automated methods, as illustrated by a July 2026 incident where an AI model halved the effective strength of a candidate signature scheme in roughly 60 hours after two years of human review, underlining ongoing algorithmic uncertainty.

More from Cryptocurrency

CT3 Ties New Storage Contract Supply to Real-Time Demand and Moves Toward Token Listing Aug 6, 2026 Bitcoin Climbs Toward $65,000 as Hormuz Deal Hope and ETF Flows Support Gains Aug 6, 2026 ChangeNOW Hires Martin Masser to Lead Strategic Partnerships for Its Crypto Super App Aug 5, 2026 CoinRabbit and ChangeNOW Release Joint Analysis on Financial Privacy for Digital Assets Aug 5, 2026 ChangeNOW and CoinRabbit Publish Joint Study Advocating Focused Regulation on Fiat Off-Ramps Aug 4, 2026