Headline: Sui plots non-obligatory post-quantum accounts for 2027 mainnet — ML-DSA-65 for customers, SLH-DSA-SHA2-128 for vaults
Sui has mapped out a staged rollout of non-obligatory quantum-resistant account authentication, including two NIST-approved post-quantum signature schemes to its roadmap because the blockchain prepares for future cryptographic dangers. The plan facilities on ML-DSA-65 for on a regular basis accounts and SLH-DSA-SHA2-128 for high-value good contract vaults — giving customers the choice to harden keys towards future quantum assaults with out altering restoration phrases or transferring belongings.
Why this issues
Blockchains expose public keys onchain as soon as an account transacts. That creates a “harvest-now, forge-later” danger: attackers can archive uncovered public keys immediately and await future quantum {hardware} to crack the corresponding non-public keys. Sui cites Google Quantum AI analysis (March 2026) estimating {that a} sufficiently succesful fault-tolerant quantum pc utilizing beneath 500,000 bodily qubits may ultimately get better non-public keys in minutes — underscoring why the business is accelerating post-quantum preparedness.
Two completely different algorithms, two defenses
Quite than betting on one method, Sui will help two standardized signature households to keep away from a single-point-of-failure:
– ML-DSA-65 (NIST FIPS 204, Degree 3): a higher-security parameter set chosen for native account authentication. Sui selected Degree 3 over lower-cost parameters after a July 2026 incident the place an AI mannequin decreased the efficient safety margin of the HAWK candidate, highlighting the advantage of stronger parameters. ML-DSA-65 already seems in production-grade contexts — Chrome and Cloudflare make use of the identical safety stage for PQ encryption, AWS KMS helps ML-DSA signing, and Android 17’s Keystore makes use of ML-DSA-65 inside safe {hardware}.
– SLH-DSA-SHA2-128 (NIST FIPS 205): a hash-based scheme meant for high-value vaults. Sui will implement SLH-DSA by way of Transfer good contracts as an alternative of embedding it in the protocol, permitting vaults to evolve with future requirements with out core-protocol modifications.
Person-friendly migration: similar seeds, similar addresses
Sui’s deterministic key structure lets post-quantum non-public keys be derived from the identical restoration phrases customers already maintain. Meaning pockets backup and restore workflows stay intact. Handle aliases (already stay on Sui) let customers swap their authorization keys for post-quantum keys whereas retaining the identical pockets tackle and balances — avoiding compelled asset transfers to new addresses.
Commerce-offs and technical standing
Publish-quantum signatures and public keys are considerably bigger than Ed25519 keys, growing transaction payloads. Sui says verification prices stay a lot nearer to Ed25519 than the bigger key sizes may indicate, and community limits plus programmable transaction blocks can take in the additional information whereas additional optimizations proceed.
Sui’s core implementation has been accomplished and benchmarked; impartial safety audits are underway. The rollout is non-obligatory and can comply with the identical mannequin used for zkLogin and passkeys — present accounts and functions proceed to perform with out modifications.
Timeline
– Quantum-safe vaults: focused for mainnet later this 12 months.
– ML-DSA-65 testnet: anticipated earlier than the top of 2026.
– ML-DSA-65 native mainnet account authentication: focused Q1 2027, with pockets, SDK and CLI help.
Optional multisig: Sui will help a multisignature authenticator that may require each a classical Ed25519 signature and a post-quantum ML-DSA-65 signature to authorize transactions.
Broader business context
Sui’s announcement follows a wave of post-quantum exercise throughout crypto and infrastructure:
– Regulators are transferring quicker: Govt Order 14412 (June 2026) requires U.S. federal companies to deploy post-quantum key institution by finish of 2030 and post-quantum digital signatures by finish of 2031 for delicate programs — accelerating timelines initially mentioned by NIST.
– Different chains and suppliers are testing PQ primitives: In Could, BNB Chain examined ML-DSA-44 signatures and pqSTARK aggregation, however famous signature sizes ballooned (from 65 bytes to ~2,420 bytes) and throughput dropped ~40–50% due to bigger blocks and community site visitors.
– Custodians and tooling are pivoting: BitGo launched quantum-risk administration instruments in July to measure public-key publicity and assist establishments transfer belongings or consolidate UTXOs earlier than publicity. Educational and business proposals — corresponding to AmericanFortress’s zero-knowledge Proof of Seed Provenance — goal to let legacy addresses show possession with out speedy key rotation, although deployment relies on protocol and pockets adoption.
Sui stresses that quantum assaults usually are not sensible immediately, however that “harvest-now, forge-later” dynamics and shifting regulatory stress make early, non-obligatory adoption prudent. The staged method goals to give customers and establishments a path to quantum-safe keys with minimal friction whereas the ecosystem finalizes requirements and optimizations.













