Skip to content
Tag

ML-KEM

Every article tagged ML-KEM, newest first.

15 articles

News

First FIPS 140-3 Level 3 HSM validated for ML-KEM, ML-DSA

NIST's Cryptographic Module Validation Program listed certificate 5497 on August 19, 2026: Crypto4A's QASM module, validated at FIPS 140-3 Security Level 3, natively implementing ML-KEM, ML-DSA, SLH-DSA, and LMS alongside AES, SHA, and RSA. Crypto4A and the press covering it call it the first PQC-capable hardware security module to clear Level 3. Whether or not it is the first, the certificate is real, and it answers a question that has been open since 2024: can you buy a validated HSM to actually run these algorithms in.

3 min read
Company

Learn post-quantum cryptography by generating the keys yourself

We have published four plain-language explainers of the algorithms that matter, RSA, elliptic curve, ML-KEM and ML-DSA, and two browser tools that let you generate real keys and run real operations with them. Everything runs in your tab, nothing is sent to us, and every guide ends at the command line so you can do it on your own machine. The guides are now browsable by topic as well as by task.

4 min read
Audit report

noble-post-quantum: 18 findings, none in the primitives

We reviewed the most widely used pure-JavaScript post-quantum library twice, six days apart, and found eighteen defects. Not one of them is in the maths. The first round was merged in two hours; the second found twelve more in the repaired code; then the maintainer read our patches and found two defects in them.

7 min read
Audit report

QuantaCipher audit: advertised ML-KEM, shipped Kyber

A product sold on FIPS 203 ML-KEM was shipping a pre-standard Kyber variant, at a lower security level than its own datasheet claimed. So we measured it. The cryptography underneath was sound, the runtime reported an algorithm string matching neither, and four of six findings are now closed.

4 min read
Research

Obelisk: the first Nostr client with post-quantum DMs

Nine days ago we published a proposal for giving a Nostr identity post-quantum keys, derived from its seed phrase where it has one. It is now running in a chat client anyone can open. Obelisk sends gift-wrapped direct messages carrying an ML-KEM-1024 payload, against public relays, with no relay changes and no changes required of clients that do not opt in. The four specification drafts are public. So is the bug we shipped and caught, which was in the routing rather than the cryptography.

10 min read
News

Lazarus used ML-KEM to hide a Windows zero-day

Check Point Research disclosed that the North Korea-linked Lazarus Group used ML-KEM, the NIST-standardized post-quantum key encapsulation mechanism, to protect the delivery channel for a Windows kernel zero-day (CVE-2026-68820) in its Operation Dream Job campaign against defense and aviation firms. Microsoft patched the flaw in its August 2026 Patch Tuesday release, the only bug that month it flagged as actively exploited. The notable part is not quantum computers, it is that a well-reviewed, standardized primitive is now common enough that attackers reach for it too.

4 min read
News

Post-quantum TLS 1.3 hybrid is now RFC 10024

The IETF has published RFC 10024, formally standardizing X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 as hybrid post-quantum key agreement mechanisms for TLS 1.3. The three groups replace the long-running draft-ietf-tls-ecdhe-mlkem specification that browsers and libraries were already shipping as a de facto default. Here is what the RFC locks in, and what it still leaves for a separate migration.

4 min read
Research

A post-quantum transition for Nostr identities

Every encrypted Nostr message published today is a future plaintext. We are proposing a NIP, jointly with nostr-wot, that lets an identity derive post-quantum keys from its seed phrase where it has a 24-word one - so those words still restore the identity after the transition. Accounts without one, which is most of them, generate an independent key that needs its own backup. It is implemented and running against public relays, not a design document: you can send a post-quantum encrypted message and take it apart layer by layer.

10 min read
News

How much of the web already uses post-quantum TLS

By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.

3 min read
News

How ML-KEM became the browser default, release by release

Chrome has negotiated hybrid post-quantum key agreement by default since version 131 in November 2024, migrating from a pre-standard Kyber draft to the finalized X25519MLKEM768. The other major browsers and libraries followed. Here is how the switch happened, and what the hybrid does and does not protect.

3 min read
Conformance

You migrated to post-quantum crypto. Is the implementation actually conformant?

Audits catch exploitable bugs; conformance is a different axis. Here is how to test any ML-KEM / ML-DSA / SLH-DSA implementation against FIPS 203/204/205 in a few minutes, plus a real (since-fixed) FIPS 203 deviation it surfaced in a widely-used library.

5 min read
Audit report

From the audit floor: replay-attackable post-quantum prekeys

A messaging system issued post-quantum prekeys one-shot but never retired them after use, letting an attacker replay the same ML-KEM encapsulation and quietly defeat forward secrecy.

2 min read
Research

X-Wing and the TLS group: choosing a hybrid KEM combiner

Hybrid KEMs and hybrid signatures are not the same problem. For key exchange, the industry has largely converged on X25519MLKEM768, and there are good reasons to follow rather than invent.

3 min read
Conformance

Sieve: conformance testing ML-KEM and ML-DSA against the bugs that matter

Even a correct-looking post-quantum implementation can fail in the specific bug-class patterns we see repeatedly in audits. Sieve encodes those classes as targeted, reusable test batteries.

2 min read
Audit report

From the audit floor: variable-time decapsulation and the KyberSlash class

We have audited ML-KEM implementations whose decapsulation leaked secret-dependent timing, the class of side-channel that the 2024 KyberSlash and clangover attacks turned into practical key recovery.

2 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.