Sui to add post-quantum signature schemes for quantum-safe accounts

Абстракт:Sui is integrating two NIST-approved post-quantum signature schemes: ML-DSA-65 for native protocol accounts at Level 3 security, and hash-based SLH-DSA-SHA2-128s inside Move smart contracts for high-value vaults. The network says users can optionally adopt quantum-safe keys derived from existing recovery phrases, with no need for new phrases or address changes. Sui cites the threat of quantum computers and "harvest-now-forge-later" attacks on exposed public keys. The two schemes rely on different mathematics to limit shared vulnerabilities. Post-quantum keys increase transaction sizes, which Sui calls an industry-wide cost. Quantum-safe vaults target mainnet this year; native ML-DSA-65 accounts target testnet by end of 2026 and mainnet authentication in Q1 2027.

Quick Take

  • Sui said it will integrate two post-quantum signature schemes approved by NIST.
  • One scheme will serve Suis native accounts while the other will cover high-value vaults.
  • Sui noted that users do not have to generate new phrases or move to another address to benefit from the quantum resistance updates.

Sui (SUI) is integrating two post-quantum signature schemes approved by the National Institute of Standards and Technology (NIST), enabling users to optionally adopt quantum-safe keys derived from existing recovery phrases.

According to its latest announcement, the blockchain network will add ML-DSA-65 as a native protocol signature scheme for everyday accounts and the hash-based SLH-DSA-SHA2-128s inside Move smart contracts for high-value vaults.

The effort comes amid the growing threat of quantum computing to the security of onchain keys.

“In most systems, an attacker needs a breach before they can start working on a key,” Sui said. “Onchain, the key is already published, exposed permanently the moment an account transacts.”

Sui argued that a sufficiently capable quantum computer running Shor's algorithm could eventually break the elliptic-curve cryptography securing most onchain accounts, and that a “harvest-now-forge-later” attack does not require quantum hardware because attackers can collect exposed public keys today and exploit them once such machines become available.

“Sui was built for cryptographic agility, which means signature schemes can be added without disturbing the fundamentals of the network,” the team said. “That property is the difference between a migration and a rebuild, and it is why the work described here is a routine protocol-feature update rather than a change to consensus or existing state.”

Two schemes

Sui highlights two schemes to address different risk profiles.

ML-DSA-65, corresponding to NIST's FIPS 204 digital signature standard, will serve native accounts at Level 3 security. The network is integrating Level 3 rather than a cheaper Level 1 option after a July incident in which an AI model halved the effective key strength of another post-quantum candidate.

“While the finding does not affect ML-DSA, the speed of it is reason to carry margin rather than take the cheapest parameters on offer,” Sui explained.

SLH-DSA-SHA2-128s, corresponding to FIPS 205, will operate inside smart contracts written in Move for high-value assets.

“For high-value assets, hash-based signatures are handled inside Move contracts,” Sui wrote. “Keeping it in-contract means Sui can stay compatible with whichever post-quantum standards the wider industry settles on, without a core protocol upgrade.”

The two schemes rest on different mathematics so that a weakness in one does not undermine the other, Sui added.

No need for new phrases

“Because Sui keys derive deterministically from a seed, users will be able to move to a quantum-safe key using the recovery phrase they already hold,” the announcement stated.

Furthermore, address aliases, already available on Sui, will let an existing account update its authorization key without transferring assets.

Meanwhile, Sui noted that because post-quantum signatures and public keys are substantially larger than Ed25519 keys, they inevitably increase transaction size.

“That is the price the whole industry is paying for quantum resistance,” Sui noted.

Sui's latest announcement said quantum-safe vaults are targeted for mainnet deployment this year, and native ML-DSA-65 accounts are planned for testnet by the end of 2026. Native account authentication on mainnet is targeted for the first quarter of 2027.

“Post-quantum accounts arrive as an additive, opt-in capability, through the same rollout path zkLogin and passkeys used,” Sui said. “Nothing existing changes, and no application needs to do anything today.”

Отказ от ответственности

Мнения в этой статье отражают только личное мнение автора и не являются советом по инвестированию для этой платформы. Эта платформа не гарантирует точность, полноту и актуальность информации о статье, а также не несет ответственности за любые убытки, вызванные использованием или надежностью информации о статье.
Предыдущая статья

В Ondo Finance разгорается борьба за власть после смерти основателя

Следущая статья

Сенат не будет голосовать по закону о криптовалютной ясности до летних каникул