Sui adds NIST post-quantum signatures to future-proof user accounts

Share

Sui becomes the first layer-1 blockchain to announce the integration of post-quantum signature schemes (PQC) validated by the U.S. National Institute of Standards and Technology (NIST). Scheduled between late 2026 and early 2027, this upgrade lets holders migrate their keys toward algorithms immune to Shor’s algorithm without changing addresses or losing funds, a feat made possible by the alias architecture already deployed on the network.

🔑 Key takeaways

  • Two post-quantum schemes adopted: ML-DSA-65 (CRYSTALS-Dilithium) for everyday accounts and a second algorithm for high-value Move vaults
  • Non-disruptive migration: key rotation possible from the existing recovery phrase, with no loss of funds or address change
  • Quantum-safe vaults on Mainnet as early as 2026; native ML-DSA-65 authentication on Mainnet targeted for Q1 2027
  • The SUI token moved less than 1.70% around the announcement, reflecting a measured market reception

Why blockchains must anticipate the quantum threat

Public blockchains rely on elliptic-curve cryptography (ECC), notably the Ed25519 algorithm used by Sui. The same mathematical family secures bank accounts, HTTPS connections and a large share of the global digital infrastructure. The danger comes from Shor’s algorithm, a theoretical quantum computation capable of deriving a private key from a public key in polynomial time. According to estimates published by Google Quantum AI in March 2026, a fault-tolerant quantum machine with fewer than 500,000 physical qubits would be enough to compromise an exposed key in minutes.

The threat is no longer theoretical but calendrical. The so-called « harvest now, decrypt later » scenario consists of collecting public keys and signatures today, then decrypting them retroactively once adequate quantum hardware exists. On a blockchain, this risk is amplified: a wallet’s public key is visible from its first transaction and remains permanent, creating cumulative exposure that cannot be undone after the fact. The U.S. National Security Agency (NSA) has also imposed, through its CNSA 2.0 framework, a full transition to PQC algorithms by 2033, with specific use cases mandatory as early as 2030.

The two schemes selected by Sui

Sui is adopting two distinct schemes, built on different mathematical foundations to hedge against the risk of a weakness being discovered in any single algorithm. The first, ML-DSA-65, is based on the CRYSTALS-Dilithium standard finalized by NIST under reference FIPS 204. It is designed for everyday accounts and standard transactions.

The second scheme, not detailed in public sources, will be reserved for Move vaults dedicated to high-value storage. This separation reflects a defense-in-depth logic: the algorithms most critical for asset custody receive the highest level of protection. NIST first announced the selection of PQC algorithms on July 5, 2022, followed on August 24, 2023 by three preliminary standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).

On the technical side, ML-DSA-65 retains a 32-byte private seed, identical in size to current Ed25519 seeds. The key is derived from the existing recovery phrase through a new standard derivation path, eliminating any hardware migration. Post-quantum signatures and public keys are substantially larger than their Ed25519 counterparts, increasing transaction size. However, the verification cost on Sui remains close enough to that of Ed25519 to keep the network fee per signature stable, thanks to transaction size limits and native support for programmable transaction blocks.

FeatureEd25519 (current)ML-DSA-65 (post-quantum)
Private key size32 bytes32 bytes (seed)
Signature size64 bytes~3,309 bytes
Public key size32 bytes~1,952 bytes
Quantum resistanceNoYes (lattice-based)

Frictionless migration for existing users

The most striking aspect of this upgrade is backward compatibility. Sui allows every account to rotate its authorization key toward a post-quantum variant derived from its existing recovery phrase. The address remains identical, balances are preserved and no decentralized application needs to modify its code. This continuity relies on address aliases, a feature already deployed on Sui that separates a wallet’s logical identity from the cryptographic key authorizing it.

« The difference between a migration and a rebuild is precisely what makes this update routine rather than a consensus change. »

Sui, official blog

The upgrade ships as an additive and optional capability, following the same deployment pathway previously used for zkLogin and passkeys. No forced migration is imposed, and the schedule provides several months of public testing before any mandatory mainnet activation. This cryptographic-agility philosophy distinguishes Sui from chains that will eventually have to orchestrate far more invasive hard forks.

Deployment timeline and milestones

Sui has published a three-step roadmap. Quantum-safe vaults are expected on mainnet as early as 2026, providing a first concrete use case for institutional holders and DeFi treasurers. ML-DSA-65 native accounts will first be deployed on testnet by the end of 2026, before a native account authentication on mainnet targeted for Q1 2027. SDK support, CLI integration and wallet integration will accompany each milestone.

Independent audits are underway and timelines remain contingent on testnet feedback. This iterative approach contrasts with the radical hard forks seen on other chains during past cryptographic migrations.

MilestoneNetworkTarget date
Quantum-safe vaultsMainnet2026
ML-DSA-65 accountsTestnetEnd of 2026
Native ML-DSA-65 authenticationMainnetQ1 2027
Wallet, SDK and CLI supportAllAligned with prior milestones

Market reaction: stability and wait-and-see

The crypto market’s response to the announcement has been measured. According to data relayed by Bitget and Binance, the SUI token moved only -1.70% in the hours following publication, with no identifiable abnormal volume. The official post announcing the integration gathered around 12,700 views and 8 replies on Binance Square, reflecting genuine but contained interest.

Analysts are primarily watching effective adoption of the new key-rotation function over the coming weeks, along with developer engagement to integrate PQC support. The transition remains a multi-year process and its success will depend as much on wallet user experience as on algorithmic performance. In the short term, the challenge is to turn a protocol-level advance into a perceptible UX advantage.


Conclusion: between competitive edge and an adoption bet

Sui’s initiative fits into a broader trend driven by NIST’s PQC standardization (FIPS 203, 204, 205) and the NSA’s requirement to complete the transition to post-quantum algorithms by 2033. By acting early, Sui turns a theoretical risk into a competitive advantage, provided the ecosystem follows suit. DeFi treasurers, stablecoin issuers and high-value applications will be the first test beds for this silent migration.

Two scenarios are emerging for the months ahead. A smooth rollout, with massive adoption of quantum-safe vaults by DeFi treasurers, would reinforce the chain’s institutional credibility and could serve as an industry benchmark. Conversely, too little adoption would relegate the feature to the rank of a technological showcase. The 2026-2027 window will be decisive in measuring the ecosystem’s real maturity in the face of a threat whose horizon is inexorably tightening.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles