FINMA Guidance 05/2026 Recommends a Post-Quantum Roadmap by Mid-2027, and Only 8 Percent of the 60 Swiss Institutions It Surveyed Had One
What the guidance is
FINMA published Guidance 05/2026 on 9 July 2026. It reports a survey of 60 authorised Swiss banks, insurance companies, managers of collective assets and financial market infrastructures, run between November 2025 and January 2026, and sets out five post-quantum cryptography recommendations. The headline recommendation is that supervised institutions draw up a migration roadmap by mid-2027 at the latest, on the basis of a strategy adopted by the board of directors.
What this read covers
A section-by-section read of the eight-page instrument: how the reported 72 percent decomposes, what the 8 percent with a roadmap actually forecast, the scope of the section 3.2 cryptographic inventory, and the crypto-agility clause section 3.5 recommends for new outsourcing arrangements in the software and data sectors. It also notes the sentence that excludes quantum key distribution from the recommendations altogether, which is worth having in writing when a proposal arrives.
Why the survey is more interesting than the date
The percentages are the part that repays attention. Around two-thirds of those surveyed expect quantum cyber risk to become directly relevant for them within seven years, while almost two-thirds do not expect to run quantum computing applications themselves for another eight years or more. Those are two aggregate distributions rather than a respondent-level comparison, but the order they describe is the whole document: the gap between what the sector says it understands and what it has done about it.
A TPM Counts as PQC-Ready Only If It Meets TCG's PTP 1.07: What the 23 March 2026 Profile Requires, and What the Chips Announced on 3 September Claim
One document now decides what “quantum-safe TPM” means
On 24 August 2026 the Trusted Computing Group published guidance telling purchasers how to test a vendor's claim that a Trusted Platform Module is post-quantum ready, and it does so by pointing at a single specification: the PC Client Platform TPM Profile version 1.07, published 23 March 2026. The profile states that a conformant TPM shall support either ML-KEM-768 or ML-KEM-1024 and either ML-DSA-65 or ML-DSA-87, makes SHA-512 mandatory, and rules out SHA-1 entirely.
Memory is the demanding part
Post-quantum objects are large — an ML-DSA-87 signature runs to 4,627 bytes — so the profile sets two normative floors: at least 68 NV indexes totalling 11,026 bytes, and a minimum of 6,896 bytes for persistent objects. The non-normative example behind the persistent-object figure reaches it by storing key seeds instead of expanded keys. Pre-provisioning endorsement key certificates in the factory stays optional, and where a vendor does pre-provision them, the profile requires a classical credential paired with the post-quantum one.
What the 3 September announcements actually claimed
SEALSQ and wolfSSL described the QVault TPM as on track to be the first shipping TPM implementing the post-quantum algorithms of the TPM 2.0 Library Specification v1.85, with testing across ML-DSA and ML-KEM at all key strengths; the release cites the library specification rather than the platform profile, and gives no shipping date. WiSECURE and ITRI showed a FIPS 203/204/205 chip at SEMICON Taiwan the same day, which the company describes as commercial grade — a cryptographic application chip, outside the scope of a PC client TPM profile. This piece reads the profile's own text against both announcements, and sets out what the two TCG designations, PQC-ready and PQC-upgradable, mean for a hardware budget.
Five Post-Quantum Dates Arrive Before the Federal Plans Are Due
Six dates between 11 September and 22 October 2026, and what each one changes
Executive Order 14412 sets 2030 and 2031 as the federal post-quantum destinations, and OMB Memorandum M-26-15 makes every agency migration plan due on 22 October 2026. Five other dates arrive first, and they move the estate rather than the plan. On 11 September the Cyber Resilience Act starts a 24-hour early warning duty for actively exploited vulnerabilities. On 15 September JDK 27 is scheduled to deliver JEP 527 and place X25519MLKEM768 first in the default TLS 1.3 preference list, so services left on that default will offer hybrid post-quantum key exchange from their next deployment. On 21 September the Cryptographic Module Validation Program moves every FIPS 140-2 certificate to the Historical List, which changes the standing of certificate numbers already written into proposals and contract schedules. On 27 September a Department of War request for information closes, specifying ML-KEM-1024 key transport for software-only encryption. On 19 October the Windows Production PCA 2011 signing certificate expires.
The parameter-set seam, and the artifact to ask for on each date
Java's default and Cisco's supported IKEv2 hybrid land on ML-KEM-768; the defense specification asks for ML-KEM-1024. Both sit inside FIPS 203, and they do not meet by accident. This read walks the six dates in order and states, for each, the single artifact a buyer or a supplier can request and check: a reporting playbook with a named CSIRT endpoint, a runtime inventory with TLS-inspection test results, a certificate register with successor or legacy status for every 140-2 number, a written parameter-set position, Microsoft's five developer actions answered for every signed component, and a checkable package for each federal customer whose plan is due.
Post-Quantum Buying Moves From Availability to Proof: What Counted as Evidence in the First Week of September 2026
A certificate that changes status on 21 September 2026 without the module changing
The NIST Cryptographic Module Validation Program has said that on 21 September 2026 it will move every FIPS 140-2 validated module to the Historical List, where federal agencies should not include the module in new systems and may procure it for legacy systems only. Nothing inside the hardware changes on 22 September. What changes is the status of the certificate a proposal cites, which turns "FIPS-validated" into three questions: which standard, which certificate number, and what status on the day the proposal is read.
A readiness level in the field, a product-attributed pipeline, and three vendor dates
Three more documents sit alongside it. QuSecure said on 2 September 2026 that QuProtect R3 reached Technical Readiness Level 7 at the U.S. Army's Project Convergence Capstone 6 at Fort Irwin, providing quantum-resistant communications, cryptographic agility and cryptographic discovery and inventory for tactical mission systems; the rating is the company's own account of the exercise. SEALSQ's preliminary first-half results of 6 July 2026 put unaudited company-wide revenue near $11 million and attributed more than $60 million of a $225 million management-estimated pipeline to the QS7001 secure element and the QVault TPM, and on 3 September the company announced wolfTPM support for that part. JDK 27 reaches general availability on 15 September 2026 with hybrid post-quantum key exchange first in the default TLS preference list, Microsoft's Windows Production PCA 2011 expires on 19 October 2026, and Cisco IOS XE 26.x carries an ML-KEM-768 hybrid for IKEv2.
Why the four together describe a procurement test
The four documents carry dates spread across July, August and September, and what changed in the first week of September is that a buyer could request all of them at once. Each names an organisation, a date and a checkable particular. Read against Executive Order 14412, OMB Memorandum M-26-15 and the Department of War request for information closing 27 September 2026, they show what a buyer of post-quantum cryptography can now ask for and expect to receive.
Coldcard Generated Bitcoin Seeds From a Software PRNG for Five Years: Block's 30 July 2026 Report, and Why Migration Deadlines Do Not Check Entropy
A five-year-old build flag, not a broken cipher
On 30 July 2026 Block's Bitcoin engineering and security team published a root-cause analysis of thefts from Coinkite's Coldcard hardware wallets. A single commit on 1 March 2021 left the macro MICROPY_HW_ENABLE_RNG defined with the value zero, and the supporting library tested whether that macro was defined rather than whether it was enabled. Seed generation silently fell through to MicroPython's Yasmarang software generator, initialised from a chip serial number and two timer registers. No error appeared on any screen for five years.
What the counts say, and where they disagree
Galaxy Research mapped a sweep of 1,082.65 BTC out of 1,196 addresses in forty-one minutes on 30 July. TRM Labs put the running total at roughly 1,816 BTC and about USD 116 million across more than 5,200 addresses by 5 August. Coinkite's own advisory of 1 August describes about 72 bits of entropy against the 128 bits a BIP-39 seed assumes. Block's figures are harsher: deterministic output on the Mk2 and Mk3, and roughly 2^31 average enumeration on the Mk4, Mk5 and Q — both figures conditional on an attacker knowing the device identifier, the timer state and the history of calls to the generator, and neither backed by an end-to-end benchmark. Attribution of individual thefts remains open.
The gap in what a federal migration plan must contain
OMB memorandum M-26-15 of 24 June 2026 fixes what a federal agency's post-quantum cryptography migration plan must contain, and Appendix B lists nine items. Entropy is not among them, and the words "entropy" and "SP 800-90B" appear nowhere in the memorandum. Entropy quality is governed separately, through NIST SP 800-90B and the Entropy Source Validation stream inside the Cryptographic Module Validation Program. This piece reconstructs the Coldcard failure end to end and shows why an algorithm inventory of the affected devices could be entirely accurate and still miss it.
A Lattice Attack Was Claimed on 3 August 2026 and Answered on 15 August: What ePrint 2026/1591 and 2026/1693 Say About ML-KEM
What Simon submitted on 3 August 2026, and what the abstract claimed
Cryptology ePrint Archive 2026/1591, “A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem,” by Daniel R. Simon of Amazon Web Services, was received on 3 August 2026 and filed under attacks and cryptanalysis. Building on Regev's reduction techniques, it claimed to handle modular subset sum without a subset-sum oracle and to yield polynomial-time quantum algorithms for lattice problems, including a polynomial-factor approximation to the shortest vector and learning with errors at noise parameter α = √n polylog(n). The abstract never mentions ML-KEM, FIPS 203, or any deployed parameter set. The paper was revised four times, most recently on 17 August 2026.
What Gupte, Ragavan and Zhandry posted on 15 August 2026
ePrint 2026/1693, “The ePrint:2026/1591 Quantum Algorithm Does Not Solve DCP,” by Aparna Gupte of MIT, Seyoon Ragavan of Google Quantum AI and MIT, and Mark Zhandry of Google Quantum AI and Stanford, was received on 15 August 2026 and last revised on 1 September. The formal finding is that Simon's algorithm does not extract the least-significant bit of the dihedral coset secret with non-negligible guessing advantage, and so cannot solve the problem it targets. The authors state that their no-go covers a much broader class of algorithms than Simon's — those that carry only a limited digest of the classical Fourier information into the uncomputation stage — and they released Lean 4 code so the argument can be machine-checked.
Why the twelve days matter more than the result
Executive Order 14412's key-establishment deadline of 31 December 2030, the Java runtime shipping hybrid key exchange on 15 September 2026, and the enterprise plans behind them all lean on lattice mathematics for key establishment. When the strongest public challenge to that mathematics this year appeared, the quality control that answered it came from three academics posting a formal no-go within twelve days, and from the author leaving his own paper up with the challenge attached. That is the working crypto-agility argument, made by demonstration.
BSI's 2030-2035 End Dates and FINMA's Mid-2027 Roadmap: What They Mean for Data Already in the Archive
What BSI dated on 11 February 2026 and what FINMA recommended on 9 July 2026
Two European authorities put years on the post-quantum transition in 2026, and neither is American. One is a cybersecurity agency and one is a financial supervisor. Germany's Federal Office for Information Security, in the annual update of its cryptographic guideline TR-02102, set the first expiry for classical asymmetric procedures: end of 2031 for key agreement and encryption, end of 2030 where protection needs are high, and end of 2035 for classical signature procedures. Switzerland's financial supervisor followed on 9 July 2026 with Guidance 05/2026, drawn from a survey of 60 authorised banks, insurers, managers of collective assets and financial market infrastructures run between November 2025 and January 2026. Around two thirds of them expect quantum-related cyber risk to reach their own institution within seven years. Seventy-two per cent had planned or implemented nothing.
The inventory FINMA recommends covers stored data, and that is the harder half
FINMA recommends a post-quantum cryptography roadmap drawn up by mid-2027 at the latest, resting on a strategy adopted by the board of directors and an inventory of every business process, explicitly covering encryption in transmission as well as stored data. The transmission half is moving on its own wherever both endpoints have shipped hybrid key agreement. The stored half is not. A record 176.5 exabytes of compressed LTO tape capacity shipped in 2024, a fourth consecutive year of growth, into archives whose key hierarchies and signature chains were designed when RSA was considered safe for a working lifetime.
Why the constraint is key management rather than algorithm choice
Standardised algorithms exist. What many archives lack is the ability to move the keys that protect decades of stored records, through key-management servers, backup appliances and self-encrypting drives, without rewriting the data itself — and whether that shortcut is available at all depends on how a given site built its key hierarchy and which payload cipher it chose. BSI's 2030 and 2031 dates fall on the asymmetric side of that question; 2035 falls on the signature chains that make an archive provable. It is a records-retention question for medical, pension and insurance files as much as a cryptographic one.
Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration
Who recommended it, where, and when
On 6 November 2025, Mauritz Kop published “A Bletchley Park for the Quantum Age” in War on the Rocks. The essay named the General Services Administration and asked that federal purchases be conditioned on validated cryptographic modules, and it asked separately that fielded systems be tested rather than vendor promises accepted. Nine months later, on 24 August 2026, GSA published a post titled “GSA Leads the Transition to Quantum-Resistant Technology”. The recommendation came first, it named the right agency, and both of the things it asked for — buy only what is validated, test what is fielded — are now federal work.
What GSA actually operates
Two things, and both are procurement rather than protocol. GSA is modernizing the Federal Identity, Credential, and Access Management architecture for quantum-resistant algorithms, with crypto agility as the stated design goal, through an interagency working group that OMB Memorandum M-26-15 ordered it to stand up and that first met on 12 August 2026. And GSA’s FIPS 201 Evaluation Program, executed through its Physical Access Control System lab, is starting to incorporate quantum-resistant algorithms into the testing that decides which badge readers and door controllers reach the Approved Products List. No quantum-resistant access product has been approved yet.
Why the doors are the hard part
Algorithm migration inside a browser handshake can often be delivered through software updates. Credentials and readers run on hardware-refresh cycles measured in a decade, which is why M-26-15 puts access control built on public-key infrastructure in its priority tier. Put quantum-resistant algorithms inside the FIPS 201 test suite and covered identity and access purchases start inheriting the requirement from the buying rule rather than from a new mandate.
Network Monitoring Learned the Cryptography That Is Being Replaced
A change underneath the measurement
Encrypted-traffic classifiers read the outside of a connection — packet sizes, directions, timings — and infer what is inside without decrypting it. A preprint posted to arXiv on 24 August 2026 by Bingzhen Li and eight co-authors asks what happens to those models when TLS moves to hybrid post-quantum key establishment. Using the deployed group X25519MLKEM768, which pairs the classical X25519 exchange with ML-KEM-768 from FIPS 203, the authors show that the larger post-quantum handshake reshapes observable traffic while leaving the application above it and its label untouched. They name the effect PQC-induced protocol drift, and they put numbers on it.
Relocated, not removed
Across five representative classifiers and three experimental settings, the result holds: the signal survives the migration but moves, and models that score well under matched conditions lose reliability once the cryptographic domain shifts beneath them. The mixed period — part traditional traffic, part hybrid, in proportions that change every month — lasts as long as both domains share the same wire, and it is precisely the condition the field's benchmarks are not built to measure. The measured scope is narrow and is stated as such: closed-world website fingerprinting, one deployed hybrid group, one purpose-built benchmark.
Why the loss has no owner
In the same week, the US Treasury launched its Quantum-Readiness Task Force under Executive Order 14412, with third-party and vendor readiness as one of three workstreams. Migration is becoming procurement. Procurement asks whether a supplier supports the new algorithm, and has no natural place to record that switching it on ages a detection baseline owned by a different team. This piece reads the paper closely and follows that seam into the operational and civic consequences, including a temporary privacy dividend that nobody planned and nobody owns.
Windows Dated Post-Quantum Signing and Left the Algorithm Open
A date, and no algorithm
Microsoft's guidance of 20 August 2026 sets three steps for the chain of trust that decides which software a Windows machine will accept. The Microsoft Windows Production PCA 2011 expires on 19 October 2026, with a replacement authority already rolling out. Signing moves to RSA-3072 and SHA-384 by the end of 2026. And in 2027, Windows signing transitions to post-quantum signing, which Microsoft says might use hybrid signature constructions. The guidance commits to a date and a direction while naming no post-quantum algorithm at all.
The bench that is supposed to answer
NIST's additional-signatures on-ramp exists chiefly to diversify beyond structured-lattice signatures, and secondarily to find short signatures and fast verification for applications that need them. Nine candidates advanced to its third round on 14 May 2026; on 29 July the HAWK team withdrew, and eight remain. Cloudflare's July analysis walked the same bench and concluded that none of the compact candidates is ready to carry the first migration, committing instead to ML-DSA on a 2029 target.
Deployment pressure, not a verdict
A vendor calendar fixed to 2027 without an algorithm. A programme built to diversify, one candidate lighter. An infrastructure provider settling on the general-purpose standard because it is finished. And a cross-regional pilot announced on 24 August that will put financial supervisors inside a live ML-DSA-65 test as observers. Microsoft selects nothing; only the last two actually pick a scheme. What they share is narrower than a verdict and still worth acting on: near-term deployment pressure is settling on ML-DSA while the alternatives mature, in a layer of the stack almost nobody outside cryptography can see.
Why the New Attack Estimate Did Not Move a Single Deadline
A twentyfold-lower estimate, now through review
In a Perspective accepted by PRX Quantum on 6 July 2026, Ryan Babbush and colleagues — a Google-led multi-institution team including Craig Gidney, Adam Zalcman, Tanuj Khattar, Justin Drake and Dan Boneh — put the quantum cost of breaking elliptic-curve cryptography at about 1,200 logical qubits and 90 million Toffoli gates in one configuration, or 1,450 logical qubits and 70 million in another, mapping to fewer than 500,000 physical qubits: roughly twenty times below the prior physical-qubit estimate for the same task. Run straight through, those circuits take 23 or 18 minutes. Only a primed attack, with the precomputation already done, falls to about 12 or 9 minutes, which is the variant that draws level with the window in which a transaction sits on a public network with its key exposed.
The deadlines that stayed where they were
None of the migration dates examined here moved. Executive Order 14412 still sets 31 December 2030 for post-quantum key establishment across federal high-value and high-impact systems and 31 December 2031 for signatures; the European roadmap still runs to 2030 for critical infrastructure; the ICAO passport standard is still expected around the middle of 2027. The US order was signed after the preprint of 30 March 2026; the European roadmap and the ICAO target both predate it. A search of official communications on 22 August 2026 found no US, EU or ICAO statement revising any of them in light of the work.
Why that is mostly defensible
Those deadlines were never derived from a resource estimate. They are procurement calendars, keyed to certification and product queues that no executive order can shorten, and a co-author of the paper has cautioned that a rushed transition is the likelier catastrophe. The reasoning holds wherever a secret can be rotated. Where something has already been captured and cannot be reissued — a biometric, an archive, a public key long since published — harvest now, decrypt later means the useful deadline for that particular record has already gone, whatever date the instrument carries.
Copy-Based Resilience Is the One Habit This Signature Scheme Cannot Allow
One key, one place, one number
Stateful hash-based signatures are the one post-quantum family that behaves like a book of numbered receipts: every leaf may be used exactly once, and the count of what has already been spent is part of the secret. NIST's 2020 recommendation for those schemes holds the line with two plain conformance clauses. The cryptographic module may not export private keying material, even in encrypted form, and it may not use a one-time key more than once. Sign twice at the same index and, in NIST's words, it becomes computationally feasible for an attacker holding both signatures to forge further ones.
Where it meets the recovery plan
Ordinary resilience engineering runs on the opposite reflex. Many conventional copy-based designs duplicate the signing environment or roll it back in time, and where they do, both faults land in the same place: an index issued twice. Safer state-aware mechanisms exist and have been catalogued at the IETF; they are simply not what most recovery machinery does by default. The problem is well enough known to have its own engineering literature at the IETF, and it reached the banking press this week through a Swiss custody bank explaining why Ethereum's post-quantum roadmap is already an operational question. Switzerland's supervisor had reached an adjacent finding in July, reporting that in most cases among the sixty institutions it surveyed there was "a lack of a clear roadmap and sufficiently forward-looking planning" for the migration.
What the standard proposed instead
The interesting part sits in the recommendation itself. NIST anticipated module failure in 2020, refused the copy, and gave over a whole section to two architectures in its place — several independent keys across several modules, or one multi-tree key whose subtrees are generated on separate hardware. That is redundancy without duplication, and it has to be chosen at the key-generation ceremony, years before anyone reaches the migration deadline written in the plan.
The Post-Quantum Handshake That Delivered a Windows Zero-Day
What the report describes
On August 11, 2026, Check Point Research published an account of an Operation Dream Job intrusion chain aimed at defense and aerospace staff in France, Germany, India and Brazil. The lure was a recruiter approach. The payload was a use-after-free race in the Windows socket driver AFD.sys, tracked as CVE-2026-68820, giving local escalation to SYSTEM. Microsoft received the report on July 28, assigned the identifier on August 5, and patched on August 11. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, with a federal remediation date of August 25.
The detail that matters
Before the exploit moved, the privilege-escalation loader carried out post-quantum key establishment with its server: it took server public keys, generated fresh key material with Kyber/ML-KEM, returned the encapsulated result, and only then requested the zero-day. The report places this inside that loader's exchange, not across the campaign's wider command infrastructure. A second cipher layer sat on top of the existing AES transport, using a randomly generated 16-byte session key prepended to each packet. The rootkit that followed blinded 94 event-tracing providers and tampered with Smart App Control.
Why it reads as an organizational story
As a general matter, a classical ephemeral exchange offers comparable protection against later decryption, so a post-quantum primitive is not by itself a new offensive capability. What the case shows is speed. NIST finalized ML-KEM in August 2024; it appeared here in an ordinary tooling update, integrated by a team with no inventory to survey and no supplier to wait for. Enterprises measure the same transition in years because their constraint was never the mathematics. That asymmetry, not the handshake, is what inspection-based defense now has to plan around.
The Vulnerability Database Is Being Rebuilt Without a Word About Cryptography
A consultation with one word missing
On August 12, 2026, NIST opened a public consultation on rebuilding the National Vulnerability Database for an era of AI-assisted attack and machine-readable security data. The notice runs to seven groups of questions, from automation of the vulnerability lifecycle through to the standards that govern vulnerability data and a five-year vision for the database itself. Comments close on October 13, 2026. The word cryptography does not appear anywhere in it.
Why the omission matters
Two years after the first post-quantum standards were finalized, European rules now require entities in scope to hold policies on the use of cryptography, and the Dutch implementing statute takes effect three days after this notice published. No instrument orders anyone to keep a cryptographic inventory — but a policy that cannot be checked against deployed systems is not one an auditor can test. The database ingests vulnerability records within about an hour of publication, so speed was never the binding constraint. The constraint is structural: a register answers only the questions its schema anticipated, and a flaw record was never built to describe a key exchange or a signing algorithm.
Who this decides for
Cryptographic discovery is already procurable by anyone with a budget, and no central record could replace it: what a given operator has configured is local knowledge that has to be found locally. What a public record could supply is the reference layer underneath — what a product version implements — so that local discovery resolves against something instead of being re-derived by everyone independently. Whether that layer acquires a cryptographic dimension will shape the real pace of migration among smaller operators more than any further deadline, and it is being settled on an open docket rather than in an instrument.
What Would Have to Hold for the New DCP Result to Reach ML-KEM
A preliminary paper reaches the mathematics under lattice-based post-quantum cryptography
The Cryptology ePrint Archive received Paper 2026/1591 on August 3, 2026 and posted it three days later. In it, Daniel R. Simon of the Amazon Web Services Cryptography Group presents a polynomial-time quantum algorithm for the Dihedral Coset Problem, which has resisted a polynomial-time solution for more than two decades. Combined with Oded Regev's reduction of lattice problems to that problem, the abstract claims polynomial-time quantum algorithms for two distinct targets: the Shortest Vector Problem at a square-root-of-n polylogarithmic approximation factor, and Learning With Errors instances in a parameter regime the abstract states as alpha equal to square-root-of-n polylog(n).
What the paper does not claim
It analyzes no standardized scheme, offers no key-recovery attack, and gives no qubit, gate or error-correction estimate. The claim is complexity-theoretic and unreviewed; the author records discussions in progress with Daniele Micciancio, Vinod Vaikuntanathan and Thomas Vidick. Nothing standardized broke in August 2026, and no honest reading of the abstract says otherwise.
Why it still lands on the migration desk
Four conditions stand between this abstract and ML-KEM, and none has been met. But certification calendars were set on the cryptographic judgment of 2024 and do not pause for a preprint. What lets an organization respond to a result like this is crypto-agility resting on a current cryptographic inventory: knowing which systems use which algorithms, and how long a substitution actually takes. That capability is built before the verdict arrives, not after.
The Post-Quantum Web Arrived as a Platform Setting
Nearly half, one default
A new longitudinal study tested more than two billion TLS handshakes across one million domains from 11 global vantage points. By March 2026, 49.22 percent of its stable panel negotiated a hybrid post-quantum key exchange by default. Every one of those default negotiations selected the same construction, X25519MLKEM768. The web appears to be moving quickly, but the route is narrower than the policy calendars suggest.
The platforms moved first
The paper attributes 93.92 percent of observed post-quantum TLS deployment to configurations likely managed by infrastructure providers. Cloudflare and Fastly alone account for nearly 70 percent. Owner-managed services, including many government domains, remain mostly classical. This changes how migration progress should be read: a high aggregate percentage may describe one upstream platform decision repeated across thousands of customers, while slower institutions still face their own software, procurement and legacy-system work.
A safer handshake can keep old baggage
The hybrid exchange added a predictable number of bytes but no meaningful median latency in the measured public-web setting. At the same time, provider-managed post-quantum domains often retained older protocol versions and deprecated cipher support. The result connects engineering, policy and market power. Cryptographic infrastructure concentration can accelerate protection at remarkable speed, yet it can also obscure who made the change, which services inherited it and how much of the harder migration remains unfinished.
HAWK Left the Standards Track Before NIST Spoke
A candidate disappeared between meetings
HAWK began the week as a live candidate in the third round of NIST’s Additional Digital Signatures process. It ended the week withdrawn by its own developers after an AI-assisted cryptanalysis project identified a structural weakness in the scheme. NIST later acknowledged the exit and updated its Round 3 record, without announcing a rule for assessing model-generated mathematical work or issuing an independent technical judgment on the finding. The outcome arrived through researchers, expert checking and voluntary withdrawal.
The process worked without a written rule
The disclosed technique concerns HAWK and its particular lattice structure. It does not establish a transfer to NIST’s finalized FIPS 203, 204 and 205 standards. The episode still changes standards governance. It shows machine-assisted cryptanalysis entering a live selection process, where a research result can alter vendor roadmaps and comparative engineering choices before an agency publishes its own reasoning.
Crypto-agility has a nearer deadline
HAWK also gives crypto-agility a practical meaning. An algorithm may leave a standards track during the life of a contract because analysis advances faster than certification, procurement and product refresh. Institutions need separate technical, procedural and commercial records: what was affected, how the finding was checked, and which dependencies must change. A compact public disclosure receipt would make the next case easier to govern. The central control is public reason-giving: a precise claim, reproducible artifacts, a response from the scheme’s developers and a dated status note once disclosure risks permit.
Post-Quantum Security Has to Survive the Radio
The handshake has a physical footprint
A remote sensor can carry strong cryptography and still fail before useful data moves. A new University of Colorado Boulder preprint models that problem on narrow radio links, where post-quantum certificates, signatures and keys arrive as long packet trains. The authors estimate bandwidth, memory, compute time and battery draw for certificate-based authentication on an NB-IoT connection. Under their stated assumptions, a security Category 1 ML-DSA-44 and ML-KEM-512 exchange produces 334 real-world packets and consumes 10,688 millijoules for transmission and reception. The proposed shared-secret route with ephemeral ML-KEM reduces those figures to 112 packets and 3,584 millijoules.
Loss changes the result
The satellite case makes packet count more than an efficiency metric. With 10 percent independent packet loss, the paper models a 0.8 percent single-attempt success rate for a 46-packet certificate-based exchange and 23 percent for a 14-packet shared-secret exchange. Those are first-order calculations, not field measurements, and the authors spell out assumptions about packet size, throughput, retransmission and device hardware. Even so, the comparison exposes a practical post-quantum authentication problem: a secure algorithm may still miss the contact window in which the device can use it.
Key management moves to the center
The proposed design uses an existing 5G or 6G shared-secret ecosystem, a Kerberos-style key distribution center and a DTLS pre-shared-key handshake with ephemeral ML-KEM. It preserves a post-quantum key-establishment step while avoiding digital-signature certificates at the endpoint. That can ease the radio and battery load, while placing more weight on enrollment, secret storage, lifecycle controls and the trusted key-distribution service. Constrained-network PQC therefore reaches beyond algorithm selection. It changes who holds trust, which infrastructure must remain available and whether a medical sensor, asset tracker or satellite terminal can authenticate reliably at all.
A Public Quantum Claim Built on a Private Attack Circuit
A claim with a missing circuit
Google Quantum AI researchers published lower resource estimates for using Shor’s algorithm against ECDLP-256, a cryptographic problem that protects many cryptocurrency systems. Their March 30 preprint describes two compiled circuits: one below 1,200 logical qubits and 90 million Toffoli gates, another below 1,450 logical qubits and 70 million Toffoli gates. Under stated assumptions, the authors estimate execution in minutes on fewer than 500,000 physical superconducting qubits. They did not publish the underlying attack circuits. That makes this a distinctive case of quantum vulnerability disclosure: the public receives a serious technical claim and a migration warning while a potentially useful attack roadmap stays private.
Zero knowledge changes the bargain
The proof makes a narrower statement than the headline resource estimate. It attests that the authors possess size-bounded reversible circuits that correctly compute secp256k1 point addition across 9,024 pseudorandom inputs derived from each circuit’s hash. Additional reasoning connects that subroutine to the overall Shor resource estimate. Google’s March 31 account says the team engaged with the U.S. government before publication. Zero-knowledge verification can expose a bounded proposition to checking while preserving sensitive implementation detail. It does not validate every hardware assumption, predict the arrival of a cryptographically relevant machine or supply a universal “Q-Day.”
The revision carries its own warning
The April 15 revision acknowledges that Keegan Ryan of Trail of Bits found a software flaw that allowed an attack on the soundness of the earlier proof. Version 2 corrects the proof layer and credits the finding. That repair belongs at the center of the story: cryptographic attestation can narrow a disclosure problem, while its software and statement still require hostile review. The case links cryptography, scientific reproducibility, market confidence and public oversight without treating the current proof as wider than it is.
A Green Check Mark Can Hide a Classical Trust Decision
Two credentials can yield one old decision
A new preprint tests whether hybrid X.509 certificates produce genuinely hybrid authentication. Taesung Kim, Boheung Chung, Keonwoo Kim and Yousung Kang examined eight path-validation stacks, nine validation modes and six certificate schemes. Under a policy requiring hybrid authentication, nearly every tested stack that could parse a separable hybrid certificate accepted through the classical path without making the post-quantum credential decisive. A system can therefore show a successful result while the newer credential never carried the trust decision.
Revocation exposes the practical gap
The paper's lifecycle experiment makes the issue concrete. When a bound post-quantum credential was revoked while the classical certificate remained valid, default validation could still accept because the newer credential sat outside the decision's scope. This matters for certificate authorities, trust stores, hardware security modules and applications whose owners may renew or revoke credentials on different schedules. It also matters for autonomous agents that consume authentication responses at machine speed and preserve whatever meaning the verifier supplies.
Migration claims need a visible scope
NIST's ML-DSA standard establishes a post-quantum signature primitive. It does not decide how every relying party should interpret a hybrid certificate. The defensible unit of assurance is one verifier decision under one explicit policy. Quentir reads the paper as a move from counting deployed certificate objects to understanding which credential actually determined access, with direct consequences for migration warranties, audit trails and trusted digital services.