technology
Hybrid post-quantum TLS (X25519MLKEM768)
Also known as X25519MLKEM768, hybrid ML-KEM, PQ/T hybrid key agreement, RFC 10024
Hybrid post-quantum TLS combines a classical elliptic-curve key exchange with ML-KEM in the TLS 1.3 handshake, so a connection stays secure unless both are broken; the most widely used combination is X25519MLKEM768.[1][2] The IETF standardized it as RFC 10024 in August 2026, by which time Chrome and Apple's operating systems offered it by default and over 65% of human traffic to Cloudflare used post-quantum encryption.[2][3][4][5]
Key facts
What it is
Every HTTPS connection begins with a TLS handshake, where browser and server agree on a session key. In hybrid post-quantum TLS, that agreement runs two key exchanges at once. One is a classical elliptic-curve Diffie-Hellman exchange; the other is the post-quantum ml-kem. The results are combined into one key.[2] Hybrids are designed to stay secure as long as at least one component is secure.[1] The goal is to stop “harvest now, decrypt later” attacks on recorded traffic.[4]
The standard
In August 2026 the IETF published RFC 10024 as a Proposed Standard. It defines three hybrid groups for TLS 1.3: X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024.[2] The first pairs the X25519 curve with ML-KEM-768. It is the group that Chrome and Apple’s operating systems offer.[3][4]
Deployment
- Google Chrome first enabled a hybrid of X25519 and pre-standard Kyber for all desktop clients.[6] It moved to ML-KEM in Chrome 131, changing the TLS codepoint from 0x6399 to 0x11EC because the final standard was not compatible with the earlier Kyber.[3]
- Apple devices running iOS 26, iPadOS 26, macOS Tahoe 26 and visionOS 26 advertise X25519MLKEM768 in every TLS 1.3 ClientHello. They fall back to classical groups if a server does not support it.[4]
- Cloudflare enabled post-quantum encryption for all websites and APIs in 2022.[7] Its Radar data shows client support rising from under 3% of traffic at the start of 2024 to over 60% in February 2026.[8] In April 2026 it said over 65% of human traffic to its network was post-quantum encrypted.[5]
- Open-source libraries. OpenSSL 3.5 (April 2025) added ML-KEM.[9]
Limits
Hybrid key exchange protects confidentiality, not identity. Server certificates are still signed with classical algorithms, which a future quantum computer could forge in real time.[10][11] Post-quantum signatures are much larger.[12] The UK NCSC expects the Web PKI to be one of the hardest parts of the migration.[13] In 2026 Google and Cloudflare both said authentication was now their priority. Cloudflare targets full post-quantum security, including authentication, by 2029.[14][15]
NIST also notes that hybrids add complexity and expects them to be temporary, leading to a second move to PQC-only algorithms.[16] Chrome’s switch from Kyber to ML-KEM was an early example of changing algorithms in a live system, a skill the field calls crypto-agility.[3][17]
Inside RFC 10024
The IETF Datatracker records RFC 10024 as published on 10 August 2026.[18] The size cost is concrete. An X25519MLKEM768 client key share is 1,216 bytes, 1,184 for ML-KEM and 32 for X25519, and the server’s reply is 1,120 bytes.[19] A purely classical X25519 share is just those 32 bytes.[19] For historical reasons, X25519MLKEM768 puts the ML-KEM share first, reversing the naming convention, while SecP256r1MLKEM768 puts the elliptic-curve share first.[20] The RFC says every group can be implemented in a FIPS-approved way. It describes SecP384r1MLKEM1024 as intended for high-security settings that want an extra margin.[21]
How governments view hybrids
Positions differ. The EU roadmap recommends standardised, tested hybrid solutions whenever feasible.[22] NSA’s CNSA 2.0 advisory accepts that hybrids may be allowed or required for protocol or interoperability reasons. But it makes the CNSA 2.0 algorithms mandatory at set dates and says classical algorithms alone will no longer be approved.[23]
Questions readers ask
Why combine ML-KEM with X25519 instead of using ML-KEM alone?
Hybrid schemes are designed to stay secure if at least one component is secure, hedging against an undiscovered flaw in the newer algorithm. NIST notes they add complexity and expects them to be temporary.[1][16]
How can I tell if a site uses post-quantum TLS?
Cloudflare Radar added a browser check for X25519MLKEM768 in October 2025, and Apple documents how to check whether a server supports quantum-secure TLS starting with macOS Tahoe 26.[24]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [2]
In August 2026 the IETF published RFC 10024, a Proposed Standard defining three hybrid key agreement mechanisms for TLS 1.3, X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024, which combine ML-KEM with elliptic-curve Diffie-Hellman. confirmedas of 2026-08-10
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- [3]
Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- [4]
In iOS 26, iPadOS 26, macOS Tahoe 26 and visionOS 26, TLS connections automatically advertise hybrid quantum-secure key exchange, including X25519MLKEM768 in the ClientHello. confirmedas of 2026-10-10
- Prepare your network for quantum-secure encryption in TLS · Apple Support (retrieved 2026-10-10)
- Prepare your network for quantum-secure encryption in TLS · Apple Support (retrieved 2026-10-10)
- [5]
As of April 2026, Cloudflare said over 65% of human traffic to its network was post-quantum encrypted. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [6]
Before ML-KEM was finalized, Google enabled a hybrid key exchange combining X25519 and Kyber for 100% of Chrome desktop clients. confirmedas of 2024-09-13
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- [7]
Cloudflare says it began preparing its post-quantum migration in 2019 and enabled post-quantum encryption for all websites and APIs in 2022. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [8]
Cloudflare Radar measured client support for post-quantum encryption growing from under 3% of traffic at the start of 2024 to over 60% in February 2026. confirmedas of 2026-02-27
- Bringing more transparency to post-quantum usage, encrypted messaging, and routing security · Cloudflare · 2026-02-27 (retrieved 2026-10-10)
- [9]
OpenSSL 3.5, released on 8 April 2025, added support for ML-KEM, ML-DSA and SLH-DSA. confirmedas of 2025-04-08
- OpenSSL 3.5 Final Release - Live · OpenSSL Library · 2025-04-08 (retrieved 2026-10-10)
- [10]
Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [11]
A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- [12]
ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 · Table 2 (retrieved 2026-10-10)
- [13]
The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20
- Timelines for migration to post-quantum cryptography · UK National Cyber Security Centre · 2025-03-20 (retrieved 2026-10-10)
- [14]
Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25
- Quantum frontiers may be closer than they appear · Google · 2026-03-25 (retrieved 2026-10-10)
- [15]
On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [16]
NIST notes that hybrid solutions add complexity, which can raise security risks and costs, and expects them to be temporary steps toward a second transition to PQC-only tools. confirmedas of 2024-11-12
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [17]
NIST defines cryptographic agility as the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations. confirmedas of 2025-12-19
- NIST CSWP 39: Considerations for Achieving Cryptographic Agility · NIST · 2025-12-19 (retrieved 2026-10-10)
- [18]
The IETF Datatracker records RFC 10024 as published on 10 August 2026. confirmedas of 2026-08-10
- IETF Datatracker: RFC 10024 publication event · IETF · 2026-08-10 · docevent record, "time": "2026-08-10T18:11:15Z" (retrieved 2026-10-10)
- [19]
Under RFC 10024, an X25519MLKEM768 client key share is 1,216 bytes (1,184 for ML-KEM and 32 for X25519) and the server share 1,120 bytes (1,088 for ML-KEM and 32 for X25519). confirmedas of 2026-08-10
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- [20]
RFC 10024 notes that X25519MLKEM768 puts the ML-KEM share before the X25519 share, reversing the usual naming convention for historical reasons, while SecP256r1MLKEM768 puts the elliptic-curve share first. confirmedas of 2026-08-10
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 · Section 4.1 note (the "|" marks are line prefixes in the RFC text) (retrieved 2026-10-10)
- [21]
RFC 10024 says each of its hybrid groups can be implemented in a FIPS-approved way, and describes SecP384r1MLKEM1024 as intended for high-security environments that need FIPS-approved mechanisms with an extra security margin. confirmedas of 2026-08-10
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF (RFC Editor) · 2026-08-01 (retrieved 2026-10-10)
- [22]
The EU roadmap recommends standardised and tested hybrid solutions whenever feasible, and suggests replacing RSA or discrete-logarithm mechanisms with a standardised hybrid combination that includes PQC. confirmedas of 2025-06-11
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (Part 1, v1.1) · NIS Cooperation Group, EU PQC Workstream (European Commission) · 2025-06-11 (retrieved 2026-10-10)
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (Part 1, v1.1) · NIS Cooperation Group, EU PQC Workstream (European Commission) · 2025-06-11 (retrieved 2026-10-10)
- [23]
NSA's CNSA 2.0 advisory says hybrid solutions may be allowed or required for protocol, product or interoperability reasons, but that CNSA 2.0 algorithms become mandatory at the given dates and classical CNSA 1.0 algorithms alone will no longer be approved. confirmedas of 2022-09-07
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Footnote 1, Timing section (retrieved 2026-10-10)
- [24]
In October 2025 Cloudflare Radar added a way for users to check whether their browser supports X25519MLKEM768, and Apple documents how to check whether a web server supports quantum-secure TLS starting with macOS Tahoe 26. confirmedas of 2026-02-27
- Bringing more transparency to post-quantum usage, encrypted messaging, and routing security · Cloudflare · 2026-02-27 (retrieved 2026-10-10)
- Prepare your network for quantum-secure encryption in TLS · Apple Support (retrieved 2026-10-10)
Revision history (2)
- Page created.
- Added RFC 10024 publication date, key-share sizes and ordering, FIPS notes, and EU and NSA positions on hybrids.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"Hybrid post-quantum TLS (X25519MLKEM768)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/hybrid-post-quantum-tls
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHarvest now, decrypt later: why the quantum threat is already hereHow attackers can store encrypted data today to decrypt with a future quantum computer, which data is at risk, and why it drives migration deadlines.
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.
- DevelopingPost-quantum cryptography and security trackerA dated, sourced timeline of post-quantum cryptography and AI security milestones: NIST standards, deployment, government deadlines, 2024-2026.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiHQC (Hamming Quasi-Cyclic)HQC is the code-based encryption algorithm NIST picked in 2025 as a backup to ML-KEM. Why it was chosen, its trade-offs and its standards status.
- WikiML-DSA (FIPS 204)ML-DSA, formerly CRYSTALS-Dilithium, is NIST's main post-quantum digital signature standard. How it works, its sizes and where it is deployed.