technology
Signal's post-quantum protocol (PQXDH and SPQR)
Also known as PQXDH, SPQR, Sparse Post Quantum Ratchet, Triple Ratchet, Signal Protocol
Signal added post-quantum protection to its encrypted messaging protocol in two stages: PQXDH in September 2023, which secures how conversations start, and the Sparse Post Quantum Ratchet (SPQR) in October 2025, which protects ongoing messages.[1][2] Both are hybrids that mix classical and post-quantum keys, so an attacker must break both, and both roll out without any action from users.[1][2]
Key facts
Why messaging needed an upgrade
End-to-end encrypted messages are an obvious target for “harvest now, decrypt later”. An adversary who records encrypted chats today could read them once a capable quantum computer exists.[3] The Signal Protocol relied on elliptic-curve cryptography, which Shor’s algorithm would break.[4]
Step one: PQXDH (2023)
In September 2023 Signal replaced its X3DH key agreement with PQXDH for starting new conversations. PQXDH computes a shared secret from both the X25519 elliptic-curve exchange and the post-quantum CRYSTALS-Kyber KEM, then combines the two. An attacker would have to break both to recover the key.[1] Signal explained the cautious design. It did not want to simply swap in a post-quantum system, noting that one candidate in NIST’s process had been broken by a classical computer.[5][6]
Step two: SPQR and the Triple Ratchet (2025)
PQXDH protected the start of a conversation. Signal’s “Double Ratchet”, which keeps refreshing keys as messages flow, was still classical. On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR).[2] It runs SPQR alongside the Double Ratchet. Each message key comes from both, mixed through a key derivation function, in what Signal calls the Triple Ratchet.[2] SPQR uses an incremental version of ml-kem 768.[7] Signal says users see no change, and that conversations migrate automatically.[2]
How it compares
Apple took a similar path with iMessage. In February 2024 it announced PQ3, which uses post-quantum cryptography both for setting up keys and for the ongoing message exchange. It rolled out with iOS 17.4.[8] Both designs are hybrids, the same approach used in hybrid-post-quantum-tls on the web. Hybrids are meant to stay secure if either the classical or the post-quantum part holds.[9]
What it does not cover
These upgrades protect message confidentiality from future quantum decryption. They do not protect conversations recorded before the upgrade reached both parties.[3] Authentication of identities is a separate problem, and the field more broadly is only now turning to post-quantum signatures.[10][11]
Engineering the rollout
Post-quantum keys are much larger than elliptic-curve ones, and phones on poor connections pay for every byte. SPQR therefore splits ML-KEM keys and ciphertexts into small chunks that travel alongside ordinary messages. It uses erasure codes, so the recipient can rebuild the data from any sufficient set of chunks. An attacker who drops some messages cannot block the exchange without causing an obvious denial of service.[12]
Not every device could support SPQR at once. Signal designed it to fall back to not being used when the other side’s client does not yet support it. A downgrade is allowed only when a session receives its first message from the other party, which stops a later downgrade by bugs or attackers. Signal plans to enforce SPQR for all sessions once all clients support it.[13]
Signal said formal verification had been important for getting PQXDH’s details right, and that it applied the same approach to SPQR from the start. The incremental ML-KEM 768 relies on the libcrux-ml-kem Rust library.[14]
Questions readers ask
Do Signal users need to do anything to get post-quantum protection?
No. Signal says that conversations move to the new protocol automatically, without users taking any action.[2]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
In September 2023 Signal introduced PQXDH, which derives a shared secret from both X25519 and CRYSTALS-Kyber so that an attacker must break both. confirmedas of 2023-09-19
- Quantum Resistance and the Signal Protocol · Signal · 2023-09-19 (retrieved 2026-10-10)
- [2]
On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR), which runs alongside its Double Ratchet and mixes both keys in a "Triple Ratchet", rolling out without any user action. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- [3]
In a "harvest now, decrypt later" attack, an adversary captures encrypted data today and stores it, hoping a future quantum computer will break the encryption. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [4]
A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- [5]
Signal said it chose to augment rather than replace elliptic-curve cryptography partly because one post-quantum candidate in NIST's process had been found attackable by a classical computer. confirmedas of 2023-09-19
- Quantum Resistance and the Signal Protocol · Signal · 2023-09-19 (retrieved 2026-10-10)
- [6]
In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30
- An efficient key recovery attack on SIDH · IACR Cryptology ePrint Archive (EUROCRYPT 2023) · 2022-07-30 (retrieved 2026-10-10)
- [7]
SPQR uses an incremental version of ML-KEM 768. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- [8]
In February 2024 Apple announced PQ3 for iMessage, which uses post-quantum cryptography for both initial key establishment and ongoing message exchange, rolling out with iOS 17.4. confirmedas of 2024-02-21
- iMessage with PQ3: The new state of the art in quantum-secure messaging at scale · Apple Security Research · 2024-02-21 (retrieved 2026-10-10)
- iMessage with PQ3: The new state of the art in quantum-secure messaging at scale · Apple Security Research · 2024-02-21 (retrieved 2026-10-10)
- [9]
Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [10]
Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [11]
Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25
- Quantum frontiers may be closer than they appear · Google · 2026-03-25 (retrieved 2026-10-10)
- [12]
Signal said SPQR splits large ML-KEM keys and ciphertexts into small chunks sent alongside ordinary messages, using erasure codes so a recipient can rebuild the data from any sufficient set of chunks even if some messages are lost or dropped by an attacker. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- [13]
Signal designed SPQR to fall back to not being used when the other party's client does not support it yet, allowing a downgrade only on a session's first received message, and plans to enforce SPQR for all sessions once all clients support it. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- [14]
Signal said formal verification had been an important tool when designing PQXDH and was used from the start for SPQR, whose incremental ML-KEM 768 relies on the libcrux-ml-kem Rust library. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
Revision history (2)
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"Signal's post-quantum protocol (PQXDH and SPQR)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/signal-post-quantum-protocol
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHarvest now, decrypt later: why the quantum threat is already hereHow attackers can store encrypted data today to decrypt with a future quantum computer, which data is at risk, and why it drives migration deadlines.
- WikiHybrid post-quantum TLS (X25519MLKEM768)How browsers and servers combine X25519 with ML-KEM to protect web traffic from future quantum decryption, and how far deployment had got by 2026.
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiHQC (Hamming Quasi-Cyclic)HQC is the code-based encryption algorithm NIST picked in 2025 as a backup to ML-KEM. Why it was chosen, its trade-offs and its standards status.
- WikiML-DSA (FIPS 204)ML-DSA, formerly CRYSTALS-Dilithium, is NIST's main post-quantum digital signature standard. How it works, its sizes and where it is deployed.