Skip to content
ContentLora

    Tip: press / anywhere to search.

    technology

    Signal's post-quantum protocol (PQXDH and SPQR)

    Also known as PQXDH, SPQR, Sparse Post Quantum Ratchet, Triple Ratchet, Signal Protocol

    Signal added post-quantum protection to its encrypted messaging protocol in two stages: PQXDH in September 2023, which secures how conversations start, and the Sparse Post Quantum Ratchet (SPQR) in October 2025, which protects ongoing messages.[1][2] Both are hybrids that mix classical and post-quantum keys, so an attacker must break both, and both roll out without any action from users.[1][2]

    Editor reviewedUpdated Post-quantum cryptography and securityComputing
    Key facts

    Why messaging needed an upgrade

    End-to-end encrypted messages are an obvious target for “harvest now, decrypt later”. An adversary who records encrypted chats today could read them once a capable quantum computer exists.[3] The Signal Protocol relied on elliptic-curve cryptography, which Shor’s algorithm would break.[4]

    Step one: PQXDH (2023)

    In September 2023 Signal replaced its X3DH key agreement with PQXDH for starting new conversations. PQXDH computes a shared secret from both the X25519 elliptic-curve exchange and the post-quantum CRYSTALS-Kyber KEM, then combines the two. An attacker would have to break both to recover the key.[1] Signal explained the cautious design. It did not want to simply swap in a post-quantum system, noting that one candidate in NIST’s process had been broken by a classical computer.[5][6]

    Step two: SPQR and the Triple Ratchet (2025)

    PQXDH protected the start of a conversation. Signal’s “Double Ratchet”, which keeps refreshing keys as messages flow, was still classical. On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR).[2] It runs SPQR alongside the Double Ratchet. Each message key comes from both, mixed through a key derivation function, in what Signal calls the Triple Ratchet.[2] SPQR uses an incremental version of ml-kem 768.[7] Signal says users see no change, and that conversations migrate automatically.[2]

    How it compares

    Apple took a similar path with iMessage. In February 2024 it announced PQ3, which uses post-quantum cryptography both for setting up keys and for the ongoing message exchange. It rolled out with iOS 17.4.[8] Both designs are hybrids, the same approach used in hybrid-post-quantum-tls on the web. Hybrids are meant to stay secure if either the classical or the post-quantum part holds.[9]

    What it does not cover

    These upgrades protect message confidentiality from future quantum decryption. They do not protect conversations recorded before the upgrade reached both parties.[3] Authentication of identities is a separate problem, and the field more broadly is only now turning to post-quantum signatures.[10][11]

    Engineering the rollout

    Post-quantum keys are much larger than elliptic-curve ones, and phones on poor connections pay for every byte. SPQR therefore splits ML-KEM keys and ciphertexts into small chunks that travel alongside ordinary messages. It uses erasure codes, so the recipient can rebuild the data from any sufficient set of chunks. An attacker who drops some messages cannot block the exchange without causing an obvious denial of service.[12]

    Not every device could support SPQR at once. Signal designed it to fall back to not being used when the other side’s client does not yet support it. A downgrade is allowed only when a session receives its first message from the other party, which stops a later downgrade by bugs or attackers. Signal plans to enforce SPQR for all sessions once all clients support it.[13]

    Signal said formal verification had been important for getting PQXDH’s details right, and that it applied the same approach to SPQR from the start. The incremental ML-KEM 768 relies on the libcrux-ml-kem Rust library.[14]

    Questions readers ask

    Do Signal users need to do anything to get post-quantum protection?

    No. Signal says that conversations move to the new protocol automatically, without users taking any action.[2]

    Why does Signal keep its old elliptic-curve cryptography?

    Signal chose to augment rather than replace it, partly because a post-quantum candidate in NIST's process had been found attackable by a classical computer; an attacker must break both systems.[5][1]

    How is SPQR different from PQXDH?

    PQXDH protects how a conversation starts. SPQR adds post-quantum protection to the ongoing ratchet, mixing its keys with the existing Double Ratchet in what Signal calls the Triple Ratchet.[1][2]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      In September 2023 Signal introduced PQXDH, which derives a shared secret from both X25519 and CRYSTALS-Kyber so that an attacker must break both. confirmedas of 2023-09-19

    2. [2]

      On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR), which runs alongside its Double Ratchet and mixes both keys in a "Triple Ratchet", rolling out without any user action. confirmedas of 2025-10-02

    3. [3]

      In a "harvest now, decrypt later" attack, an adversary captures encrypted data today and stores it, hoping a future quantum computer will break the encryption. confirmedas of 2026-10-10

    4. [4]

      A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10

    5. [5]

      Signal said it chose to augment rather than replace elliptic-curve cryptography partly because one post-quantum candidate in NIST's process had been found attackable by a classical computer. confirmedas of 2023-09-19

    6. [6]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    7. [7]

      SPQR uses an incremental version of ML-KEM 768. confirmedas of 2025-10-02

    8. [8]

      In February 2024 Apple announced PQ3 for iMessage, which uses post-quantum cryptography for both initial key establishment and ongoing message exchange, rolling out with iOS 17.4. confirmedas of 2024-02-21

    9. [9]

      Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12

    10. [10]

      Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10

    11. [11]

      Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25

    12. [12]

      Signal said SPQR splits large ML-KEM keys and ciphertexts into small chunks sent alongside ordinary messages, using erasure codes so a recipient can rebuild the data from any sufficient set of chunks even if some messages are lost or dropped by an attacker. confirmedas of 2025-10-02

    13. [13]

      Signal designed SPQR to fall back to not being used when the other party's client does not support it yet, allowing a downgrade only on a session's first received message, and plans to enforce SPQR for all sessions once all clients support it. confirmedas of 2025-10-02

    14. [14]

      Signal said formal verification had been an important tool when designing PQXDH and was used from the start for SPQR, whose incremental ML-KEM 768 relies on the libcrux-ml-kem Rust library. confirmedas of 2025-10-02

    Revision history (2)
    1. Page created.
    2. Added how SPQR handles large keys, rollout and downgrades, and formal verification.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "Signal's post-quantum protocol (PQXDH and SPQR)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/signal-post-quantum-protocol

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.