Post-quantum encryption in messaging, explained
What quantum computers mean for encrypted chats, why “harvest now, decrypt later” matters today, and how PQXDH, ML-KEM and hybrid MLS protect messages.
Frozen Chat Team · · 7 min read
You may have seen “post-quantum” or “quantum-resistant” on messaging apps lately. It can sound like science fiction marketing. It isn't: it is a practical defence against a specific risk that applies to messages you send today. This article explains it without the maths.
The problem: today's key exchange and tomorrow's computers
Encrypted messaging relies on two kinds of cryptography. Symmetric encryption (like AES) scrambles the messages themselves. Public-key cryptography (like elliptic-curve Diffie-Hellman, X25519) lets two devices agree on the symmetric keys over an open network.
A large enough quantum computer, running Shor's algorithm, could break the public-key part: it could work out the shared secrets from the public keys exchanged at the start of a conversation. Symmetric encryption with long keys, such as AES-256, is not broken the same way; quantum attacks only weaken it modestly. So the weak point is the handshake.
Nobody has publicly demonstrated a quantum computer that can do this to real-world keys, and estimates of when one might exist vary widely. So why act now?
“Harvest now, decrypt later”
Because encrypted traffic can be recorded today and kept. An adversary with enough storage can capture the handshake and the encrypted messages now, and decrypt them years later if a capable quantum computer arrives. For most chit-chat that doesn't matter. For sources, health information, business plans, legal matters or anything that should stay private for ten years or more, it does. The only defence is to make today's handshakes quantum-resistant, today.
The new building block: ML-KEM
After an open competition that ran for several years, the US National Institute of Standards and Technology (NIST) standardised ML-KEM in 2024 (FIPS 203). It is based on the algorithm known as Kyber, and it relies on mathematical problems (on lattices) that are believed to be hard for both normal and quantum computers. ML-KEM is a key encapsulation mechanism: it lets one side send the other a secret that only the holder of the private key can recover.
Why “hybrid” is the safe choice
Post-quantum algorithms are much newer than elliptic curves. To avoid betting everything on them, careful designs are hybrid: they combine a classic key agreement (X25519) with a post-quantum one (ML-KEM) so that an attacker has to break both. If ML-KEM turned out to have a flaw, the classic part still protects you against today's computers; if a quantum computer arrives, ML-KEM still protects the handshake.
PQXDH: post-quantum one-to-one chats
In 2023 Signal introduced PQXDH (Post-Quantum Extended Diffie-Hellman), an upgrade of the handshake that starts every Signal-protocol conversation. It mixes the usual elliptic-curve exchanges with an ML-KEM encapsulation, so the session's first secret is protected against harvest-now, decrypt-later. The Double Ratchet then continues as before, giving every message a new key.
Groups: MLS with a hybrid cipher suite
Groups have their own protocol. Messaging Layer Security (MLS, RFC 9420) is the IETF standard for efficient end-to-end encrypted groups. MLS supports different cipher suites, and hybrid suites that combine X25519 with ML-KEM bring the same post-quantum protection to group keys.
What post-quantum does not change
- It protects the key exchange. It doesn't hide metadata such as who talks to whom.
- Authentication (proving who you are talking to) still uses classic signatures in most deployed protocols. That matters less for harvest-now attacks, because faking a signature later can't change a recording of the past.
- It doesn't protect a compromised device, or screenshots.
How to check if your messenger is post-quantum
Look for a published technical description that names the algorithm (ML-KEM or Kyber) and the protocol (such as PQXDH or a hybrid MLS suite), and whether it covers one-to-one chats only or groups too. A vague “quantum-safe” badge without details is not enough.
Frozen Chat's approach
Frozen Chat uses libsignal with PQXDH for every one-to-one chat, and runs groups on MLS with a hybrid X25519 + ML-KEM-768 suite. We invent no cryptography of our own; we combine published protocols and well-reviewed libraries. The details, and the limits we know about, are on our security page. New to all this? Start with what is end-to-end encryption?, or see how we compare with WhatsApp and Telegram.