Signal announced a revolutionary advancement in secure messaging with the introduction of Sparse Post Quantum Ratchet (PQ Ratchet), a revolutionary cryptographic enhancement designed to protect against future threats from quantum computing.
See also: APT28 hackers use Signal to distribute malware

This latest security upgrade represents a significant milestone in the evolution of the Signal protocol, which secures billions of daily communications worldwide.
The new security enhancement introduces the Triple Ratchet protocol , which combines Signal’s proven Double Ratchet mechanism with the quantum-resistant SPQR system . This hybrid approach ensures that users maintain existing security guarantees while gaining protection from potential quantum computer attacks that could breach traditional cryptographic methods .
The SPQR implementation uses ML-KEM 768 (Machine Learning Key Encapsulation Mechanism), a NIST quantum-secure algorithm that generates strong cryptographic keys resistant to both classical and quantum computing attacks. The system uses Encapsulation Keys (EK) of 1,184 bytes and Ciphertext (CT) of 1,088 bytes, significantly larger than the 32-byte keys used in traditional ECDH (Elliptic Curve Diffie-Hellman) implementations.
To address bandwidth concerns, Signal engineers developed an innovative solution using erasure codes for efficient data transmission. This approach breaks large cryptographic keys into smaller pieces, allowing any subset of the transmitted pieces to reconstruct the original key, making the system resistant to message loss and malicious interference.
See also: Signal Windows: Taking screenshots from Recall is prohibited

The SPQR protocol maintains Signal's core security principles, such as Forward Secrecy (FS) and Post-Compromise Security (PCS). Forward Secrecy protects past messages from future compromises, while Post-Compromise Security ensures that future messages remain secure even if current keys are compromised. The quantum-safe implementation extends these protections against attacks by sufficiently powerful quantum computers.
The system addresses “ collect-now-decrypt-later ” attacks , where adversaries collect encrypted communications today with the intention of decrypting them when quantum computers become available. By implementing PQXDH (Post-Quantum Extended Diffie-Hellman) for session establishment and SPQR for ongoing protection, Signal creates a complete quantum-resistant communications framework.
The Signal implementation includes sophisticated logic for coordinating key exchanges between communicating parties. The protocol efficiently manages the exchange of large cryptographic keys through a carefully orchestrated process involving ML-KEM Braid, ensuring optimal use of available bandwidth while maintaining security guarantees.
See also: Signal phishing attacks target Ukrainian military

Signal has employed rigorous formal verification procedures using the ProVerif and F* to mathematically prove the security properties of the protocol. The Rust implementation is continuously verified through the hax translation system, ensuring the correctness of the code and preventing execution failures. This comprehensive approach to security verification demonstrates Signal’s commitment to providing mathematically proven protection for user communications in the emerging era of quantum computing.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
