ML-DSA Explained: The Post-Quantum Signature Standard
What ML-DSA is
ML-DSA stands for Module-Lattice-Based Digital Signature Algorithm. NIST published it in 2024 as FIPS 204. During the competition it was known as CRYSTALS-Dilithium. It is intended to be the general purpose signature standard for the post-quantum era, alongside SLH-DSA, which is built on different math.
What a digital signature does
A signature scheme has key generation, signing and verification. The signer keeps the private key secret and publishes the public key. Signing a message produces a signature that anyone can verify against the public key, and nobody without the private key should be able to forge one. Wallets rely on this every time you approve a transaction, as described in How Wallet Signing Works and Why Keys Stay Private.
Why a replacement is needed
Most blockchains, including Solana, use elliptic curve signatures. A large enough fault tolerant quantum computer running Shor's algorithm could in principle derive a private key from a public key. That is the concern behind Will Quantum Computers Break Bitcoin and Solana. Such machines do not exist today, but migration takes years, which is why standards are being finished early.
How the lattice approach works in general terms
ML-DSA follows a design often described as Fiat-Shamir with aborts. The signer commits to a masked random value, derives a challenge from a hash of the message, and computes a response. If the response would leak information about the private key, the signer discards the attempt and tries again with fresh randomness. Security is tied to lattice problems, the same family of ideas used in ML-KEM.
Trade-offs compared with elliptic curves
| Elliptic curve signatures | ML-DSA | |
|---|---|---|
| Quantum resistance | No | Believed yes |
| Public key and signature size | Very small | Much larger |
| Speed | Fast | Also fast |
| Years of public scrutiny | Decades | Fewer |
Larger signatures matter a lot for blockchains, because transaction size and storage are limited resources. That is a central engineering challenge of any migration.
Where it fits
ML-DSA is a strong candidate wherever signatures are needed and size is tolerable. For a survey of options see Quantum-Resistant Signatures Explained. To understand how networks might adapt, read Crypto Agility Explained.
The standard defines several parameter sets, giving a choice between smaller sizes and larger security margins. Implementers must also take care with randomness and with side channels, since a signing routine that leaks timing information can expose a private key. This is one reason careful, audited libraries matter more than the algorithm name alone.
Another point to keep in mind is that signatures protect two different things. They prove who authorized a transaction, and they protect against tampering with its contents. A replacement scheme has to preserve both properties, and every wallet, explorer and validator that checks signatures would need to understand the new format before it could be used widely. That coordination is slow even when the math is ready, so readers should expect a gradual transition and not a sudden switch.
Frequently asked questions
What does ML-DSA stand for?
Module-Lattice-Based Digital Signature Algorithm. It is the standardized form of the scheme submitted to the NIST competition as CRYSTALS-Dilithium.
Is ML-DSA the same as ML-KEM?
No. ML-DSA is for signatures and authentication. ML-KEM is for establishing shared secret keys. They share a lattice foundation but do different jobs.
Are ML-DSA signatures bigger than ECDSA or Ed25519?
Yes, substantially. That size difference is one of the main obstacles for blockchains, where each byte of a transaction has a cost.
Is Solana using ML-DSA?
Solana accounts commonly use Ed25519 signatures today. Any future change would be a network level decision, and this site does not claim any specific plan.
Does ML-DSA protect a token like QNT?
A token's safety depends on the wallets and network that hold it. A new signature standard would need to be adopted by the network and wallets first.
Can ML-DSA be broken?
No practical break is publicly known, but it is based on assumptions, not proofs. Cryptographers keep analysing it, and standards can be revised.
Keep reading
- ML-KEM Explained: The Post-Quantum Key Exchange Standard
ML-KEM (FIPS 203) is NIST's standard for post-quantum key encapsulation. Learn what a KEM is, how lattices fit in, and where it is used, in plain English. - SLH-DSA Explained: Hash-Based Stateless Signatures
SLH-DSA (FIPS 205) is NIST's hash-based, stateless post-quantum signature standard. Learn how it works, why it is cautious, and its size and speed trade-offs. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - How Wallet Signing Works and Why Keys Stay Private
How a crypto wallet signs transactions with a private key, what you approve when you confirm, and why you must never share a seed phrase with anyone.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary