Post-Quantum Messaging and SSH: iMessage PQ3, Signal SPQR and OpenSSH
Why chats and logins went first
Messages and remote logins are exactly the kind of data an adversary might record today and try to read in the future. Chat history can stay sensitive for decades, and remote server access can expose entire companies. So it is not surprising that the first big wave of post-quantum deployment came from messaging apps and SSH, the tool administrators use to log in to servers. Better still, these teams control both ends of the connection, so they could move faster than the open web.
Apple iMessage PQ3
Apple announced PQ3 on February 21, 2024, beginning with iOS 17.4, iPadOS 17.4, macOS 14.4 and watchOS 10.4. According to Apple, it uses Kyber (the design that became ML-KEM) for initial key setup, with Kyber-1024, and a post-quantum rekeying ratchet using Kyber-768. It keeps classical P-256 elliptic curve elements, so it is a hybrid: attackers need to break both. The design uses several ratchets, including a post-quantum one that, at launch, ran roughly every 50 messages and at least once every seven days, adding a little over 2 KB when it runs.
Apple also proposed a simple scale of messaging security. Level 2 means post-quantum protection only when a conversation is set up (as Signal's PQXDH did). Level 3 means protection both at setup and during the ongoing conversation, and Apple said PQ3 was the first widely deployed messaging protocol at that level. That is Apple's own framing, so treat it as a claim from the vendor, though the technical description is public.
Signal: PQXDH, then SPQR
Signal first added post-quantum protection at session setup with PQXDH. On October 2, 2025 it announced the Sparse Post-Quantum Ratchet (SPQR), which runs alongside the existing Double Ratchet, forming what Signal calls the Triple Ratchet. Keys from both are mixed so an attacker needs to break the elliptic curve protection and ML-KEM. SPQR uses ML-KEM-768, whose keys and ciphertexts are over a kilobyte each, so Signal splits them into small chunks that travel with ordinary messages, using an incremental design it calls the ML-KEM Braid. Signal says users need not do anything, and that it intends to enforce SPQR on all sessions later. It also describes formal verification work (ProVerif models and verification in its build pipeline), which is a good sign of engineering care.
OpenSSH
The OpenSSH project reports that post-quantum key agreement has been the default since release 9.0 in April 2022, starting with sntrup761x25519-sha512. Version 9.9 added mlkem768x25519-sha256, and version 10.0 in April 2025 made that the default. Version 10.1 goes further: it warns users when a connection uses a key agreement that is not post-quantum, citing store now, decrypt later risk. If you see that warning, the project says the usual fix is to upgrade the server. This is a nice example of software nudging people in the right direction.
| Tool | What is protected | Reported milestone |
|---|---|---|
| iMessage PQ3 | Setup and ongoing rekeying | Announced Feb 21, 2024 |
| Signal SPQR | Ongoing ratchet, added to PQXDH setup | Announced Oct 2, 2025 |
| OpenSSH | Key agreement for remote logins | Hybrid default since 9.0 (2022); ML-KEM hybrid default in 10.0 (Apr 2025) |
What these do not do
Be careful with the word "quantum-proof." These upgrades protect the secrecy of message and session keys. They do not make a phone, a server or a person secure against phishing, malware or stolen passwords, which cause far more real breaches than quantum computers ever have. Identity verification (who is on the other end) generally still relies on classical signatures in several of these systems, which the field is working on next, see quantum resistant signatures.
What you can do
- Update your messaging apps and operating system; the protection arrives automatically.
- Admins: run a recent OpenSSH on clients and servers, and do not disable the post-quantum algorithms in KexAlgorithms.
- Treat any app claiming "quantum encryption" with healthy skepticism and ask which standard it follows. See also quantum key distribution, a different idea that needs special hardware.
The big picture
When messaging apps and SSH are quietly upgraded years before a cryptographically relevant quantum computer exists, we are seeing the best-case version of a security transition: early, boring and invisible. The same pattern is now spreading to browsers (hybrid TLS) and to company systems (migration checklist).
Sources and further reading
- Apple Security Research: iMessage with PQ3
- Signal: Sparse Post-Quantum Ratchet (October 2, 2025)
- OpenSSH: post-quantum cryptography
Reported as of 2026-10-09. Standards and rollout numbers change often, so check the primary documents before relying on any figure. This is education, not financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of any lab or government.
Frequently asked questions
What is iMessage PQ3?
Apple's post-quantum upgrade for iMessage, announced on February 21, 2024. It protects both the start of a conversation and the ongoing rekeying, using a hybrid of Kyber and classical elliptic curves.
What is Signal's SPQR?
The Sparse Post-Quantum Ratchet, announced October 2, 2025. It adds ML-KEM-768 based ongoing protection next to the existing Double Ratchet.
Is OpenSSH post-quantum by default?
OpenSSH reports a post-quantum hybrid has been the default since 9.0 (2022), with an ML-KEM hybrid default in 10.0 (April 2025) and a warning for non-post-quantum connections in 10.1.
Does this make my chats unhackable?
No. It protects the secrecy of keys against future quantum attacks. Phishing, malware and weak passwords remain the bigger practical risks.
Does QNT have anything to do with Signal, Apple or OpenSSH?
No. It is an independent memecoin. This is not financial advice.
Keep reading
- ML-KEM Explained: The Post-Quantum Key Exchange Standard
ML-KEM (FIPS 203) is NIST's standard for post-quantum key encapsulation. Learn what a KEM is, how lattices fit in, and where it is used, in plain English. - Hybrid Key Exchange in TLS Explained: How Your Browser Is Already Quantum Ready
A plain English guide to X25519MLKEM768, the hybrid handshake that now protects a large share of web traffic against harvest now, decrypt later attacks. - Quantum Key Distribution (QKD) Explained vs Post-Quantum Cryptography
QKD uses quantum physics to share encryption keys. Learn how it works, its limits, and how it differs from post-quantum cryptography. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary