Sui Plans Quantum-Safe Signatures Without Moving Users’ Funds

Key Takeaways Sui plans two NIST-standardized post-quantum signature systems for different types of accounts. Existing users should be able to switch to a quantum-safe signer without moving assets to a new address. The same recovery phrase can generate the new key through a separate derivation path. Post-quantum signatures are substantially larger, increasing transaction data requirements. The upgrade is still being audited and tested; Sui is not fully quantum-resistant today. Sui has outlined how it plans to introduce post-quantum signatures without forcing users through one of the most difficult parts of a blockchain security upgrade: moving everything they own to a new account. The network plans to support ML-DSA-65, standardized by NIST under FIPS 204, for normal accounts and SLH-DSA-SHA2-128s under FIPS 205 for higher-value vaults built with Move smart contracts. Both are designed to resist attacks from the type of large-scale quantum computers that could eventually threaten the elliptic-curve signatures widely used across crypto today. The Account Can Stay Even When the Key Changes Normally, replacing the cryptography behind a blockchain account can require users to create a new address and transfer tokens, NFTs and other assets. Applications and contracts tied to the old address may also need to adjust. Sui’s existing Address Aliases system provides a way around that problem. An account can maintain a set of authorized aliases, allowing another signer to authenticate transactions on behalf of the original address. A new signer can be added to that authorized set and eventually become the only signer allowed to approve transactions, while the original address continues to appear as the sender. When ML-DSA accounts become available, Sui says an existing account will be able to authorize a post-quantum signer while retaining the same address. That is particularly useful for accounts already connected to smart contracts, identities or other applications where changing an address creates more work than simply transferring SUI. The recovery process is also designed to remain familiar. An ML-DSA-65 key can be derived from a user’s existing recovery phrase through a new derivation path rather than requiring an entirely different backup method. An authorized alias has full authority over the account. Sui’s documentation warns that adding one effectively gives that signer control over the assets owned by the address, meaning wallet software will need to make the migration process difficult to misuse or misunderstand. Why Sui Is Using Two Different Quantum-Safe Systems Account TypeNIST StandardCryptography BasisSignature SizeNormal AccountsML-DSA-65 (FIPS 204)Lattice-based (Category 3)3,309 bytesHigh-Value VaultsSLH-DSA-SHA2-128s (FIPS 205)Hash-based (Category 1)7,856 bytes Sui is not relying on one post-quantum design for every use case. ML-DSA-65 is lattice-based and intended for normal transaction signing. It corresponds to NIST security Category 3, providing more security margin than the smaller ML-DSA-44 configuration while remaining practical enough for frequent verification.
عنوان اصلی (انگلیسی): Sui Plans Quantum-Safe Signatures Without Moving Users’ Funds
مشاهدهی خبر کامل در منبع ↗ بازگشت به سوییاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.