Post-quantum encryption

What this criterion guarantees: Your communications recorded today cannot be decrypted tomorrow, on the day a sufficiently powerful quantum computer exists.

Without it: An adversary who records your encrypted communications today will be able to decrypt them retroactively as soon as they have such a computer.

At a glance
• Olvid — ❌ Poor (planned for 2027)
• Signal — ✅ Good
• WhatsApp — ❌ Poor
• Telegram — ❌ Poor
• Matrix-based — ❌ Poor
• SimpleX — 🟠 Partial
• Threema — ❌ Poor

The arrival of a sufficiently powerful quantum computerarchived would threaten the asymmetric cryptography used today by almost all messaging apps (RSA, Diffie-Hellman, elliptic curves): Shor’s algorithmarchived would make it possible to break it, calling into question the authenticity and confidentiality of exchanges. Such a computer does not exist yet, but communications intercepted and stored today could be decrypted retroactively the day it does, a risk summed up by the expression “harvest now, decrypt later,” and one that particularly concerns exchanges meant to remain confidential in the long term. The NSA formalized this threat in its CNSA 2.0archived suite, which imposes on the systems it governs a migration schedule toward post-quantum algorithms. Germany’s BSIarchived and France’s ANSSIarchived are both pushing security vendors to take this risk into account.

Why encryption, and not signatures?

Let us first clarify what a quantum computer actually threatens. Message content is encrypted with symmetric algorithms, such as AES-256 (or XSalsa20 in Threema’s case), which already resist a quantum computer: Grover’s algorithm does speed up an exhaustive search for a symmetric key, but this speedup only halves the effective key length, so a 256-bit key still retains 128 bits of security, which is sufficient. This is in line with ANSSI’s recommendations (in French) for symmetric primitives. It is the asymmetric algorithms that are threatened, and a messaging app uses them for two purposes:

  • encryption, to establish a shared secret between two devices, from which the symmetric keys that encrypt the messages are derived;
  • signatures, to authenticate users and their keys, when this shared secret is established but also in other protocols of the messaging app.

Faced with a quantum computer, these two uses do not carry the same risk. The establishment of the shared secret is threatened as of today: an adversary who records all the traffic, including the key exchange on which the messages depend, will later be able to recover this secret, derive the symmetric keys from it and decrypt the messages. A signature, on the other hand, only matters at the moment it is verified: to forge one, the attacker must have a quantum computer at the very moment of the exchange. As long as such a computer does not exist, classical signatures therefore remain secure, which is why this criterion covers encryption only.

Hybrid encryption

Post-quantum algorithms are recent and their security is less proven than that of classical algorithms: ML-KEMarchived was only standardized by NIST in 2024. Messaging apps that adopt them therefore combine them with a classical key exchange: this is what is called hybrid encryption. The secrets resulting from the two exchanges are mixed to produce the key that encrypts the messages, and an attacker must break both algorithms to recover it. Hybrid encryption is therefore never less secure than the classical encryption it complements.

Among the messaging apps in this benchmark, two have already deployed such encryption:

  • Signal introduced the PQXDHarchived key agreement as early as 2023, then began in October 2025archived the gradual rollout of a “triple ratchet” that extends this resistance to the entire encryption of the conversation.
  • SimpleX Chat, for its part, has added a post-quantum double ratchetarchived to its direct chats, enabled by default since version 5.7; group chats do not benefit from it yet.

A serious threat, but not a structural one

This criterion nevertheless differs from the others in two respects. First, the quantum threat is not “structural”: it is very likely that all the messaging apps in this benchmark will follow in the footsteps of Signal and SimpleX and soon adopt post-quantum encryption. The main difficulty is making a “smooth” transition that preserves compatibility with users who have not yet updated their application, but replacing a cryptographic building block is not hard in itself. Structural properties, on the other hand, such as the use of a phone number or of a central directory for contact discovery, are much harder to change, because they directly affect the user’s everyday experience.

Second, the other criteria in this benchmark correspond to weaknesses that give rise to real attacks right now, and they therefore remain a priority for anyone choosing a messaging app today. Communications recorded today can only be decrypted with a quantum computer whose cost will run into the millions of euros, whereas intercepting an SMS to take control of an account costs only a few dozen euros. It would be unfortunate to choose a messaging app for its post-quantum security while forgetting to protect yourself against these very real attacks.

The case of calls

Most messaging apps rely on WebRTC technology for their audio and video calls. The keys for these calls are established by the DTLS protocol, whose hybrid post-quantum variant is still experimental in the reference WebRTC library and remains disabled by default. Once it is enabled, the transition should be simple for most messaging apps: for now, we therefore consider calls to be outside the scope of this criterion. Signal is the exception: its RingRTC layer replaces DTLS with a Diffie-Hellman exchange sent inside its messages, which are themselves protected by post-quantum encryption, so that an adversary who records the traffic has no access to the elements of this exchange.

Applying this criterion

A messaging app gets a ✅Good if all its conversations, one-to-one and group chats alike, benefit from hybrid post-quantum encryption by default. It gets a 🟠Partial if this encryption is enabled by default for only some of its conversations, for example one-to-one chats but not groups. It gets a ❌Poor if it offers no post-quantum encryption at all.