Blog

Zentalk | Post-Quantum Migration Clock

NSA CNSA 2.0 requires post-quantum completion by 2035. Zentalk shipped hybrid post-quantum by default — the migration clock, for its users, has already stopped.

May 30, 2026 · 11 min · Zentachain Team
A watchmaker's bench in a dark workshop, a network of interlocking brass gears held together by the Zentachain logo at its centre — post-quantum migration as precise clockwork.
On this page

An intelligence agency is recording your ciphertext right now. This is the adversary behind metadata surveillance at its most patient. It cannot decrypt it today. In a decade, with sufficient quantum hardware, it will. The content you consider private in 2026 is an investment the adversary is making against a future capability. The attack is called harvest-now-decrypt-later, and it is operational — not theoretical — against every system still using classical key exchange.

In August 2024, the US National Institute of Standards and Technology finalized three post-quantum cryptographic standards: ML-KEM (based on Kyber-768), ML-DSA (based on Dilithium), and SLH-DSA (based on SPHINCS+). The event closed a decade-long standardization process and started a different clock: the migration clock. Per the NSA's CNSA 2.0 guidance (2022), all national security systems must complete transition to post-quantum algorithms by 2035.

Most of the industry is not ready. The underlying algorithms are well-defined; integrating them into deployed protocols, client libraries, and user-facing applications is a multi-year engineering effort that most vendors have not yet begun in earnest. A significant post-quantum market migration is underway — estimates in external market research reports (to verify) place the total modernization cost in the tens of billions of dollars across the next five to seven years.

Zentalk shipped hybrid post-quantum by default in its first public release. This article lays out why the migration clock matters, what Zentalk's specific roadmap for 2026-2028 covers, and what the industry race looks like from the inside.

The two clocks

The migration is not one deadline — it is two, running at different speeds for different adversaries.

The first is the NIST compliance clock. Per NSA CNSA 2.0 (2022), federal systems must complete the transition to post-quantum-resistant primitives by 2035. Commercial systems serving federal use cases or operating under federal contracts are pulled into the same timeline. This is the policy clock, and it has known deadlines with published milestones.

The second is the adversary clock. Intelligence agencies and well-funded research labs are recording ciphertext now with the intent of decrypting it when hardware capability arrives — exactly the harvest-now-decrypt-later threat described above. The agencies do not announce when they expect to have the hardware; published research suggests cryptographically relevant quantum computers could be plausible within the 2030s. The adversary clock has no public deadline, only an operational one, and systems that assume a specific year of readiness are betting on a schedule the adversary has not published.

Serious migration planning optimizes against the second clock, not the first. A system secure against the policy clock is secure against predictable deadlines; a system secure against the adversary clock is secure regardless of which decade the capability arrives. Zentalk's design targets the adversary clock.

What the industry actually has

A survey of mainstream messaging and transport protocols as of 2026:

  1. TLS 1.3: Hybrid X25519-Kyber is specified and increasingly deployed, with Chrome and Cloudflare leading rollout. Most TLS endpoints still use classical-only key exchange.
  2. Signal Protocol: PQXDH (post-quantum X3DH) was introduced in 2023, adding Kyber to the initial handshake. Ongoing sessions and older deployments remain classical-only.
  3. WhatsApp: No public post-quantum deployment.
  4. Telegram: No public post-quantum deployment.
  5. SSH: Hybrid post-quantum is available in OpenSSH but is not yet the default on most systems.
  6. Web browsers: Kyber-integrated TLS is available in Chrome, Firefox, Edge.
  7. Enterprise VPN: Largely classical; post-quantum options emerging in niche vendors.

The pattern is uneven. The leading-edge systems have started. The mainstream has not, or has started in narrow components. The long tail of deployed systems — embedded devices, corporate VPNs, legacy enterprise software — is largely untouched and will be the expensive, slow part of migration.

Zentalk's current state

Zentalk's handshake, signatures, and key derivation use hybrid constructions combining classical primitives (X25519, Ed25519) with NIST-standardized post-quantum primitives (ML-KEM based on Kyber-768, ML-DSA based on Dilithium-3). Every session, by default, is protected by both. This is in production today. Users do not opt in. The migration clock, for Zentalk users, is not running; they are already on the other side of it.

The 2026–2028 roadmap

Being post-quantum does not mean being done. The cryptographic landscape continues to evolve, and Zentalk's roadmap covers the next phase of hardening and extension.

2026: Consolidation

The current hybrid stack remains the baseline. Engineering focus shifts to audit coverage: independent third-party audits of the post-quantum integration, formal verification of critical code paths, and cryptanalytic review of the specific parameter choices. The goal is defense-in-depth not just in the protocol but in the confidence the protocol is worth trusting.

The routing layer currently uses RSA-4096-OAEP per relay hop. Whether that layer will receive a parallel post-quantum encapsulation path is per the 2026 whitepaper (to verify); any such migration would follow the same phased model — opt-in, then default, then sole option — already established for the message-encryption layer.

2027: Signature modernization

Current validator signatures use Dilithium-3. The standard is sound, but signature sizes (roughly 3 KB) are a meaningful fraction of block overhead at scale. The 2027 roadmap evaluates whether hash-based signatures (SLH-DSA) should replace Dilithium for specific high-volume use cases where the per-signature cost matters more than the more compact Dilithium output.

Hash-based signatures have the advantage of being based on extremely conservative assumptions (only the security of the hash function), at the cost of larger signatures (tens of kilobytes). For long-lived archival signatures that must remain credible against future cryptanalytic progress, the conservatism is worth the size.

2028: Full hybrid maturation

By 2028, the expectation is that classical primitives are transitioning from the primary to the backup role in most key exchanges. If Kyber-based encapsulation has survived five additional years of cryptanalysis without incident, the hybrid construction shifts its emphasis: Kyber as primary, X25519 as backup, with an option to disable the classical half entirely for users who judge the quantum threat to be the dominant concern.

The migration of the wider internet continues. Zentalk's role at this point is to demonstrate that a fully post-quantum stack is not an experiment; it is a production system carrying real traffic for real users, with a multi-year track record of reliable operation.

The competitive picture

In the decentralized-messaging space, Zentalk's post-quantum posture is ahead of comparable products. In the centralized-messaging space, Signal Protocol's PQXDH is the strongest comparable deployment. Most other competitors — Telegram, standard WhatsApp configurations, enterprise messengers — have made no visible post-quantum commitments.

This is not a criticism. It is a description. Migration is expensive, requires deep engineering, and produces no visible feature benefit to users today. The decision to invest in it early reflects a specific view of what the threat model requires. Zentalk's view is that a messenger built for privacy that does not address the adversary clock is incomplete, and that shipping hybrid from day one was the only position consistent with the product's stated purpose.

What users should watch

The migration clock is public, but the adversary clock is not. Users whose threat models include state-level adversaries should plan on the more conservative timeline. Users whose threat models are more modest can tolerate a slower industry migration with less immediate consequence.

For either group, the useful check is the same: does the system you are trusting use a hybrid post-quantum construction, and has it been audited? For mainstream systems, the answer is increasingly yes; for the long tail, the answer is still no. The migration is underway. Any system that has not begun seriously by the mid-2030s — the NSA CNSA 2.0 completion deadline — will find the engineering effort larger than budgeted, the user base moved on, and the competitive landscape already decided.

The clock is not theoretical. It is running. Zentalk's roadmap is designed around the clock that is actually running, not the one that looks comfortable on a slide.

  Thanks & Best Regards Zentachain Team!

Keep exploring

The network grows with the people using it.

Private communication, node hardware and the CHAIN economy — built since 2018.

TaggedZentalk
Keep reading

Related articles

Zentachain

Zentachain

Decentralized communication infrastructure. Trust math, not servers. Building the future of privacy, connectivity, and digital sovereignty.

Zentalk

© 2026 Zentachain LLC

All Rights Reserved