VOIDEXJournal

Hybrid Post-Quantum Encryption: Why Two Locks Beat One Right Now

Why combining classical and post-quantum cryptography is the safest choice during the transition, what SIKE's 2022 collapse taught us, and how VOIDEX does it.

By the VOIDEX team · 7 min read · 2026-09-29
Hybrid Post-Quantum Encryption: Why Two Locks Beat One Right Now

Security engineering has an old rule: never bet everything on one assumption. The post-quantum transition is where that rule matters most. The cryptography that has protected the internet for decades is known to fall to a large quantum computer. The cryptography designed to replace it is newer, and newer means less tested.

The answer adopted by the most careful teams in the industry is hybrid encryption: run a proven classical algorithm and a new post-quantum algorithm together, so that an attacker has to break both. VOIDEX uses this approach for both key agreement and identity. This article explains why, using one of the most instructive failures in modern cryptography.

Two ways to be wrong

During the transition, a security designer faces two distinct risks.

Risk one: quantum computers arrive. Classical public-key cryptography such as X25519, ECDSA and RSA relies on problems that Shor's algorithm solves efficiently on a large quantum computer. If you use only classical algorithms, a future machine can read what you encrypted today. Research published in 2025 and 2026 has lowered the estimated size of that machine considerably, as we describe in Q-Day in 2026.

Risk two: the new algorithm is flawed. Post-quantum schemes are built on mathematics that has been studied for less time in real deployment. A new algorithm might have an undiscovered mathematical weakness, or an implementation might leak secrets through timing or error handling. If you use only post-quantum algorithms, a single breakthrough could expose everything even without a quantum computer.

Pure classical protects you against the second risk and leaves you exposed to the first. Pure post-quantum does the opposite. Hybrid protects against both, because breaking the combination requires defeating each component.

The cautionary tale of SIKE

If the second risk sounds theoretical, consider SIKE.

SIKE (Supersingular Isogeny Key Encapsulation) was a post-quantum key exchange based on a sophisticated branch of mathematics involving maps between elliptic curves. It was elegant and compact, with some of the smallest keys of any post-quantum candidate. It reached the fourth round of NIST's standardisation process and had attracted serious interest from industry, including large technology companies that had experimented with it.

In July 2022, Wouter Castryck and Thomas Decru of KU Leuven published an attack that recovered SIKE's secret key using a classical computer. The version targeting NIST's lowest security level fell in about an hour on a single processor core. No quantum computer was involved. The attack drew on a mathematical result from 1997 that had simply not been connected to SIKE before.

SIKE was not alone that year. Earlier in 2022, Ward Beullens published a practical key-recovery attack on Rainbow, a post-quantum signature scheme that had been a finalist in NIST's process, reporting that it could be broken over a weekend on a laptop.

The lesson is not that post-quantum cryptography is untrustworthy. ML-KEM and ML-DSA rest on lattice problems with a much longer and deeper research history, and they survived years of public attack before standardisation. The lesson is humility. Candidates that looked solid to experts were broken with ordinary computers. Any system that had deployed SIKE on its own would have been completely exposed. Any system that deployed SIKE in a hybrid with X25519 would have lost nothing, because X25519 was still standing.

How hybrid key exchange works

A hybrid key exchange runs two key agreements in parallel and combines their outputs.

  1. The devices perform a classical exchange, for example X25519, producing one shared secret.
  2. They perform a post-quantum key encapsulation, for example ML-KEM-768, producing a second shared secret.
  3. Both secrets are fed together into a key derivation function, which produces the final session keys.

Because the final key depends on both inputs, an attacker who learns only one of them learns nothing useful about the result. A quantum computer that breaks X25519 still faces ML-KEM-768. A mathematical breakthrough against ML-KEM still faces X25519. The combination is at least as strong as the stronger of the two parts.

The costs are modest. The post-quantum half adds a little over a kilobyte to each handshake, which we detail in ML-KEM-768 explained, and the classical half is almost free. For messaging, where a single photo is far larger, the overhead is not something anyone notices.

The industry has converged on hybrid

This is not a niche position. It is where the leading implementations have landed:

  • Signal introduced PQXDH in 2023, combining X25519 with a post-quantum KEM, and in October 2025 added ML-KEM-768 to its ongoing ratchet with SPQR.
  • Apple built iMessage PQ3 (February 2024) on a hybrid design combining elliptic-curve and post-quantum key establishment.
  • Web browsers adopted hybrid key exchange for TLS. Google moved Chrome from an early Kyber hybrid to the standardised `X25519MLKEM768` in late 2024, as it explained on its security blog.

Some European security agencies have gone further and recommended hybrid use of post-quantum algorithms during the transition. The broad consensus among practitioners is the same: until post-quantum schemes have accumulated years of real-world deployment, pair them with something proven.

Hybrid signatures: protecting identity too

Key exchange protects confidentiality. Signatures protect identity, meaning the assurance that the key you are encrypting to really belongs to the person you think it does.

Signatures face a different quantum timeline. A recorded signature cannot be retroactively forged in a way that decrypts old messages, so harvest now, decrypt later applies less directly. But identity keys are long-lived, and a system that plans to be trustworthy for decades should not tie its identity layer entirely to elliptic curves. Hybrid signatures follow the same logic as hybrid key exchange: a signature is only accepted if both the classical and post-quantum signatures verify.

The main cost is size. ML-DSA-65, the mid-level parameter set in FIPS 204, has signatures of 3,309 bytes and public keys of 1,952 bytes, against 64 and 32 bytes for Ed25519. For identity keys that are verified occasionally rather than on every message, that is an easy trade.

How VOIDEX combines them

VOIDEX applies the hybrid principle at every layer where public-key cryptography protects private communication.

Key agreement: X25519 plus ML-KEM-768. Every direct conversation in VOIDEX Messenger begins with a PQXDH-style handshake that combines both algorithms. The session keys are derived from both secrets, so a recorded handshake stays protected unless an attacker breaks both.

Ongoing protection: a ratchet with post-quantum re-keying. After the handshake, a double ratchet derives a new key for every message, and post-quantum re-keying keeps adding fresh material. That provides forward secrecy and post-compromise security, so a single stolen key cannot unlock a whole conversation. We explain the mechanism in Forward secrecy and the double ratchet.

Identity: Ed25519 plus ML-DSA-65. Device identities are signed with both, so proving who owns a device does not rest on elliptic curves alone.

Transparency: signed with both as well. VOIDEX records every device key change in a public, append-only key transparency log. The log's signed tree heads carry both an Ed25519 and an ML-DSA-65 signature.

Groups and private VOIDEX Channels use MLS (RFC 9420). Keys are generated on members' own devices, and VOIDEX servers hold only public keys and ciphertext. The cryptographic core is open source, and the full design is laid out in the VOIDEX security report, so the claims in this article can be checked rather than trusted.

When does hybrid end?

Eventually, the classical half may become unnecessary. Once post-quantum algorithms have many years of deployment, once implementations are mature, and once quantum computers make classical algorithms pointless, a purely post-quantum design may be the natural choice. NIST's draft IR 8547 proposes disallowing quantum-vulnerable algorithms after 2035.

We are not there. In 2026, the honest position is that both risks are real: quantum computers are getting closer, and new cryptography still earns trust slowly. Two locks cost almost nothing. Choosing one and being wrong could cost everything.

The takeaway

Hybrid encryption is not indecision. It is the professional response to uncertainty in both directions. SIKE showed how quickly a respected post-quantum candidate can fall. Shor's algorithm shows that the classical world has an expiry date. Combining them buys protection against the failure of either.

VOIDEX is invite-only. Ask for an invitation, or review the complete VOIDEX encryption design first.

Sources

  • Castryck, W. and Decru, T. "An efficient key recovery attack on SIDH" (2022): https://eprint.iacr.org/2022/975
  • Beullens, W. "Breaking Rainbow Takes a Weekend on a Laptop" (2022): https://eprint.iacr.org/2022/214
  • Signal, "SPQR: Signal's post-quantum ratchet" (October 2025): https://signal.org/blog/spqr/
  • Apple Security Research, "iMessage with PQ3" (February 2024): https://security.apple.com/blog/imessage-pq3/
  • Google Security Blog, "A new path for Kyber on the web" (September 2024): https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html
  • NIST FIPS 204, Module-Lattice-Based Digital Signature Standard (August 2024): https://csrc.nist.gov/pubs/fips/204/final
  • NIST IR 8547 (initial public draft, November 2024): https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  • RFC 9420, The Messaging Layer Security Protocol: https://www.rfc-editor.org/rfc/rfc9420

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps