ML-DSA Explained: Post-Quantum Digital Signatures and FIPS 204
What digital signatures do, why quantum computers threaten them, and how ML-DSA (FIPS 204) and hybrid Ed25519 + ML-DSA-65 signatures protect identity.
Most conversations about quantum computers and cryptography focus on secrecy: will someone be able to read my messages? That is the right place to start, but it is only half of the story. The other half is identity. Before you encrypt anything, you need to know whose key you are encrypting to. That question is answered by digital signatures, and signatures are just as exposed to quantum attack as encryption.
This article explains what digital signatures do, why the ones in common use today are vulnerable, what NIST's new standard ML-DSA changes, and why VOIDEX signs identities with a hybrid of Ed25519 and ML-DSA-65.
What a digital signature does
A digital signature is a mathematical proof that a specific private key approved a specific piece of data. Anyone holding the matching public key can check the proof. If a single bit of the data changes, or if the proof was made with a different key, the check fails.
That simple property carries an enormous amount of weight in modern computing:
- Software updates are signed so your device installs only code from the real vendor.
- Websites present certificates signed by certificate authorities, which is how your browser knows it has reached your bank and not an impostor.
- Messaging apps sign identity keys and device keys, so that when your contact's phone offers a key, your phone can confirm it really belongs to them.
Encryption keeps outsiders from reading. Signatures stop outsiders from pretending. A system with perfect encryption and forgeable signatures can be defeated simply by tricking you into encrypting to the attacker.
Why quantum computers threaten signatures
The signature schemes used almost everywhere today, RSA signatures, ECDSA and EdDSA schemes such as Ed25519, rely on problems that are hard for classical computers: factoring large numbers and computing discrete logarithms on elliptic curves. A large, fault-tolerant quantum computer running Shor's algorithm would solve both.
Estimates of when that becomes possible have been falling. In May 2025, Craig Gidney of Google Quantum AI estimated that RSA-2048 could be broken with fewer than one million noisy qubits in under a week, down from roughly twenty million in a 2019 estimate. Later work has pushed estimates for elliptic-curve attacks lower still, as summarised in Q-Day in 2026.
There is one important difference between signatures and encryption. For encryption, the danger starts today, because an adversary can record ciphertext now and decrypt it later, the problem known as harvest now, decrypt later. For signatures, an attacker gains nothing from recording old signatures. The danger arrives on the day a quantum computer can forge new ones.
That might sound like a reason to wait. It is not. Signature keys are baked into long-lived systems: device identities, root certificates, firmware, archives and legal records. Replacing them takes years, and anything still relying on classical signatures when that day comes can be impersonated. This is why NIST's draft transition guidance, NIST IR 8547, proposes deprecating quantum-vulnerable algorithms, including classical signatures, after 2030 and disallowing them after 2035.
ML-DSA and FIPS 204
On 13 August 2024, NIST finalised its first three post-quantum standards. FIPS 203 defines ML-KEM for key establishment. FIPS 204 defines ML-DSA, the Module-Lattice-Based Digital Signature Algorithm. FIPS 205 defines SLH-DSA, a hash-based signature scheme intended as a conservative alternative.
ML-DSA is derived from CRYSTALS-Dilithium, one of the winners of NIST's multi-year public competition. Its security rests on lattice problems, structured mathematical puzzles for which no efficient quantum algorithm is known. It was chosen as the primary general-purpose signature standard because it balances security, speed and implementation simplicity well.
FIPS 204 defines three parameter sets, each aimed at a different security level:
- ML-DSA-44, targeting NIST security category 2.
- ML-DSA-65, targeting category 3, broadly comparable to the security of AES-192.
- ML-DSA-87, targeting category 5, broadly comparable to AES-256.
The trade-off: size
Post-quantum signatures are larger than the ones they replace. An Ed25519 public key is 32 bytes and a signature is 64 bytes. Under FIPS 204, an ML-DSA-65 public key is 1,952 bytes and a signature is 3,309 bytes. For a messaging app signing identities and device keys, that is entirely manageable. For systems that send thousands of signatures per second over constrained links, it requires careful engineering. Signing and verification with ML-DSA are fast, so the cost is mainly in bytes, not in time.
Where ML-DSA sits among the alternatives
ML-DSA is not the only post-quantum signature NIST standardised. SLH-DSA, in FIPS 205, builds signatures entirely from hash functions. Its security assumptions are about as conservative as cryptography gets, since it relies only on the strength of the hash, but its signatures are considerably larger and slower to produce. That makes it attractive for rarely changed, high-value keys such as firmware roots, and less practical for identities that sign often. ML-DSA occupies the middle ground: modern, efficient, and designed to replace classical signatures in everyday protocols. Having two standards built on unrelated mathematics is itself a safeguard for the whole ecosystem.
Why hybrid signatures
ML-DSA is new as a standard, even if the mathematics behind it has been studied for years. Classical schemes like Ed25519, specified in RFC 8032, have a long record in real systems. Hybrid signing uses both at once: a message or key is signed with Ed25519 and with ML-DSA, and a verifier accepts it only if both signatures check out.
The logic mirrors hybrid post-quantum encryption. An attacker who wants to forge a hybrid signature has to break both schemes. If a flaw is ever found in the newer lattice-based scheme or its implementations, Ed25519 still stands. If a quantum computer breaks Ed25519, ML-DSA still stands. You give up a few kilobytes and gain protection against two very different kinds of failure.
How VOIDEX uses ML-DSA
In VOIDEX, identity signatures are hybrid Ed25519 and ML-DSA-65. That choice matters because the whole security of VOIDEX Messenger rests on knowing that a key belongs to the person you think it does.
Direct messages begin with a hybrid post-quantum key agreement, X25519 combined with ML-KEM-768, and run on a double ratchet with post-quantum re-keying, so each message has its own key. Groups and private VOIDEX Channels use MLS, RFC 9420. All of that protects secrecy. The hybrid signatures protect the other half: they make it much harder for anyone, now or after the arrival of large quantum computers, to pass off a forged identity or device key.
VOIDEX applies the same hybrid signatures to key transparency. Every device key change is appended to a public, append-only Merkle log, and the tree heads of that log are signed with Ed25519 and ML-DSA-65. Clients check keys against the log and refuse keys that are not in it, anyone can audit it through public endpoints, and an independent witness watches it. A log is only as trustworthy as the signatures on its heads, so signing them in a way that survives quantum attack keeps the whole audit trail meaningful. The details are in key transparency.
The cryptographic core is open source at github.com/voidexbycnota/voidex-crypto, and the design is documented in the public security report, so these choices can be checked rather than taken on faith.
What to take away
Signatures are the part of cryptography people notice least, because when they work nothing happens. Your update installs, your page loads, your contact's key checks out. Their failure would be loud: convincing impersonation of devices, services and people.
ML-DSA gives the world a standardised, well-studied way to sign that does not collapse in the face of quantum computers. Pairing it with Ed25519 adds a second lock of a completely different design. For any system that expects to protect identities into the 2030s, that is the prudent path.
VOIDEX is invite-only. Request access to join a network where identities are signed for the quantum era, or read how VOIDEX protects keys and identities.
Sources
- NIST FIPS 204: Module-Lattice-Based Digital Signature Standard
- NIST FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard
- NIST FIPS 205: Stateless Hash-Based Digital Signature Standard
- NIST Post-Quantum Cryptography Standardization
- NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards
- Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits (2025)
- RFC 8032: Edwards-Curve Digital Signature Algorithm (EdDSA)
- RFC 9420: The Messaging Layer Security (MLS) Protocol
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



