ML-KEM-768 Explained: The Post-Quantum Lock Inside Your Messages
A clear guide to ML-KEM-768, the NIST FIPS 203 post-quantum key encapsulation standard: lattices, key sizes, security level, and how VOIDEX uses it.
Every encrypted conversation begins with a small miracle. Two devices that have never shared a secret manage to agree on one while every byte they exchange is visible to anyone watching. For most of the internet's history, that miracle has been performed by elliptic-curve mathematics. From now on, it increasingly relies on a newer idea with a less friendly name: ML-KEM-768.
ML-KEM-768 is the post-quantum algorithm at the heart of VOIDEX Messenger's key agreement. This guide explains what it is, why it resists quantum computers, what "768" means, and how VOIDEX combines it with classical cryptography. No mathematics degree required.
The problem ML-KEM solves
Encrypting a message is the easy part. Modern symmetric ciphers such as AES are fast and extremely strong. The hard part is getting the same secret key onto both devices without an eavesdropper learning it.
Public-key cryptography solves this. Each side has a public key it can share openly and a private key it keeps. The widely used method today, X25519, is a form of Diffie-Hellman key agreement on an elliptic curve. It is elegant and efficient, but it has one fatal weakness: a large quantum computer running Shor's algorithm could recover the shared secret from the public values. Anyone recording traffic today could decrypt it on that day, which is the threat we describe in Harvest Now, Decrypt Later.
ML-KEM exists to do the same job, agreeing on a shared secret over an open channel, using mathematics for which no efficient quantum attack is known.
From Kyber to FIPS 203
ML-KEM began life as CRYSTALS-Kyber, one of dozens of submissions to a public competition NIST opened in 2016. After three rounds of analysis by cryptographers around the world, Kyber was selected in 2022. On 13 August 2024, NIST published the final standard as FIPS 203, renaming it the Module-Lattice-Based Key-Encapsulation Mechanism, or ML-KEM.
The name is dry but precise. "Module-lattice" describes the mathematics. "Key encapsulation mechanism" describes how it is used. Both are worth understanding.
Lattices, in one picture
Imagine an infinite grid of points in space, like the corners of stacked boxes stretching forever. That is a lattice. In two dimensions it is easy to look at a random point and say which grid point is closest. Now imagine the grid in hundreds of dimensions, slightly skewed, and described by a set of awkward, tilted directions. Finding the nearest grid point becomes extraordinarily hard.
ML-KEM builds on a closely related problem called Module Learning With Errors (Module-LWE). Loosely, you are given a large set of equations that would be easy to solve, except that each one has had a small random error added. Without the secret, separating the signal from the noise is believed to be hard for classical and quantum computers alike. With the secret, it is trivial.
That asymmetry is what every public-key system needs: easy with the key, hard without it. What makes lattices special is that decades of research, including by quantum algorithm specialists, have produced no quantum shortcut comparable to what Shor's algorithm does to factoring and discrete logarithms.
The "module" part is an efficiency trick. Instead of working with huge unstructured matrices, ML-KEM works with small grids of polynomials, which keeps keys compact and operations fast.
What "key encapsulation" means
Diffie-Hellman is symmetrical: both sides contribute and both compute the same result. A key encapsulation mechanism works more like a sealed envelope.
- Key generation. The recipient creates a key pair and publishes the public key.
- Encapsulation. The sender uses that public key to generate a fresh random shared secret and a ciphertext, which is that secret sealed so only the recipient can open it. The sender keeps the secret and sends the ciphertext.
- Decapsulation. The recipient uses the private key to open the ciphertext and recover the same shared secret.
Both sides now hold an identical 32-byte secret that never travelled across the network in readable form. That secret is then fed into a key derivation function to produce the keys that actually encrypt messages.
One subtle property matters in practice. If someone tampers with an ML-KEM ciphertext, decapsulation does not return an error. It returns a different, unrelated value, a design called implicit rejection that prevents attackers from learning anything from failures. Protocols built on ML-KEM therefore have to confirm that both sides really derived the same key, which well-designed messengers do by checking that the first message decrypts correctly.
What the 768 means: security levels
FIPS 203 defines three parameter sets: ML-KEM-512, ML-KEM-768 and ML-KEM-1024. The numbers loosely reflect the size of the underlying lattice. Larger means more security and larger keys.
NIST maps them to security categories defined against well-understood symmetric primitives:
- ML-KEM-512: Category 1, comparable in difficulty to breaking AES-128.
- ML-KEM-768: Category 3, comparable to breaking AES-192.
- ML-KEM-1024: Category 5, comparable to breaking AES-256.
ML-KEM-768 is the parameter set that most of the industry has converged on for general use. It carries a comfortable margin above the minimum while keeping message sizes practical. It is the choice in Signal's post-quantum ratchet, in Apple's PQ3 for iMessage, and in the hybrid `X25519MLKEM768` key exchange that major browsers now use for TLS.
How big is it?
Post-quantum security costs bytes. Here is the scale for ML-KEM-768, from FIPS 203:
- Public (encapsulation) key: 1,184 bytes
- Ciphertext: 1,088 bytes
- Shared secret: 32 bytes
For comparison, an X25519 public key is 32 bytes. ML-KEM keys are roughly thirty-five times larger. That sounds dramatic until you remember that a single photo in a chat is often several hundred thousand bytes. For messaging, the overhead is noticeable to engineers and invisible to people.
Speed is not the concern many expect. ML-KEM operations are fast, often comparable to or quicker than elliptic-curve operations on modern hardware, because they rely on simple polynomial arithmetic rather than expensive curve maths.
Why not use ML-KEM alone?
ML-KEM is young by cryptographic standards. Lattice problems have been studied for decades, and Kyber survived years of intense public scrutiny, but X25519 has an even longer track record in real-world deployment. Implementation details also matter: a correct algorithm can still be undermined by a flawed implementation.
The cautious answer, adopted by Signal, Apple, browser vendors and VOIDEX, is hybrid key exchange. Combine a classical algorithm and a post-quantum one so that an attacker has to break both. We make the full case, including the cautionary tale of SIKE, in Why hybrid post-quantum encryption wins.
How VOIDEX uses ML-KEM-768
In VOIDEX Messenger, every direct conversation starts with a PQXDH-style handshake that combines X25519 and ML-KEM-768. Both contribute to the shared secret, and the derived keys depend on both. Recording that handshake and breaking only one of the two gives an attacker nothing useful.
The handshake is only the beginning. VOIDEX then runs a double ratchet with post-quantum re-keying, so fresh key material keeps entering the conversation and each message is encrypted with its own key. That is what provides forward secrecy and post-compromise security, which we explain in Forward secrecy and the double ratchet.
Identity is protected too. Device identities are signed with hybrid Ed25519 plus ML-DSA-65, where ML-DSA is the lattice-based signature standard published alongside ML-KEM as FIPS 204. And every device key is written to a public, append-only key transparency log, so a server cannot quietly substitute a key it controls.
All keys are created on members' own devices. VOIDEX servers store public keys and ciphertext, never private keys. The cryptographic core is published as open source, and the design is documented in the public VOIDEX security report, so anyone with the expertise can check that ML-KEM-768 is used the way we say.
What ML-KEM does not do
It is worth being precise about limits, because good cryptography is never magic.
- ML-KEM protects key agreement. It does not by itself authenticate who you are talking to. That is the job of signatures and verification.
- It does not hide metadata such as when you are online or who you talk to. That requires separate design choices.
- It does not protect content you choose to publish. On VOIDEX, public posts in VOIDEX Space and Public channels are meant to be seen and are clearly labelled as not end-to-end encrypted.
The takeaway
ML-KEM-768 is not a futuristic experiment. It is a finalised federal standard, based on well-studied lattice mathematics, sized for real-world use and already deployed by some of the most careful engineering teams in the world. Its job is simple to state: make sure that a conversation recorded today stays unreadable even when quantum computers arrive.
On VOIDEX, that protection is on by default in every direct message, paired with classical cryptography so that neither half has to be perfect.
VOIDEX is invite-only. If you want messages built for the next thirty years, request access, or read the full VOIDEX security design.
Sources
- NIST FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (13 August 2024): https://csrc.nist.gov/pubs/fips/203/final
- NIST Post-Quantum Cryptography Standardization project: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
- Signal, "SPQR: Signal's post-quantum ratchet" (October 2025): https://signal.org/blog/spqr/
- Apple Security Research, "iMessage with PQ3" (February 2024): https://security.apple.com/blog/imessage-pq3/
- Google Security Blog, "A new path for Kyber on the web" (September 2024): https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



