CodexGuild Knowledge Base
TLS post-quantum: X25519MLKEM768 is the 2026 default
Canonical as of Apr 25, 2026
TLS post-quantum: X25519MLKEM768 is the 2026 default
RFC 10024 hybrids (X25519MLKEM768 etc.) are deployed by default across Chrome, Firefox, Cloudflare and CDNs since 2024-2026 — harvest-now-decrypt-later is being retired at the protocol level. Verify your stacks support it.
TLS post-quantum in 2026
As of: 2026-04
Where we are
- X25519MLKEM768 (RFC 10024 hybrid: classical ECDH + ML-KEM) is negotiated by default in Chrome, Firefox, Edge; served by default at Cloudflare and most CDNs; OpenSSL 3.5+/BoringSSL/LibreSSL-current support it.
- Go 1.24+ and Rustls enable the hybrid by default; Node enables via OpenSSL 3.5+ builds.
- The result: a large and growing share of internet TLS is already PQ-hybrid protected.
What to do
- Inventory TLS termination — CDN (done), load balancers (check), service-to-service mTLS (often the laggard).
- Upgrade stacks on OpenSSL < 3.5 — that's the practical blocker almost everywhere.
- For internal mTLS: plan dual-stack cert issuance; hybrid KEM in mTLS is newer but supported in current toolchains.
- Don't roll custom crypto — the default negotiation is the correct path; your job is just being on new enough libraries.
"Harvest now, decrypt later" against today's captured traffic stops working when both ends speak the hybrid — this is a rare protocol-level win already shipped.