Surfshark Claims First Full Post-Quantum WireGuard Implementation With ML-DSA Certificates
Surfshark says it has integrated ML-DSA certificates into WireGuard for server authentication, completing what it calls the first fully post-quantum WireGuard implementation. The feature is live on iOS, macOS, and Windows.
The company said the upgrade closes the authentication gap in post-quantum VPN security. A fully post-quantum secure VPN depends on three pillars: encryption, key exchange, and authentication. Earlier this year, Surfshark added post-quantum encryption and key exchanges, known as ML-KEM, to WireGuard. Other providers have made similar moves, and NordVPN has extended post-quantum protection across its applications, but Surfshark says fully securing authentication remains rare.
Karolis Kaciulis, leading system engineer at Surfshark, said in the report that a truly full post-quantum secure VPN rests on those three pillars. He said the industry has widely adopted quantum-safe encryption and key exchange, such as ML-KEM, while authentication remains the forgotten step. He added that many organizations, including Big Tech, hesitate because certificates for authentication are difficult to scale and currently lack a global public infrastructure for post-quantum certificates.
Authentication matters because an attacker who uses a quantum computer to break a VPN's authentication layer could perform a session takeover, impersonating the secure server as a user connects and intercepting data. Kaciulis said ignoring the last step creates a vulnerability when quantum computers become accessible. He said Surfshark took the ML-DSA standards and integrated them with its certificates into a protocol to make authorization fully quantum-resistant. By using ML-DSA certificates, he said, Surfshark completed the final pillar and achieved the first full post-quantum WireGuard implementation.
The technical milestone stems from Dausos, Surfshark's proprietary VPN protocol engineered with complete post-quantum security from the ground up. According to the report, Dausos paved the way for the WireGuard upgrade.
Surfshark is deploying a level of security that is rare in the consumer space. An evaluation by the company of 15 major tech platforms found that only two, AWS KMS and Google Cloud KMS, have actually deployed ML-DSA, and both are cloud key-management services rather than consumer applications. Apple and Microsoft have access to ML-DSA, but neither has enabled it by default in primary user-facing software such as Safari or Edge.
Kaciulis said it comes as no surprise that industry peers prioritize implementing ML-KEM key exchange before placing authentication on their engineering roadmaps. He said quantum computing poses no immediate threat today, but delaying authentication security until these machines emerge leaves connections vulnerable, which is why Surfshark is taking proactive measures to deliver complete post-quantum defense ahead of potential quantum threats.
The fully post-quantum WireGuard implementation is currently accessible to Surfshark users on iOS, macOS, and Windows. The company plans to bring support to additional platforms in future releases.