lattice
Y2Q warning — quantum computers will break RSA & ECDSAtime to quantum 2029 · migrate to lattice
threat: high 48,210 keys get a key
post-quantum security · mainnet

keys the quantumage can't break.

Lattice is a post-quantum security layer — quantum-resistant keys, signatures, and encryption for every chain, wallet, and agent, so your crypto survives the day a quantum computer breaks ECDSA.

48,210 keys issued · 11.9M signatures · Y2Q 2029

● livequantum threat scan · key #77812shor · grover
RSA-2048✗ brokenshor, 4,000 qubits
ECDSA · secp256k1✗ brokenshor, 2,330 qubits
ML-KEM · kyber✓ safelattice
ML-DSA · dilithium✓ safelattice
migrate now → latticerisk high
RSA-2048 · broken at ~4,000 qubitsECDSA · broken at ~2,330 qubitsML-KEM · quantum-safeML-DSA · quantum-safemigrate before Y2QRSA-2048 · broken at ~4,000 qubitsECDSA · broken at ~2,330 qubitsML-KEM · quantum-safeML-DSA · quantum-safemigrate before Y2Q
the quantum threat

shor's algorithm
breaks your keys.

A quantum computer doesn't need your password — it factors your public key back into your private key. Here's what survives, and what doesn't.

RSA-20482,048-bit factoring
✗ broken

shor's algorithm factors it in hours on a fault-tolerant quantum computer.

ECDSA · secp256k1the key every chain uses
✗ broken

a quantum computer with ~2,330 qubits recovers your private key from the public key.

ML-KEM (kyber)lattice key encapsulation
✓ safe

no known quantum attack. standardized by NIST in 2024.

ML-DSA (dilithium)lattice signatures
✓ safe

signatures that survive shor and grover alike. NIST-standardized.

the lattice

hard problems
from neat grids.

Lattice cryptography rests on a question that's hard even for a quantum computer: given a point in a high-dimensional grid, find the closest lattice point. No quantum speedup exists — and none is expected.

lattice · 512 dimensions · closest-vector problemquantum resistance ✓ proven
what survives

the great
migration.

Every chain, wallet, and agent is running algorithms a quantum computer can break. Lattice swaps them for NIST-standardized lattice primitives — one migration, done.

purposetodayon latticestatus
signaturesECDSAML-DSA (Dilithium)post-quantum
encryptionRSA / ECIESML-KEM (Kyber)post-quantum
key exchangeECDHML-KEM (Kyber)post-quantum
hashingSHA-256SHA-256unchanged
how it works

issue, sign,
verify, migrate.

01

generate

issue a quantum-resistant key — ML-KEM for encryption, ML-DSA for signing.

keys/generate
02

sign

sign with dilithium. every signature is a proof, not a secret.

sign/dilithium
03

verify

verify anywhere — on chain, in a wallet, in an agent. open standards.

build/contracts
04

migrate

move off ECDSA before the quantum era. hybrid mode until you're ready.

build/migration
the network

3,412 validators,
quantum-safe.

A global set of validators issues keys, signs, and verifies — every signature a lattice proof, every key quantum-resistant.

live topology · 3,412 validatorsregions 28 · avg uptime 99.98%
the key vault

keys, on hardware
quantum can't touch.

Lattice keys live on verified hardware — HSMs and secure enclaves that sign with dilithium and never expose the secret.

48,210keys issued
11.9Msignatures secured
3,412validators
2029years to quantum
on the ground

the vault,
in hardware.

Photos via Pexels, credited below.

roadmap

ahead of
the quantum clock.

now
v0.4

ML-KEM keys + ML-DSA signatures live

q3 2026
hybrid mode

ECDSA + dilithium side by side for safe migration

q4 2026
hardware hsms

quantum-safe signing on secure enclaves

2027
lattice protocol v1

permissionless validators + $LAT staking on chain

faq

short
answers.

when will quantum actually break crypto?

The honest answer is 'nobody knows exactly, but the direction is clear.' Estimates cluster around the end of this decade for ECDSA. Lattice's position is simple: don't wait to find out — migrate now, while there's no rush.

why lattices?

Lattice problems — finding the closest point in a high-dimensional grid — have resisted decades of classical and quantum attack. NIST standardized lattice primitives (ML-KEM, ML-DSA) precisely because they have no known quantum speedup.

can I keep using ECDSA?

Yes, in hybrid mode. Lattice issues a dilithium signature alongside your ECDSA one, so you get quantum safety today without breaking any existing integration.

is this actually urgent?

Yes, for anything long-lived. A 'harvest now, decrypt later' attack can record your encrypted data today and crack it the moment a quantum computer exists. Secrets with a multi-year shelf life should migrate first.

the quantum clock
is already ticking.

Migrate before the era catches up with your keys. Everything else is a countdown.