Post-quantum cryptography support has been added to Python through the widely used pyca/cryptography library, bringing NIST-standard algorithms into the ecosystem ahead of broader migration pressure. The update introduces ML-KEM for key establishment and ML-DSA for digital signatures, giving Python developers access to standardized post-quantum primitives as organizations prepare for future quantum-era risks.
Trail of Bits reported shipping the capability with funding from the Sovereign Tech Agency, while subsequent coverage highlighted the move as a practical step toward greater crypto agility in mainstream software. The addition is intended to help developers begin testing, integrating, and planning for post-quantum transitions now, rather than waiting for an emergency replacement cycle once quantum threats become more immediate.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Trail of Bits reported that the Python ecosystem now has post-quantum cryptography support through the pyca/cryptography library, including ML-KEM and ML-DSA. The work was funded by the Sovereign Tech Agency and was presented as a step toward crypto agility.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.