IETF RFC 10024 establishes three hybrid post-quantum TLS 1.3 key-agreement groups that combine ML-KEM with elliptic-curve Diffie-Hellman. X25519MLKEM768 is the only group designated Recommended in IANA’s TLS Supported Groups registry; NIST-curve variants remain available for compliance-focused deployments. The standard formalizes an approach already used by browsers, CDNs, and TLS libraries and discourages use of earlier Kyber768 draft code points, reducing a standards barrier to mitigating harvest-now-decrypt-later exposure.
Cloudflare has deployed Automatic Key Exchange to probe origin-server capabilities and select the strongest mutually supported TLS 1.3 group, prioritizing X25519MLKEM768. The rollout increased post-quantum traffic across scanned origins from roughly 25 billion to 45 billion daily connections, with 99.2% of post-quantum handshakes completing in one network round trip; retry-dependent handshakes fell from about 52% to 3.7%, cutting 90th-percentile handshake latency by more than 150 ms. Organizations still need origins that support X25519MLKEM768 to receive end-to-end hybrid key-establishment protection, while post-quantum TLS authentication remains constrained by limited public WebPKI support for ML-DSA certificates and trusted roots.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
The IETF published RFC 10024 as a Proposed Standard defining X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 hybrid TLS 1.3 key-agreement groups. IANA marked X25519MLKEM768 as Recommended and relabeled the earlier Kyber768 draft groups as obsolete and discouraged.
Executive Order 14412 required U.S. federal civilian agencies to migrate high-value assets and high-impact systems to post-quantum key establishment by the end of 2030 and to post-quantum digital signatures by the end of 2031.
More than two-thirds of human-initiated TLS traffic to Cloudflare negotiated a hybrid post-quantum key exchange.
Chrome enabled X25519MLKEM768 by default starting with Chrome 131.
Firefox enabled the hybrid X25519MLKEM768 TLS key-agreement group by default beginning with Firefox 132.
NIST finalized the ML-KEM post-quantum key-encapsulation mechanism in FIPS 203.
Cloudflare began deploying hybrid key exchange at its edge using the experimental X25519Kyber768Draft00 group.
Cloudflare began automatically probing TLS 1.3-capable origins and selecting the strongest mutually supported key-exchange algorithm, prioritizing X25519MLKEM768. During rollout, post-quantum traffic among scanned origins rose from about 25 billion to 45 billion daily connections and retry-required handshakes fell from about 52% to 3.7%.
After its earlier experimental Kyber deployment, Cloudflare adopted the standardized X25519MLKEM768 hybrid key-exchange group.
rustls 0.23.44 enabled ML-DSA certificate verification by default for private-PKI use cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
postquantum.com
Open sourcesdxcentral.com
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.