Cloudflare deployed Automatic Key Exchange for TLS connections between its edge network and customer origins, replacing a universal X25519 key-agreement assumption with per-origin measurements of supported and preferred key-exchange groups. The system probes origins outside production traffic, refreshes results daily, and gradually applies learned settings with rollback controls when connection failures or retry rates increase.
For scanned origins, the change reduced TLS HelloRetryRequest rates from roughly 52% to 3.7% and cut more than 150 ms from p90 handshake latency. It also enables most compatible X25519MLKEM768 post-quantum hybrid handshakes to complete in one round trip, although legacy origins may reject the larger ClientHello key share and strict TLS compliance policies can prevent TLS 1.3 connections where no mutually permitted algorithm exists.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Cloudflare began supporting ML-DSA post-quantum signatures in Authenticated Origin Pulls and Custom Origin Trust Store in mid-2026.
Since September 2023, Cloudflare has led origin TLS handshakes with classical X25519 and used HelloRetryRequest as a safety mechanism for post-quantum upgrades, requiring capable post-quantum origins to complete a second round trip.
Cloudflare retained the Origin Post-Quantum Encryption API, but it no longer changes a zone's post-quantum key-agreement behavior.
Cloudflare introduced Compliance requirements settings that can limit origin TLS negotiations to post-quantum hybrid algorithms, FIPS-compliant algorithms, or compatible combinations. Enforcing requirements where no mutually supported algorithm exists can cause TLS 1.3 connections to fail.
Automatic Key Exchange selects X25519MLKEM768 where supported, allowing most compatible post-quantum origin handshakes to complete in one round trip. Among scanned origins, 33% moved to the hybrid exchange and the share of scanned post-quantum TLS 1.3 traffic completing without HelloRetryRequest rose from 0% to 99.2%.
Cloudflare introduced Automatic Key Exchange, which actively probes origins for supported and preferred TLS key-agreement groups and gradually deploys learned zone-level preferences with rollback protections. The system reduced HelloRetryRequests among scanned origins from roughly 52% to 3.7% and removed more than 150 ms from p90 origin-handshake latency.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.