Cloudflare introduced CryptoLabe, an internal AI-assisted cryptographic discovery and inventory system supporting its goal of complete post-quantum readiness by 2029. The platform examines immutable, read-only snapshots of repositories and related configurations, manifests, scripts, tests, documentation, tickets, and dependencies to locate cryptographic implementations, assess runtime context, classify findings, and surface migration dependencies. It distinguishes conventional encryption, signatures, and JWT deployments from post-quantum-ready mechanisms, including TLS 1.3 X25519MLKEM768 hybrid key exchange and ML-DSA.
The company said CryptoLabe is intended to prioritize engineering work rather than provide definitive coverage: findings must be validated by system owners because Cloudflare has no ground-truth dataset to measure prompt performance. The inventory has highlighted difficult dependencies, including insufficient library and issuer support for post-quantum JWTs, absent post-quantum SAML support, and HTTP header certificate-size limits. JWTs, standardized in RFC 7519 as signed, MACed, and/or encrypted JSON claims containers, remain a significant migration concern because their security depends on context-appropriate cryptographic protection and interoperable issuer and verifier support.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
The IETF published RFC 7519 as a Standards Track specification defining JWTs, including signed, MACed, encrypted, nested, and unsecured token forms, registered claims, validation procedures, and implementation requirements.
Cloudflare developed CryptoLabe, an internal AI-assisted cryptographic inventory tool that scans repositories and related data to identify cryptography, assess post-quantum readiness, and surface migration blockers. The company uses it to support a target of complete post-quantum readiness by 2029, while requiring engineering teams to validate findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.