Cloudflare and Google are developing Merkle Tree Certificates (MTCs) to bring post-quantum resilience to WebPKI authentication without the impractically large TLS certificate chains produced by conventional quantum-safe signatures. Under the proposed design, a certificate authority adds certificates to an append-only Merkle tree, signs a checkpoint representing potentially millions of certificates, and supplies a compact inclusion proof; TLS handshake data is expected to remain near 40 KB. Certificate Transparency is built into issuance, with an independent mirror cosigning log state, aiming to reduce exposure to rogue certificates and forged transparency records.
Cloudflare is building a CA that will issue both conventional certificates and MTCs, using ACME and a fork of Boulder for validation and issuance, plus Azul and the C2SP tlog-mirror protocol for log mirroring. A Chrome Beta 146 experiment covering 50% of users and free-plan domains found landmark-based MTC handshakes had a 9% median speed improvement over classical chains, though it used classical signatures and benefited partly from removing an intermediate certificate. MTC remains an IETF PLANTS Internet-Draft, and Cloudflare must enter Chrome's Quantum-resistant Root Store before trusted production deployment; it plans initial issuance in Q1 2027 and advises continued Certificate Transparency monitoring for legacy certificates that could enable downgrade paths.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The 2011 compromise of Dutch certificate authority DigiNotar enabled issuance of roughly 500 counterfeit certificates for Google and other websites. Some were used to surveil web users in Iran, helping spur certificate-transparency programs.
Cloudflare reported a deployment to 50% of Chrome Beta 146 users that issued billions of Merkle Tree Certificates for free-plan domains. Landmark-based handshakes showed a reported 9% median speed improvement over classical certificate chains, though the test used classical signatures and benefited partly from omitting an intermediate certificate.
Google announced a Merkle Trees-based approach intended to make WebPKI certificates resistant to future quantum attacks, avoiding the overhead of replacing every certificate-chain signature with a post-quantum signature.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.