Your encrypted data could be stolen today — and decrypted years from now. That’s the threat quantum computers pose. To keep our users protected, Surfshark has made its implementation of WireGuard, one of the VPN protocols, fully post-quantum secure. The updated WireGuard protocol is now available on iOS and macOS, with more platforms coming soon.
What are the quantum threats?
Quantum computers could enable two types of attacks on your data:
- Steal now, decrypt later — attackers collect your encrypted data today and wait until quantum computers can read it in the future.
- Real-time attacks — once quantum computers arrive, they could intercept your connection and decrypt your data on the spot.
This is possible because quantum computers excel at solving math problems that keep today’s encryption safe. As this technology improves, these attacks become realistic concerns.
Where the vulnerability actually is
When you connect to a VPN, three things happen:
- Authentication — your device verifies the server is genuine using digital certificates.
- Key exchange — your device and the server agree on a shared encryption key. It’s done using complex math problems, like factoring large numbers or solving discrete logarithms.
- Encryption — using the agreed key from earlier, a secure tunnel is created to encrypt and send your data.
Modern encryption, like AES-256, is already safe against quantum computers because the keys are too long to guess. The real weak spot is how that encryption key is created and shared.
If the key exchange isn’t secure against quantum computers, they could solve the math problems used to generate the key and decrypt data stolen today. If authentication isn’t protected, quantum computers could impersonate a VPN server and intercept your security keys in real time.
To solve both problems, you need to secure key exchange and authentication together.
What we did
A while back, we implemented post-quantum secure key exchange for our version of the WireGuard protocol. We have now added post-quantum-secure authentication, too. This was done by applying two post-quantum cryptography standards:
- ML-KEM — secures the key exchange process;
- ML-DSA — secures authentication.
The fully post-quantum-safe WireGuard is available on macOS and iOS, with additional platforms planned for the future.
How ML-KEM and ML-DSA work
Both standards are built on lattice-based cryptography — a complex, multi-dimensional grid filled with intentional noise.
ML-KEM handles key exchange. It generates a shared key from the noisy grid. Both your device and the server can work out the same key, but from the outside, extracting it means solving the lattice. Quantum computers have no shortcut for that.
ML-DSA handles authentication. The server uses its private key and the same noisy grid to create a digital signature. Then, it sends its public certificate so your device can verify the signature is real. Because of lattice-based cryptography, even quantum computers can’t forge that certificate.
True post-quantum security requires both standards working together — and that’s exactly what Surfshark now offers with WireGuard.
WireGuard and Dausos: both protected
WireGuard with full post-quantum security is available now. The same dual-standard approach was used when we built Dausos, our custom VPN protocol. Dausos is currently available on macOS and offers the same level of quantum-resistant protection.
What this means for you
With Surfshark’s post-quantum-secure WireGuard, you’re safe against “steal now, decrypt later” and future quantum attacks. Your data stays private today and years from now.
You don’t have to wait for quantum computers to become widely accessible to secure yourself against them. The protection is here now.
If you want to learn more about post-quantum security, watch this video: