Insider Brief
Surfshark Adds ML-DSA Authentication to Post-Quantum WireGuard
PRESS RELEASE — This major security development milestone follows the initial launch of Dausos, Surfshark’s proprietary VPN protocol engineered with complete post-quantum security from the ground up. By pairing encryption with ML-KEM…
The Quantum Insider
Publisher
Oct 8, 2026 at 2:12 PM UTC · 3 min de leitura

- Surfshark has added ML-DSA-based certificate authentication to its WireGuard implementation, completing its stated full post-quantum security architecture.
- The company combines ML-DSA authentication with previously added ML-KEM encryption and key exchange to protect VPN traffic against potential quantum attacks.
- The fully post-quantum WireGuard implementation is currently available on iOS and macOS, with support for additional platforms planned.
PRESS RELEASE — This major security development milestone follows the initial launch of Dausos, Surfshark’s proprietary VPN protocol engineered with complete post-quantum security from the ground up. By pairing encryption with ML-KEM (key encapsulation mechanism) and certificates using ML-DSA (digital signature algorithm) for authentication, WireGuard now incorporates the final step required to deliver complete post-quantum security. Interestingly, this is not even seen among Big Tech companies. Only AWS (Amazon) and Google Cloud KMS have implemented this in their cloud management services, while companies like Apple or Microsoft have not enabled it in their primary user-facing software.
According to Karolis Kaciulis, Leading System Engineer, developing and launching our Dausos protocol with full post-quantum security enabled Surfshark to extend this level of protection across other protocols.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
