Virtual private network provider Surfshark has announced the completion of its full post-quantum WireGuard implementation, marking an expansion of its cryptographic defenses designed to withstand future quantum computers. The update integrates Module-Lattice-Based Digital Signature Algorithm (ML-DSA) certificates directly into the WireGuard protocol, focusing on server authentication to prevent malicious actors from intercepting or hijacking encrypted traffic.
Addressing the Three Pillars of VPN Security
Modern cryptographic protocols rely on distinct layers of defense to safeguard user data across public networks. According to Surfshark, a fully post-quantum secure connection requires three essential pillars: encryption, key exchange, and authentication. Earlier this year, the service implemented quantum-resistant encryption and key exchange mechanisms using ML-KEM across its WireGuard setup, joining broader industry shifts where competitors like NordVPN have also expanded post-quantum protections.
However, securing server authentication has historically proven much more challenging across the cybersecurity landscape. Karolis Kaciulis, Leading System Engineer at Surfshark, noted that while quantum-safe key exchanges have seen wider adoption, authentication has largely remained an overlooked component of VPN architectures. Kaciulis explained that many organizations, including major technology firms, hesitate to implement post-quantum authentication because digital certificates are difficult to scale and the global public infrastructure required to support post-quantum certificates remains underdeveloped.
Mitigating Session Takeover and Server Impersonation
Authentication forms a critical defensive barrier for everyday web traffic. Without quantum-resistant authentication, an adversary equipped with sufficiently powerful quantum computing capabilities could undermine the connection handshake, impersonating a trusted VPN server in a session takeover attack. Under this scenario, an attacker could pose as the legitimate endpoint at the moment a client connects, effectively intercepting and decrypting data streams in transit.
Kaciulis warned that leaving this final layer unprotected introduces a significant vulnerability for the era when quantum hardware becomes accessible. To counteract that risk, Surfshark integrated ML-DSA standards into its certificate architecture, enabling quantum-resistant server validation. The company claims that the addition of ML-DSA certificates completes all three security pillars, representing the first full post-quantum deployment built for WireGuard.
The upgrade follows the development of Dausos, a proprietary VPN protocol engineered by Surfshark with end-to-end post-quantum protections. The groundwork established during the creation of Dausos served as the technical foundation for adapting the open-source WireGuard protocol to full post-quantum standards.
Deployment Gaps in the Wider Tech Ecosystem
The rollout of ML-DSA in consumer-facing networking tools remains rare. An evaluation conducted by Surfshark across 15 major technology platforms revealed that only two cloud infrastructure offerings—Amazon Web Services Key Management Service (AWS KMS) and Google Cloud KMS—have deployed ML-DSA, with both implementations targeted at enterprise cloud key management rather than end-user client applications.
The company also observed that while major ecosystem operators such as Apple and Microsoft have access to ML-DSA cryptographic standards, neither company has enabled the algorithm by default in primary consumer applications such as Safari or Edge. Kaciulis pointed out that industry competitors frequently prioritize ML-KEM key exchanges on product roadmaps while delaying authentication, largely because quantum computing does not present an immediate, day-to-day threat today. Nevertheless, Surfshark maintained that proactive implementation is necessary to prevent legacy connections from remaining exposed once quantum systems mature.
Current Platform Availability
Surfshark’s fully post-quantum WireGuard implementation is currently active and available for users running the application on iOS, macOS, and Windows. The company has stated that it plans to expand support for the upgraded protocol configuration to additional client platforms in upcoming releases.














