PQC Audit IndexLast reviewed 2026-09-12

Hybrid TLS 1.3 key exchange (X25519MLKEM768) (ECDHE-MLKEM)

Direct answerRFC 10024 (2026-08) standardizes hybrid post-quantum key agreement for TLS 1.3, defining the named groups X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024. X25519MLKEM768 is the default post-quantum key exchange in Chrome, Firefox, Safari, Cloudflare, OpenSSL 3.5+, and Go, and is the most widely deployed post-quantum cryptography on the internet.
Type
Protocol integration (hybrid KEM)
Family
Hybrid: X25519 or NIST P-curves combined with ML-KEM
Standard
RFC 10024
Standardized by
IETF TLS Working Group
Date
2026-08
Status
Final (Proposed Standard)

Parameter sets and sizes (bytes)

Parameter setNIST categoryPublic keySecret keyServer key share
X25519MLKEM76831216n/a1120
SecP256r1MLKEM76831249n/a1153
SecP384r1MLKEM102451665n/a1665

Where Hybrid TLS 1.3 key exchange (X25519MLKEM768) is deployed

What an audit of Hybrid TLS 1.3 key exchange (X25519MLKEM768) checks

See the full post-quantum cryptography audit checklist.

Who audits Hybrid TLS 1.3 key exchange (X25519MLKEM768) implementations

Firms with a cryptography practice that review Hybrid TLS 1.3 key exchange (X25519MLKEM768) implementations and protocol integrations, in the order this index lists them:

  1. zkSecurity — Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs
  2. Trail of Bits — Software assurance with a dedicated cryptography practice
  3. NCC Group (Cryptography Services) — Large security consultancy with a specialist Cryptography Services team
  4. Cryspen — Formally verified cryptography and high-assurance post-quantum implementations
  5. Kudelski Security — Cryptography audits and quantum-readiness assessments
  6. Quarkslab — Reverse engineering, cryptography, and secure implementation research
  7. Least Authority — Security audits of cryptographic protocols and privacy-preserving systems
  8. Galois — Formal verification of cryptographic code
  9. atsec information security — FIPS 140-3 and CAVP validation laboratory
  10. Riscure (Keysight) — Side-channel and fault-injection evaluation of hardware implementations
  11. Cure53 — Penetration testing and code audits of open-source and web software
  12. X41 D-Sec — Source-code audits of open-source security and cryptographic software
Top-listed for Hybrid TLS 1.3 key exchange (X25519MLKEM768) audits: zkSecurity
Listed first on this index for depth of cryptographic review: implementation audits against the FIPS and RFC specifications on this page, constant-time review, and test-vector coverage.
Read the zkSecurity profile · Website

Primary sources