Key Highlights
- Cosmos Ledger Security 2026.1 adds native support for ML-DSA signatures for user accounts and consensus signing.
- The release spans Cosmos SDK v0.55.0, CometBFT v0.40.0, enterprise proof-of-authority module v1.1.0, and cosmos/kms v0.1.0.
- A network becomes post-quantum configured once validators representing two-thirds of voting power rotate to ML-DSA keys.
Cosmos, a decentralized, open-source ecosystem, has released Ledger Security 2026.1, introducing native support for post-quantum secure keys across its software stack. The update enables the use of ML-DSA signatures, standardized under FIPS 204, for both user-account keys and consensus signing.
In an X post on October 8, Cosmos stated that the release is distributed through four components: Cosmos SDK v0.55.0, CometBFT v0.40.0, the enterprise proof-of-authority module v1.1.0, and cosmos/kms v0.1.0. These form part of the existing 2026.1 release family.
Post-quantum signature support
Blockchains built on Cosmos can now configure consensus parameters to allow ML-DSA keys. Existing networks may enable the option and allow individual validators or operators to migrate at their own pace. New networks can include ML-DSA support from launch.
A network reaches a post-quantum configuration once validators controlling two-thirds of voting power have rotated to ML-DSA keys. Chains that connect via the Inter-Blockchain Communication protocol to a post-quantum network must also support ML-DSA verification for CometBFT light-client proofs. Operators are directed to confirm that counterparties run CometBFT v0.40.0, v0.38.26, or later before upgrading.
ML-DSA keys are larger than the ed25519 keys previously standard in Cosmos. The increase adds overhead to network bandwidth and block size. Documentation states that the impact remains limited when measured on enterprise proof-of-authority networks.
Documentation published with the release includes guides on post-quantum keys, enabling ML-DSA, migrating a validator, creating an ML-DSA user account, and performing zero-downtime key rotation.
Zero-downtime validator key rotation
The update allows staked validators and proof-of-authority operators to rotate consensus keys directly. The process preserves the validator’s identity, voting power, misbehavior record, and delegations. No downtime occurs during the rotation.
On proof-of-stake networks, the change removes the previous requirement to rebuild a delegator base. On permissioned networks, administrators may also rotate keys on behalf of an operator. Complete guides for both proof-of-stake and proof-of-authority validators are available in the Cosmos documentation.
Remote signing via cosmos/kms
The release introduces cosmos/kms, which provides native support for remote validator signing through hardware security modules and key management services. Supported backends include all hardware security modules that implement the PKCS#11 interface and Amazon Web Services Key Management Service.
The module supports ed25519, secp256k1eth, and ml_dsa_65 keys. It replaces the earlier TMKMS software for most use cases. TMKMS previously supported only three specific hardware devices and standard Cosmos consensus keys. Support for YubiHSM and Ledger devices has been removed, while Fortanix DSM remains available through the PKCS#11 interface.
Cosmos Labs has stated that TMKMS will be removed from the Cosmos Bug Bounty Program at the beginning of the first quarter of 2027. Operators have approximately three months from the release date to evaluate and complete any migration.
Context of recent quantum-resistant development
The release comes amid broader industry attention to quantum-computing risks for public-key cryptography used in digital assets. Europol’s European Cybercrime Centre published a report on October 7 examining potential effects of quantum computers on cryptocurrency security infrastructure and outlining pathways for incremental upgrades to post-quantum cryptography.
Separate initiatives have also advanced post-quantum work. Shielded Labs announced its Epoch project to develop production-ready post-quantum cryptography and formal verification for components of the Zcash protocol.
Meanwhile, LayerZero introduced Akita, a polynomial commitment scheme intended to supply post-quantum security for zero-knowledge proving systems, with initial deployment planned inside the Jolt proving system.
The Cosmos update provides operators with the option to adopt ML-DSA keys for both consensus and user accounts while adding remote signing and key-rotation capabilities that align with certain regulatory cryptographic-module requirements, including FIPS 140-3 validation.
Also Read: Securitize Brings Tokenized U.S. Stocks to Solana With 1:1 Backing
