cd /news/artificial-intelligence/hybrid-encryption-why-combine-classi… · home topics artificial-intelligence article
[ARTICLE · art-115946] src=dev.to ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Hybrid encryption: why combine classical and post-quantum cryptography

A developer has released Quipu, an open-source library that implements hybrid encryption by combining classical and post-quantum algorithms. The library uses X25519 with ML-KEM-1024 for key exchange and Ed25519 with ML-DSA-87 for signatures, targeting NIST security level 5. The developer notes that while the library composes standard primitives, it has not yet undergone an independent cryptographic audit.

read1 min views2 publishedAug 30, 2026

When a new cryptographic algorithm appears, a tension shows up: classical algorithms such as X25519 or Ed25519 have resisted attacks for years, but are vulnerable to a future quantum computer; post-quantum ones such as ML-KEM or ML-DSA resist quantum attacks, but are newer and less tested. Hybrid encryption resolves the tension: use both at once.

Combine a classical and a post-quantum algorithm so that the system

only breaks if both fail simultaneously.

A classical attacker would have to break the post-quantum algorithm; a quantum attacker would have to break the classical one and the post-quantum one. You gain security against the future without betting everything on a young algorithm.

Key exchange (encrypting for a recipient). You combine: The two resulting keys are mixed with a context-bound derivation function (HKDF), so that neither one alone is enough.

Digital signatures (authenticity). You combine: The message is accepted only if both signatures verify — an AND combiner.

There is a golden rule in cryptography, Kerckhoffs's principle: a system must be secure even if the attacker knows its entire design; security lives in the key, not in hiding the format. A good hybrid system uses public, audited primitives — XChaCha20-Poly1305 to encrypt, Argon2id to derive keys from passwords, HKDF to separate domains — and never invents its own cryptography.

Quipu is a free library implementing exactly this approach for data at rest: hybrid X25519 + ML-KEM-1024 encryption, hybrid Ed25519 + ML-DSA-87 signatures, and only verified primitives underneath. It targets NIST security level 5 (CNSA 2.0) and is open source, so anyone can review how it works.

An honest note: Quipu composes standard primitives, but the composition has not yet passed an

independentcryptographic audit. For real high-value secrets, that external review is the seal worth waiting for.

The code is at github.com/isazajuancarlos/quipu, AGPL-3.0.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @quipu 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hybrid-encryption-wh…] indexed:0 read:1min 2026-08-30 ·