Cosmos released Ledger Security 2026.1 on October 8, 2026, adding its first native post-quantum key option to the Cosmos software stack. According to the release announcement, blockchains built with Cosmos can now use ML-DSA signatures for both validator consensus keys and user-account keys. The release also adds validator key rotation without downtime and a new remote-signing service for hardware security modules and cloud key management.

The update ships as four components: Cosmos SDK v0.55.0, CometBFT v0.40.0, the enterprise proof-of-authority module v1.1.0 and cosmos/kms v0.1.0.

What ML-DSA is

ML-DSA is the digital signature scheme that the US National Institute of Standards and Technology published as FIPS 204, the Module-Lattice-Based Digital Signature Standard. It is designed to stay secure against attacks by large quantum computers, which are expected to be able to break the elliptic-curve signatures most blockchains use today. Cosmos chains currently sign consensus messages with ed25519 keys.

Cosmos frames the release around that timeline. Its announcement cites NIST’s plan to deprecate RSA-2048 and 256-bit elliptic-curve cryptography in 2030 and disallow them in 2035, and says regulated financial firms face migration deadlines over the next five to ten years.

How a chain moves over

The switch does not require every node to change at once. A chain’s operators choose which key types are allowed through consensus parameters. An existing chain can turn on ML-DSA and let each validator rotate to a new key on its own schedule; a new chain can allow ML-DSA from the start.

Cosmos says a chain reaches post-quantum security once validators holding two-thirds of the voting power have rotated to ML-DSA keys. There is a compatibility catch for connected networks. Chains linked to a post-quantum chain over IBC, the Cosmos interchain protocol, must be able to verify ML-DSA in CometBFT light-client proofs, so Cosmos tells engineers to confirm their counterparties run CometBFT v0.40.0, v0.38.26 or later before upgrading. CometBFT v0.38.26, released on August 13, 2026, already carries the post-quantum functionality for that purpose.

The keys have a cost. ML-DSA keys are larger than ed25519 keys, which adds network bandwidth and block size. Cosmos says the effect is negligible at the scale of enterprise proof-of-authority networks; it does not give figures for large public chains.

Key rotation and remote signing

Before this release, a validator that wanted a new consensus key had to stand up a new validator. On proof-of-stake networks that meant rebuilding its delegator base. Ledger Security 2026.1 lets a validator rotate its consensus key directly while keeping its identity, voting power, misbehavior record and delegations, with no downtime. On permissioned networks, administrators can rotate keys on an operator’s behalf.

The new cosmos/kms service handles remote signing. It supports hardware security modules that implement the PKCS#11 interface and AWS Key Management Service, and it can hold ed25519, secp256k1eth and ml_dsa_65 keys. It replaces TMKMS, the older tool, for most uses. Support for YubiHSM and Ledger devices has been dropped, while Fortanix DSM remains available through PKCS#11. Cosmos Labs says it will remove TMKMS from its bug bounty program at the start of the first quarter of 2027, giving operators about three months to migrate.

Where this fits

Cosmos is not the only network working on the problem. In September, Tezos contributors launched Quantumnet, an experimental testnet for post-quantum accounts and consensus. The Cosmos release differs in that it ships in production software versions that chains can adopt now. For background on how validators and voting power secure a chain, see our explainer on proof of work vs proof of stake.