KXCO Now Verifies ML-DSA-87 in Consensus, the Signature Level Named by the NSA
KXCO's chain began verifying ML-DSA-87 at 08:37 UTC on 6 October 2026, 87 days before new US national security acquisitions must meet CNSA 2.0. Signing, hardware keys, the network and the chain moved together, and anyone can check the result.
Part of theQuantum Computing Center
At 08:37:11 UTC on 6 October 2026, at block 4,951,111, KXCO's chain began verifying ML-DSA-87 signatures as a rule of consensus, per the chain's public record. Twenty-eight seconds later the first ML-DSA-87 identity registered on chain. Four seconds after that, it anchored its first attestation. All four validators checked both signatures before each block was final.
ML-DSA-87 is the strongest of the three parameter sets in FIPS 204, NIST's post-quantum signature standard. It sits at security category 5, with a 2,592-byte public key and a 4,627-byte signature, per FIPS 204. The United States has named it for every classification level of its national security systems, and Australia prefers it. KXCO now ships it for signing and for keys held in hardware security modules, accepts it across its network and verifies it on chain.
Why ML-DSA-87 matters
A signature makes a promise about the future. A contract, a title, a firmware image or an audit record has to stay unforgeable for as long as anyone relies on it, and for most of what institutions sign that is decades. NIST states the threat plainly in FIPS 204: the security of many commonly used public-key cryptosystems "will be at risk" if large-scale quantum computers are ever built. The same standard says "ML-DSA is believed to be secure, even against adversaries in possession of a large-scale quantum computer". The 87 parameter set carries the widest margin it offers.
The NSA's Commercial National Security Algorithm Suite 2.0, known as CNSA 2.0, sets the algorithms for US national security systems. Its FAQ specifies "ML-DSA-87 for all classification levels", for signatures "in any use case, including signing firmware and software". It also sets the clock. From 1 January 2027, "all new acquisitions for NSS will be required to be CNSA 2.0 compliant unless otherwise noted", NSS being national security systems. KXCO's chain went live with ML-DSA-87 87 days before that date.
Australia points the same way. The Australian Signals Directorate's Information Security Manual.pdf) says: "When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87." It adds that ML-DSA-65 "will not be approved beyond 2030", and it requires new cryptographic equipment, applications and libraries to support ML-DSA-87 "by no later than 2030".
For a government buying technology, and for an institution selling into one, that settles the level. What remains is finding a supplier that delivers it end to end today, in a form an outsider can check.
Exhibit 1. Each requirement is quoted from its primary text, and the build checks the quote. Each KXCO fact was checked when the figure was built: the packages on npm, the block on the chain.
What went live
KXCO moved ML-DSA-87 through every layer it operates:
Signing. kxco-post-quantum signs and verifies ML-DSA-87, and its ML-KEM-1024 covers key establishment at the matching level.
Keys in hardware. kxco-pq-hsm 1.5.0 generates ML-DSA-87 keys on a PKCS#11 hardware security module. On a token that supports ML-DSA, the key is created on the token and marked non-extractable, so the private key never reaches the application.
The network. The relay at relay.kxco.ai accepts ML-DSA-87 signed writes and publishes the levels it accepts. Today that is ML-DSA-65 and ML-DSA-87.
The chain. A verification precompile, a function built into the chain itself, checks every ML-DSA-87 signature as part of block validation. It sits at an address that spells "KXCO" in ASCII followed by 87.
Continuity. ML-DSA-65 verification continues at its own address, unchanged, and ML-DSA-65 identities need no change.
On 5 and 6 October KXCO released 13 npm packages carrying the category 5 level, each with SLSA build provenance, which ties the published package to the public source and the build that produced it.
The level is part of what gets signed. An ML-DSA-87 signature covers the chain, the contract, the operation, the key and a tag naming the parameter set, so a signature made at one level cannot pass as the other. The contract also reads the level from the length of the key itself. Neither check is a setting anyone can switch off.
Exhibit 2. Every block, time and transaction is the chain's own answer, read from its public endpoint when the figure was built.
Ahead of the field
Ethereum's proposal for an ML-DSA verification precompile, EIP-8051, is a draft, created on 15 October 2025, and its text says "this EIP only covers NIST level II, corresponding to 128 bits of security". KXCO's chain verifies category 3 and category 5 in consensus today, on a live network with four validators.
In this field, leadership is what an outsider can verify.
Checkable by anyone
No account is needed. Sign a message with ML-DSA-87 using the public npm package, send the key, the signature and the message to the chain's public endpoint, and the chain answers 01. Flip one bit of the message and it answers 00. The companion developer note prints the code, which ran against the live chain on 6 October.
The first ML-DSA-87 registration is transaction 0xe78bd1e6 in block 4,951,125 on the public explorer. The first anchor is transaction 0xd51255d5 in block 4,951,127.
How KXCO built it
The work was briefed on 5 October and was live in consensus on the morning of 6 October.
KXCO Soul. The written judgement of the house. Every figure traces to its source, every gate is a script that fails the build, and a named person approves each release.
KXCO skills. The working method that applies that judgement to each job. This upgrade ran from a written plan, put through an adversarial critique before any code was written, and each part of the build was reviewed independently against that plan.
Code modernisation, with the system running. The cryptography of a live estate changed underneath it: libraries, hardware keys, the network service, the contract and all five chain nodes. The nodes moved one at a time while the chain kept producing blocks. Before any validator moved, an observer node ran the new software against 6,915 live blocks, including 47 real verification transactions, and found no difference in state, according to KXCO's rollout log.
Knowledge graphs. Both exhibits here are knowledge graphs, and every edge is checked when the figure is built: a quote against its source text, a package against npm, a block against the chain. If a source changes, the build fails. KXCO keeps the same model for its clients, where every claim carries its source and the date it was true.
What to watch
1 January 2027, when CNSA 2.0 applies to new acquisitions for US national security systems. Then 2030, when ASD stops approving ML-DSA-65 and NSA expects software and firmware signing to use CNSA 2.0 exclusively.
Shayne Heffernan, Ph.D., is the founder of Live Trading News, the KnightsBridge Group, Knightsbridge Law and the KXCO.ai ecosystem spanning post-quantum cryptography, identity, attestation and enterprise ontology.

Post-Quantum Has a Deadline: 2030 for Keys, 2031 for Signatures
Executive Order 14412 gives federal high-value systems until 31 December 2030 for post-quantum key establishment and until 31 December 2031 for signatures. Six of the seven official calendars put a milestone in 2030. The Order reaches vendors through the contract, the purchase, the build, the data and the inventory. The runtimes already moved: a stock Node.js client negotiates X25519MLKEM768 by default. What is left is in the application.

Tokenising a Share in Code: the Register Entry, the Credential and 4 Checks
The SEC has said what a tokenised share's record must hold: wallet, quantity and issue date on chain, the holder's name off chain, permissioned participants, and the same dividends as the share. This developer note builds it in JavaScript: an ML-DSA-65 signed register entry, a stranger's check, the same check at Armature's 0x0b precompile, a credential gate and an exact dividend at a record date.

The 2030 Post-Quantum Deadline in Code: 6 Changes and the Test for Each
A stock Node.js client already negotiates X25519MLKEM768, so TLS 1.3 took the first post-quantum step on its own. Nothing the application owns has moved. This developer note reads Executive Order 14412 and OMB M-26-15 as six changes: ML-KEM key establishment, ML-DSA signatures, a one-import move to Category 5, PQC-signed JWS at the gateway, re-encryption of long-lived data and a CycloneDX CBOM from the lockfile. Every block was run against the published packages.

Careful of the Prompts You Give Yourself
A prompt is not only what you type into a model. It is any sentence that gets inside you and starts issuing orders. Most of what we call goals were written by comparison, media, competition and now the model, and they arrive dressed as ambition. Shayne Heffernan maps how an imported sentence becomes a week, why a want should carry its source the way a Round Table claim does, and how to strip, lock and guard the objective that is actually yours.
Every story, signed and delivered.
Subscribe to the kxco channel and get the headline, the AI-written key takeaways, and the chain-anchor link the moment we publish. Audio versions and per-ticker subscriptions arrive in the next iteration.