Mysten Labs Cryptographer to Mass-Produce Sub-$10 Quantum-Resistant Hardware Wallets for Sui Following Coldcard Breach
Key Takeaways
- •Kostas Chalkias plans to mass-produce a quantum-resistant hardware wallet for the Sui blockchain at a target price under $10, far below competing devices that typically cost $59 to $150 or more.
- •A firmware flaw in Coldcard wallets went undetected for roughly four years and enabled attackers to steal approximately 2,055 BTC valued at nearly $130 million across more than 7,700 addresses.
- •The Sui blockchain will integrate two NIST-approved post-quantum signature schemes: ML-DSA-65 for everyday accounts and SLH-DSA-SHA2-128s within Move smart contracts for high-value vaults.
- •Sui's deterministic key derivation will allow existing users to rotate to quantum-safe keys using their current recovery phrases without creating new accounts or transferring assets.
- •Mainnet deployment of quantum-safe vaults is targeted this year, with native ML-DSA-65 accounts expected on testnet by year-end and mainnet authentication in the first quarter of 2027, subject to audits and feedback.

Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs, has announced plans to mass-produce an affordable quantum-resistant hardware wallet for the Sui blockchain. Working as a personal initiative outside his corporate role, Chalkias said he leased a dedicated factory at an undisclosed location to manufacture the Quantum 2FA Sui card, targeting a retail price under $10 with an NFC quantum signature time of one to two seconds. The price point would undercut virtually every hardware wallet on the market—established devices like the Ledger Nano and Trezor One typically retail between $59 and $79, while specialist models such as Coldcard cost upwards of $150.
The announcement comes amid escalating concerns over hardware wallet security following a major breach affecting Coldcard, one of the industry's most established devices. In late July, manufacturer Coinkite disclosed that a firmware flaw originating from a 2021 update had bypassed the device's dedicated hardware randomness chip during key generation, substituting it with a predictable software-based process that was in some cases tied to device serial numbers. Attackers began draining funds on July 30, with losses climbing in successive waves to approximately 2,055 BTC—valued at close to $130 million—across more than 7,700 addresses. Galaxy Research head Alex Thorn reported that at least 15 distinct attackers were actively exploiting the remaining vulnerable wallets.
Chalkias directly linked his manufacturing effort to this broader threat landscape. In a post on X (formerly Twitter) dated August 10, 2026, he wrote:
Reportedly working on affordable Quantum 2FA Sui cards. What happened to Coldcard will NEVER happen to my people, but I need to step up with personal time (dear wife, please excuse me) Last year, with help from some friends, I leased a dedicated factory in a secret location to… pic.twitter.com/QESxCR7S93
— Kostas Kryptos (@kostascrypto) August 10, 2026
Chalkias expanded on his motivation, stating that "crypto users shouldn't be the victims" and that "everyone deserves top-tier protection hygiene." He indicated that cards could be sponsored for users who cannot afford them.
Although the Coldcard incident originated from compromised randomness rather than quantum computing, it demonstrated how hardware wallets that fail at the cryptographic level can become silent attack vectors—precisely the category of risk Chalkias aims to eliminate. The breach also underscored a broader industry challenge: hardware wallets are only as trustworthy as their firmware update pipelines, and the Coldcard flaw went undetected for roughly four years before exploitation began.
Separately, Adeniyi.sui (@EmanAbio) reported on X on August 10, 2026:
BREAKING: We just broke another Quantum cryptography record at the Sui MicroChip Lab. Live in Athens. #Sui. Cc @kostascrypto pic.twitter.com/FABtVG6UIA
— Adeniyi.sui (@EmanAbio) August 10, 2026
Sui Protocol Prepares Native Post-Quantum Infrastructure
The hardware wallet initiative builds on post-quantum work already underway at the Sui protocol level. The Layer 1 blockchain has announced plans to integrate two post-quantum signature schemes approved by the National Institute of Standards and Technology (NIST). ML-DSA-65 will function as a native protocol signature for everyday accounts, while the hash-based SLH-DSA-SHA2-128s will be implemented within Move smart contracts to safeguard high-value vaults. NIST finalized its first set of post-quantum cryptography standards in August 2024, formalizing ML-DSA (derived from CRYSTALS-Dilithium) under FIPS 204 and SLH-DSA (derived from SPHINCS+) under FIPS 205, giving the broader industry a stable reference point for implementation.
The push carries particular weight for blockchain networks because public ledgers expose account public keys once they are used in a transaction, making them visible targets if sufficiently powerful quantum computers materialize. A widely discussed concern is the "harvest now, decrypt later" scenario, in which adversaries capture encrypted or signed data today to break it once quantum hardware matures.
A key architectural advantage is Sui's deterministic key derivation. Because existing keys are generated from a seed, users will be able to rotate to quantum-safe keys using their current recovery phrases without creating new accounts or transferring assets. Sui's live address alias feature further enables existing accounts to update authorization keys directly, removing the need for disruptive migrations.
The network is targeting mainnet deployment of quantum-safe vaults this year, with native ML-DSA-65 accounts expected on testnet by year-end and mainnet authentication scheduled for the first quarter of 2027. Chalkias has cited Sui's capacity to introduce new authentication methods without a hard fork as a structural advantage over competing blockchains, many of which would require protocol-level upgrades to adopt new signature schemes at the consensus layer. These timelines remain provisional, subject to independent audits and testnet feedback.