arXiv · 2512.12989
Can Coding Agents Migrate to Post-Quantum Cryptography?
Abstract
A program migrated to post-quantum cryptography can verify its own signatures while producing keys or signatures that another implementation rejects. We introduce a contract-based task for migrating a Go file signer from RSA to ML-DSA-44, and compare coding agents with and without structured checker feedback. Both conditions receive the contract, compiler, documentation, and OpenSSL. Across 160 attempts in four local-agent configurations, twelve final patches pass local verification but fail external requirements. Checker access does not increase the observed completion rate in any comparison. Recorded traces show unresolved defects and checks invoked only after a patch is correct. Serving settings also affect completion: reducing only Qwen3.8's context window from 128K to 32K lowers full passes from 36/40 to 4/40. Four exploratory trials using GPT-6 Astra through Codex and Claude Fable 5.1 through Claude Code pass all 40 checks, including both baselines. These findings support evaluating interoperability separately from local agreement and reporting harness and serving limits alongside agent results.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Abdulmalik Alquwayfili. 2026-09-20. Can Coding Agents Migrate to Post-Quantum Cryptography?. https://arxiv.org/abs/2512.12989
Cite the original work for its findings. Save a collection to share your selection of sources.