Generate
B runs ML-KEM-768 key generation inside its own Web Worker and shares only the public key.
LatticeLink seals messages between two agents with ML-KEM-768, HKDF-SHA-256 and AES-256-GCM, entirely inside your browser. Then it invites you to break it.
Live channel · this tab
A … ⇄ B …
Built on open standards
01 Live trace
This console is not a recording. When it scrolls into view, your browser generates a key, seals a message, opens it, then attacks it three ways, and prints what actually happened, with the time each step took.
Timings measured in this tab · lines paced for reading
02 Try to break it
Below is a real envelope, sealed a moment ago to a key that exists only inside a worker on this page. Click any byte to flip its lowest bit. The worker runs the real decryption on the altered copy.
Waiting for the envelope
03 The protocol
Standardized primitives, composed in the open and executed entirely on the two parties’ own devices.
B runs ML-KEM-768 key generation inside its own Web Worker and shares only the public key.
A encapsulates to B’s public key, producing a fresh 32-byte shared secret and a 1,088-byte KEM ciphertext.
HKDF-SHA-256 derives a single-use AES-256 key. AES-256-GCM encrypts the message and authenticates every header field.
B parses strictly, decapsulates and checks the tag. On any failure it releases nothing, not a single byte.
One message, end to end. Only B can derive the AES key; everything on the channel is public.
1,184bytes
ML-KEM-768 public key
1,088bytes
KEM ciphertext, fresh for every message
128bits
authentication tag over the message and every header
0servers
ever see your keys or your message
04 Why now
Encrypted traffic can be recorded today and stored until a large enough quantum computer exists. Shor’s algorithm would then break RSA and elliptic-curve key exchange, the public-key cryptography behind most secure connections today.
No one has publicly demonstrated a quantum computer capable of that. The risk is to data with a long shelf life, which is exposed the moment it is captured. Post-quantum key encapsulation such as ML-KEM is designed to resist the attack.
Peter Shor publishes a quantum algorithm that factors integers and computes discrete logarithms efficiently.
NIST opens its call for post-quantum public-key algorithms.
NIST selects CRYSTALS-Kyber for standardization as its key-encapsulation mechanism.
NIST publishes FIPS 203. Kyber becomes ML-KEM.
NIST’s draft transition plan, IR 8547, proposes deprecating quantum-vulnerable public-key algorithms after 2030 and disallowing them after 2035.
You can run ML-KEM-768 in this browser tab, and check every step yourself.
05 Envelope v1
A strict JSON envelope with explicit algorithm identifiers. Every header field is bound into the AES-GCM tag as associated data, so changing any of it is detected.
Sealing a live envelope…Sealed moments ago by the self-test, to a key that existed only inside a worker on this page.
06 Isolation
Each agent runs in its own Web Worker. B’s secret key is created inside its worker, and the worker’s protocol has no request that returns it. It is never displayed, stored, exported, sent to A or shown to the AI.
Keys live in memory only. Closing or refreshing the tab destroys them, and every envelope sealed to them becomes unopenable.
The site’s Content-Security-Policy allows connections only to itself, plus Hugging Face for model files once you opt in to the AI.
No cookies, analytics, accounts or server-side processing. Messages and keys never reach a server, because there is none.
07 On-device intelligence
An optional small language model drafts messages and explains results in plain English. It runs on your GPU through WebGPU, loads only when you ask, and never sees a key, a shared secret or an envelope.
Internal tests, 10 October 2026, Chrome 154: over WebGPU on an NVIDIA RTX 4070 the model was ready in 32.5 s including the download and generated 34 to 79 tokens per second; on the CPU path it was ready in 49.6 s and generated 3.4 tokens per second. Small models make mistakes; every answer is labelled as live model output.
08 Security posture
Strong cryptography is necessary, not sufficient. This is exactly what a passing run demonstrates, and what it does not.
Audit status. ML-KEM is provided by noble-post-quantum 0.7.1, which states that it has not been independently audited (it was self-audited at version 0.6.1 in April 2026). LatticeLink’s own code has not been externally reviewed. It is a research preview, not an audited secure messenger.
Read the security modelResearch preview
It takes about a second, it runs entirely on your device, and every verdict comes from the cryptography.