Cloudflare's Automatic Key Exchange Now Covers 45 Billion Daily Connections

Cloudflare now scans every origin server daily and completes 99.2% of post-quantum handshakes on the first try, no retry needed.
- HelloRetryRequest failures dropped from 52% to 3.7% once Cloudflare began choosing the algorithm itself.
- Only 12.8% of origin servers actually support post-quantum encryption, up from 0.5% a year ago.
- The post-quantum key, X25519MLKEM768, runs 1,216 bytes; the old classical key ran just 32.
Why it matters: One company, sitting between visitor and server, now decides by default how each origin encrypts itself.