Key facts
- Advanced quantum computers could undermine cryptography used for communications, transactions, databases, and blockchains.
- Data captured today could be decrypted later by quantum computers, a tactic known as "harvest now, decrypt later."
- The EU recommended member states adopt a post-quantum cryptography migration strategy by the end of 2026.
- Quantum computing could transform the financial sector through optimization, fraud detection, and improved pricing and simulation.
- An estimated 6.04 million BTC, or 30.2% of the issued supply, have public keys visible on-chain and are targetable.
- Estimates for 'Q-Day,' when a machine can break Bitcoin and Ethereum cryptography, range from 2030 to 2032 and later.
The European Union's financial regulators have warned that the development of advanced quantum computers poses a significant threat to the security of financial systems, potentially undermining cryptography before the technology reaches commercial viability. The joint assessment from the European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority highlighted the "harvest now, decrypt later" tactic, where encrypted data captured today could be decrypted in the future by more powerful quantum machines.
The regulators noted that this threat could materialize earlier than any useful commercial application of quantum computing. The Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography, and the EU's NIS Cooperation Group has recommended that member states implement a post-quantum cryptography migration strategy by the end of 2026.
Despite the risks, the supervisors acknowledged that quantum computing could also transform the financial sector in the medium term by optimizing processes, enhancing fraud and compliance work, and improving pricing and simulation. For blockchains, the exposure is already measurable, with Glassnode reporting in May that over 6 million BTC had visible public keys on-chain, making them potentially targetable. Estimates for 'Q-Day,' the point at which a machine can break Bitcoin and Ethereum cryptography, range from 2030 to 2032.
