Key Points

  • The European Union's financial regulators caution that advanced quantum computers may compromise cryptographic systems that safeguard communications, transactions, databases, and blockchain technology.
  • They emphasize the risk of data captured today being decrypted in the future, a strategy referred to as "harvest now, decrypt later."
  • The EU has urged its member nations to implement a strategy for transitioning to post-quantum cryptography by the end of 2026.

The European Union's three financial regulatory bodies have issued a warning regarding the potential for advanced quantum computing to jeopardize the cryptographic measures essential for protecting communications, transactions, databases, and blockchain systems, as noted in their latest risk assessment concerning the financial system.

This alert, stemming from the joint committee of the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority, indicates that the threat could arise before quantum computing is commercially viable, suggesting that machines capable of breaking encryption could emerge prior to their practical applications.

⚠️ The ESAs have identified three emerging vulnerabilities threatening the EU financial system:

🌐 Dependence on non-EU entities
🤖 Cybersecurity threats and AI-related risks
📈 Increasing private credit vulnerabilities

While the overall financial system shows resilience, ongoing vigilance and preparation are crucial.
👉 https://t.co/z7iVITSxtv pic.twitter.com/s0rRBGMN4F

— EU Banking Authority - EBA 🇪🇺 (@EBA_News) September 23, 2026

The report highlights that stolen encrypted data does not need to be accessed immediately; information intercepted now could be decrypted later, a concept known as "harvest now, decrypt later." Any data captured today that retains value in the future is at risk.

The Digital Operational Resilience Act mandates that financial institutions employ cutting-edge cryptography to counteract emerging threats. Additionally, the EU's NIS Cooperation Group has recommended that member states implement a transition strategy to post-quantum cryptography by year's end, just three months away.

Balancing Risks and Opportunities

However, the regulators also recognized potential benefits, stating that quantum computing could significantly enhance the financial sector over the medium term by optimizing processes related to fraud detection, compliance, pricing, and simulation.

In the context of blockchain, the risks are already quantifiable. A study by Glassnode in May revealed that 6.04 million BTC, representing 30.2% of the total supply and valued over $469 billion at the time, had public keys exposed on-chain, making them susceptible to attack without any transactions needed. Estimates for Q-Day, when a quantum machine could break the cryptographic defenses of Bitcoin and Ethereum, range from 2030 to 2032 and beyond.

Among the recommendations for authorities and financial institutions is to continue preparing for the risks associated with the rapid advancements in AI and quantum technology while enhancing operational resilience and cybersecurity practices.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, videos, and more.