The European Union's banking, insurance, and securities regulators warned that advanced quantum computers could compromise the cryptographic systems securing communications, transactions, databases, and blockchains, according to their autumn assessment of financial system risks.
The joint committee of the European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority highlighted a particular concern: the encryption-breaking threat could materialize before quantum computing achieves viable commercial applications, meaning a machine capable of breaking encryption may exist before the technology becomes useful for legitimate purposes.
Harvest Now, Decrypt Later
The regulators emphasized that encrypted data stolen today need not be decrypted immediately. Information intercepted now could be decrypted in the future through a practice known as harvest now, decrypt later. Any material captured today that retains value in coming years already faces this risk.
Blockchain Exposure
For blockchains specifically, the exposure is already quantifiable. Research from May found that 6.04 million BTC—30.2% of the circulating supply and valued at more than $469 billion at that time—had publicly visible keys on-chain and would be vulnerable to attack without requiring any transaction. Estimates for Q-Day, the point at which a quantum computer can break the cryptography underpinning Bitcoin and Ethereum, range from 2030 to 2032 and beyond.
EU Recommendations
The Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography against emerging threats. The EU's NIS Cooperation Group has separately recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026.
The regulators also identified potential opportunities, noting that quantum computing could transform financial processes including optimization, fraud detection, compliance work, pricing, and simulation over the medium term. Their recommendations to authorities and institutions include maintaining planning for risks from rapid AI and quantum development while strengthening cybersecurity practices and operational resilience.


