News

EU Regulators Put Quantum Risk on Crypto Custody & Bank Agenda

EU financial supervisors have added quantum computing to their autumn risk assessment. The warning covers banks, exchanges, and custodians. It also puts post-quantum cryptography planning under greater regulatory focus.

Written By : Yusuf Islam
Reviewed By : Pranchal Srivastava

The European Union’s three financial supervisors added quantum computing to their autumn 2026 risk assessment on September 23. The warning covers cryptography that protects communications, transactions, databases and blockchains. It does not point to an imminent attack. Instead, it raises expectations for how financial providers prepare for future cryptographic threats.

The European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority issued the assessment through their Joint Committee. Its core findings had already reached the EU Economic and Financial Committee’s Financial Stability Table on September 10.

The update places quantum computing beside two other major areas of concern. Those include reliance on providers and infrastructure outside the EU and rapid growth in private credit markets.

EU Supervisors Add Quantum Computing to Risk Picture

The supervisors said quantum computing could transform several parts of finance. Potential applications include process optimization, fraud detection, compliance monitoring, pricing, and financial simulations.

Yet the same technology could weaken cryptographic systems that institutions use at scale. Those systems protect financial communications, transactions, and databases. The assessment also names blockchains directly among the technologies exposed to future cryptographic disruption.

The timing of that threat forms a central part of the warning. According to the assessment, quantum risks could emerge before commercially viable quantum applications become widely available. That creates a security challenge before many firms gain practical economic benefits from the technology.

The concern extends beyond data generated in the future. Attackers can collect encrypted information now and attempt to decode it years later when stronger computers become available.

The industry calls this method “harvest now, decrypt later.” Therefore, information intercepted today could face future exposure if it retains financial or security value for many years.

EU Rules Push Firms Toward Cryptographic Migration

Existing European rules already provide a framework for dealing with emerging technology risks. The Digital Operational Resilience Act requires financial entities to use state-of-the-art cryptography against developing threats.

Meanwhile, the EU’s NIS Cooperation Group has recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026. That leaves only months for national strategies to meet the recommended timeline.

The September risk update therefore arrives during a broader push toward digital resilience. On September 23, ESMA also named digital innovation as a new supervisory priority beginning in 2027.

Together, those developments expand the attention placed on financial firms that rely on encryption. Banks, custodians and crypto exchanges operating within the EU now face a clearer benchmark for future cryptographic planning.

The assessment does not state that quantum computers can currently break Bitcoin, Ethereum or modern financial encryption. Nor does it describe an active quantum attack against European financial infrastructure.

Instead, it focuses on preparation. Providers must account for a technological shift that could undermine cryptographic tools used across traditional finance and blockchain systems.

Bitcoin Exposure Shows Why Preparation Matters

For blockchain networks, some exposure can already be measured. Glassnode reported in May that 6.04 million BTC had public keys visible on-chain.

That represented 30.2% of Bitcoin’s issued supply. Glassnode valued those coins at more than $469 billion at the time of its assessment.

According to the data cited in the risk discussion, those visible public keys could become potential targets if a sufficiently advanced quantum computer gained the ability to defeat the cryptography protecting them. Such exposure would not necessarily require holders to make a new transaction.

Read More: How Businesses Can Prepare for Upcoming EU IoT and AI Regulations

Estimates for so-called Q-Day vary. The term describes a point when quantum computers could break cryptographic protections underpinning networks including Bitcoin and Ethereum. Estimates mentioned in the material range from 2030 to 2032 and later.

For investors, the September assessment does not change the status of existing holdings today. Instead, it changes the standards against which exchanges, banks and custodians can increasingly be measured.

Users can therefore examine whether custody providers track post-quantum risks, maintain cryptographic migration plans and explain how they intend to adapt security systems. Those checks rely on current provider practices rather than waiting for quantum technology to reach cryptographic-breaking capability.

Conclusion:

EU supervisors now treat quantum computing as a financial security risk that requires preparation rather than immediate alarm. DORA and the 2026 migration timeline add pressure for stronger planning, while Bitcoin’s visible public-key exposure shows why crypto custodians must prepare before quantum capabilities mature.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

                                                                                                       _____________                                             

Disclaimer: Analytics Insight does not provide financial advice or guidance on cryptocurrencies and stocks. Also note that the cryptocurrencies mentioned/listed on the website could potentially be risky, i.e. designed to induce you to invest financial resources that may be lost forever and not be recoverable once investments are made. This article is provided for informational purposes and does not constitute investment advice. You are responsible for conducting your own research (DYOR) before making any investments. Read more about the financial risks involved here.

Jumper to Launch JUMP Token Sale on Legion as it Spins Out to Build the Super-App for Onchain Finance

What is Ethereum’s Glamsterdam Upgrade?

XRP and XLM Pull Back as ETF Demand and Stellar Adoption Grow

BlockDAG Boosts USDT Buyback to $0.05 - The Best Crypto Bet Over Avalanche & Worldcoin

Bitcoin SIP Over 5 Years