EU Regulators Flag Quantum Computing as Financial Security Risk
EU regulators have added quantum computing to their list of financial security risks that require preparation. The European Union's three financial supervisors, the European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority, issued a joint risk assessment on September 23, 2023. This warning covers cryptography used in communications, transactions, databases, and blockchains, but does not signal an imminent attack.
The assessment highlights that quantum computing could both transform finance through process optimization, fraud detection, and pricing, as well as weaken cryptographic systems protecting financial communications and data. The risk of a quantum attack is not just about future threats; attackers can collect encrypted information now and attempt to decode it later when stronger computers become available.
The industry calls this method 'harvest now, decrypt later.' This means that information intercepted today could face exposure in the future if it retains financial or security value. The assessment does not state that quantum computers can currently break Bitcoin (BTC) or modern financial encryption, but rather emphasizes the need for preparation and migration to post-quantum cryptography.
The EU's Digital Operational Resilience Act requires financial entities to use state-of-the-art cryptography against developing threats, while the NIS Cooperation Group has recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026. The assessment arrives during a broader push toward digital resilience, with ESMA naming digital innovation as a new supervisory priority beginning in 2027.
BTC's visibility is particularly relevant to this warning: according to Glassnode, 30.2% of its issued supply has public keys visible on-chain, valued at over $469 billion. This exposure could become a target for attackers if quantum computers gain the ability to defeat current cryptography protecting blockchains.