AI

Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns

· Decrypt

Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns

The EU's banking, insurance and markets regulators said an advanced quantum computer could undermine cryptography protecting communications, transactions, databases and blockchains.

They warn that data captured today could be decrypted later, a tactic known as “harvest now, decrypt later.”

The EU has recommended member states adopt a post-quantum cryptography migration strategy by the end of 2026.

An advanced quantum computer could undermine some of the cryptography systems used to secure communications, transactions, databases and blockchains, the European Union's three financial supervisors said in their autumn assessment of risks to the bloc's financial system.

The warning, from the joint committee of the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority, highlighted that the threat could materialise “earlier than any viable commercial application,” meaning a machine capable of breaking encryption may exist before quantum computing is useful for anything else.

⚠️ The ESAs identify 3 emerging vulnerabilities for the EU financial system:

The assessment noted that encrypted material does not have to be read at the moment it is stolen. Information gathered now could be decrypted in future, the report said, a practice the industry calls “harvest now, decrypt later.” Anything intercepted today that still has value in a decade is already at risk.

The Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography against emerging threats, while the EU's NIS Cooperation Group has separately recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026, which is three months away.

The supervisors were not uniformly negative. Quantum computing could “transform the financial sector” over the medium term, they said, pointing to optimisation of financial processes, fraud and compliance work, pricing and simulation.

For blockchains the exposure is already measurable. Glassnode found in May that 6.04 million BTC, 30.2% of the issued supply and worth more than $469 billion at the time, had public keys visible on-chain and would be targetable without any transaction being required. Estimates for Q-Day, the point at which a machine can break the cryptography underpinning Bitcoin and Ethereum, run from 2030 to 2032 and later.

Among the report's recommendations to authorities and financial institutions is to keep planning for risks from the rapid development of AI and quantum computing, alongside maintaining operational resilience and strengthening cybersecurity practices.

Start every day with the top news stories right now, plus original features, a podcast, videos and more.