Before anyone has figured out how to put them to practical use, a quantum computer could arrive on the scene, according to the EU’s financial watchdogs. When that moment comes, the data you sent yesterday will no longer be secret.
The ESAs — the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority — issued their autumn review of risks facing the EU’s financial system. It warns that a sufficiently powerful quantum computer could break the encryption protecting communications, transactions, databases and blockchains. The report notes that the threat could arrive “earlier than any viable commercial application,” — a machine capable of breaking encryption may be built before quantum computing has any other practical use.
The EU finds itself in an unusual spot, since it is not waiting for quantum technology to actually work before it prepares for it. Instead, the bloc is getting ready for a hypothetical arrival that comes before the payoff. The ESAs advise that financial institutions continue planning for risks from the quick advance of AI and quantum computing, while also keeping up operational resilience and boosting cybersecurity measures.
What the ESAs Actually Said
Tomorrow’s arrival of a quantum computer that cracks encryption is not what the ESAs are forecasting. What they are doing is issuing a warning about a timeline that has grown unexpectedly shorter. According to their assessment, an advanced quantum machine could weaken some of the cryptography systems that protect communications, transactions, databases and blockchains.
The document points to a specific hazard: data collected now might be cracked open later. The trade refers to this method as “harvest now, decrypt later.”. Any material captured today that retains worth over ten years is already exposed to that risk.
There is a deadline attached to the warning. The NIS Cooperation Group of the EU has separately advised that member states should put in place a plan for moving to post-quantum cryptography by the end of 2026, which is just three months away.
Why Q-Day Is Already Measurable
The warning from the ESAs carries real weight. Glassnode discovered in May that 6.04 million BTC, which represents 30.2% of the total supply and was valued at over $469 billion at the time, had public keys exposed on-chain, making them vulnerable to attack without any transaction needed. The estimates for Q-Day, the moment a machine could break the cryptography behind Bitcoin and Ethereum, range from 2030 to 2032 and later.
A quantum computer could, in theory, break the encryption protecting Bitcoin and Ethereum transactions before the technology finds any other major use. The data is already visible to anyone who can read it. The open question is whether someone constructs the machine before the coins themselves become worthless.
The Three Vulnerabilities
The ESAs identify three emerging vulnerabilities for the EU financial system:
| Vulnerability | Description |
|---|---|
| Quantum computing undermines existing cryptography | A sufficiently powerful quantum computer could break encryption protecting communications, transactions, databases and blockchains |
| Harvest now, decrypt later | Data collected now could be cracked open later; any material with value over ten years is already exposed |
| Timeline precedes practical commercial use | A machine capable of breaking encryption may be built before quantum computing has any other practical use |
This is not a set of what-ifs. The ESAs warn that information taken now could be broken into tomorrow, a method the industry refers to as “harvest now, decrypt later.”.
What Financial Institutions Should Do
Financial entities must already use up-to-date cryptography against new dangers under the Digital Operational Resilience Act. The ESAs back that demand while also asking firms to plan for quantum risks at the same time they prepare for AI risks.
Here’s how to approach the matter: prepare for a quantum computer showing up before there is any clear use for it. Bolster cybersecurity measures. Keep operations running smoothly through any disruption.
The Positive Side of Quantum Computing
Not all of the ESAs’ findings are negative. They pointed to several areas where quantum computing could “transform the financial sector” over the medium term: the optimisation of financial processes, fraud and compliance work, pricing, and simulation.
The two points are distinct. The document admits that quantum computing could benefit finance, yet its main aim is to get institutions prepared for the negative consequences before anything else.
The Bottom Line
The warning from the EU rests on a wager about timing. It urges financial institutions to ready themselves for a quantum computer arriving before any practical use for quantum technology exists. The reasoning behind it is straightforward: should the machine prove capable of breaking encryption before anyone has figured out how to put quantum tech to work for anything else, the damage will already be done.
The ESAs are not claiming that quantum computing is harmful. What they are saying is that it is arriving sooner than anticipated, and the information is already vulnerable. The single unknown factor is the hardware itself.
The ESAs are urging member states to put together a plan for moving away from classical cryptography by the end of 2026, which the EU recommends as a target. That is a short window for a problem without a known solution. The ESAs are telling institutions to prepare for a machine that may show up before anyone has figured out how to use it.
There is genuine cause for alarm. The device approaches, and its information is already laid bare.
Source material: “Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns,” Decrypt.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

