
Joint committee cautions that quantum machines could break cryptography before commercial viability, putting sensitive data and blockchains at risk.
EU financial supervisors warn that advanced quantum computers could undermine cryptography systems and blockchains earlier than expected, exposing intercepted data to future decryption risks.
AI-generated summary
The joint committee of EU financial supervisors released its autumn risk assessment highlighting cryptographic vulnerabilities.
An advanced quantum computer could undermine some of the cryptography systems used to secure communications, transactions, databases and blockchains, the European Union's three financial supervisors said in their autumn assessment of risks to the bloc's financial system.
The warning, from the joint committee of the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority, highlighted that the threat could materialise “earlier than any viable commercial application,” meaning a machine capable of breaking encryption may exist before quantum computing is useful for anything else.
The assessment noted that encrypted material does not have to be read at the moment it is stolen. Information gathered now could be decrypted in future, the report said, a practice the industry calls “harvest now, decrypt later.” Anything intercepted today that still has value in a decade is already at risk.
The Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography against emerging threats, while the EU's NIS Cooperation Group has separately recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026, which is three months away.
Threats and opportunities
The supervisors were not uniformly negative. Quantum computing could “transform the financial sector” over the medium term, they said, pointing to optimisation of financial processes, fraud and compliance work, pricing and simulation.
For blockchains the exposure is already measurable. Glassnode found in May that 6.04 million BTC, 30.2% of the issued supply and worth more than $469 billion at the time, had public keys visible on-chain and would be targetable without any transaction being required. Estimates for Q-Day, the point at which a machine can break the cryptography underpinning Bitcoin and Ethereum, run from 2030 to 2032 and later.
Among the report's recommendations to authorities and financial institutions is to keep planning for risks from the rapid development of AI and quantum computing, alongside maintaining operational resilience and strengthening cybersecurity practices.
AI outlook — possibilities, not facts
EU member states adopt post-quantum cryptography migration strategy
Likely · Within months

Blockchain analytics firm Elliptic has introduced 'Pulse,' an AI-driven tool designed to help non-specialist police officers interpret cryptocurrency wallet addresses and transaction hashes in the field, facilitating immediate decision-making during investigations.

On September 6, 2026, the Liquid sidechain suffered a security breach resulting in the unauthorized release of 3,996 BTC. A cryptographic cache flaw allowed invalid L-BTC to be accepted, while a lack of automated payout limits facilitated the final withdrawal.

Cosmos Hub restarted block production after a nearly 24-hour halt, securing 1.23 million ATOM linked to a recent governance exploit on the Neutron blockchain.

Neutron voters passed proposal #9 on Sept. 22, as security tracker SlowMist recorded estimated losses of $4.9 million at Astroport and $4.4 million at Drop following administrative updates.

Anthropic announced its AI model Claude discovered a molecular machine called ART in bacteriophage DNA, though the company admits the discovery's precise function, utility, and significance are still unknown. The finding sparked interest from scientists like Feng Zhang but also skepticism, with gene-editing company shares dipping on the news despite no immediate practical application.

OpenAI announced Ukraine's government will receive access to Daybreak, an AI tool designed to identify software vulnerabilities before Russian hackers can exploit them. The offer was made to Ukraine's Ministry of Digital Transformation during the UN General Assembly by Dmytro Kushneruk and Sasha Baker. Daybreak, powered by GPT-5.6 Sol, scans systems for weaknesses, validates exploitability, and confirms patch effectiveness. OpenAI has previously provided similar access to cyber agencies in France, Germany, and Poland, and pledged $1 billion in subsidized access to defenders worldwide. The company reversed its ban on military use in January 2024, and while some view the move as strategic intelligence gathering, Ukraine prioritizes the defensive outcome in its ongoing cyber conflict.