Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Regulators Warn
Key Takeaways
- •The EU's banking, insurance and markets supervisors warned that advanced quantum computers could undermine the cryptography protecting communications, transactions, databases and blockchains before quantum technology achieves any viable commercial use.
- •The assessment identified three emerging vulnerabilities for the EU financial system — non-EU dependencies, cyber risks and AI-driven threats, and growing private credit risks — while stating the system remains resilient overall.
- •Due to 'harvest now, decrypt later' practices, encrypted material stolen today could be decrypted in the future, placing the start of the risk at present-day interception rather than the future arrival of quantum machines.
- •Member states have been advised to adopt post-quantum cryptography migration strategies by the end of 2026, while the Digital Operational Resilience Act already requires financial entities to use state-of-the-art cryptography against emerging threats.
- •Glassnode found in May that 6.04 million BTC, equal to 30.2% of the issued supply and worth more than $469 billion at the time, had public keys visible on-chain and would be targetable without any transaction being required.

An advanced quantum computer could undermine some of the cryptography systems used to secure communications, transactions, databases and blockchains, the European Union's three financial supervisors said in their autumn assessment of risks to the bloc's financial system.
The warning came from the joint committee of the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority — the bodies that together oversee the EU's banking, insurance and markets sectors. It highlighted that the threat could materialise “earlier than any viable commercial application,” meaning a machine capable of breaking encryption may exist before quantum computing is useful for anything else. That sequencing is the core of the warning: the clock on cryptographic risk runs independently of the clock on commercial quantum usefulness.
Announcing the assessment on September 23, the EBA said the European Supervisory Authorities had identified three emerging vulnerabilities for the EU financial system: non-EU dependencies, cyber risks and AI-driven threats, and growing private credit risks, while stressing that the system overall remains resilient.
⚠️ The ESAs identify 3 emerging vulnerabilities for the EU financial system: 🌐 Non-EU dependencies 🤖 Cyber risks & AI-driven threats 📈 Growing private credit risks The overall system remains resilient, but vigilance and preparedness are essential. 👉 pic.twitter.com/s0rRBGMN4F
— EU Banking Authority - EBA 🇪🇺 (@EBA_News) September 23, 2026
The assessment noted that encrypted material does not have to be read at the moment it is stolen. Information gathered now could be decrypted in the future, the report said — a practice the industry calls “harvest now, decrypt later.” Anything intercepted today that still has value in a decade is already at risk. For the banks, insurers and market operators the ESAs supervise, whose records and client data can stay sensitive long after transmission, that places the starting point of the risk at interception today, not at the future arrival of a decryption-capable machine.
Regulators are already pushing the sector to prepare. The Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography against emerging threats, while the EU's NIS Cooperation Group has separately recommended that member states adopt a post-quantum cryptography migration strategy — a plan for shifting to encryption designed to withstand quantum attacks — by the end of 2026, a deadline that falls three months away.
Threats and opportunities
The supervisors were not uniformly negative. Quantum computing could “transform the financial sector” over the medium term, they said, pointing to optimisation of financial processes, fraud and compliance work, pricing and simulation.
For blockchains, the exposure is already measurable. Glassnode found in May that 6.04 million BTC — 30.2% of the issued supply, worth more than $469 billion at the time — had public keys visible on-chain and would be targetable without any transaction being required. Estimates for Q-Day, the point at which a machine can break the cryptography underpinning Bitcoin and Ethereum, run from 2030 to 2032 and later — a range that would put the cryptographic milestone ahead of any proven commercial payoff from the technology, echoing the supervisors' central warning.
Among the report's recommendations to authorities and financial institutions is a call to keep planning for risks from the rapid development of AI and quantum computing, alongside maintaining operational resilience and strengthening cybersecurity practices. The most immediate marker will be whether member states meet the NIS Cooperation Group's end-of-2026 deadline for national migration strategies — a test of preparedness that lands years before the earliest Q-Day estimates.