EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
EBA, EIOPA and ESMA name quantum computers explicitly as a threat to blockchain cryptography in their autumn risk picture of September 23. What the paper says, which migration deadlines run to 2030, and three things you can check about your custody.

Table of Contents
Table of Contents
The three European financial supervisory authorities added quantum risk to their official autumn risk picture on September 23, 2026. Nothing about your holdings changes today, and the paper is not a warning about an imminent attack. What changes is the expectation placed on your provider: exchanges, custodians and banks in the EU now have to plan the migration of their encryption, and you can measure them against that.
This article sets out what the document actually says, which deadlines sit behind it, where the real attack surface lies for Bitcoin and Ether, and which three things you can check about your own custody without waiting for technology that does not yet exist.
What the EU supervisors wrote about quantum risk on September 23
Behind the paper stand the three European Supervisory Authorities, the ESAs: the banking authority EBA, the insurance authority EIOPA and the markets authority ESMA. Twice a year they publish a joint risk update in which the Joint Committee names the weak points of the EU financial system. The autumn 2026 edition appeared on September 23, and its core findings had been presented on September 10 at the Financial Stability Table of the EU Economic and Financial Committee. The statement is available in full at ESMA and at the EBA.
On quantum computing the text says the technology could transform the financial sector in central areas, from process optimisation through fraud and compliance monitoring to pricing. The same paragraph carries the flip side: the technology could equally create significant risks by undermining cryptographic systems that are used at scale to secure communications, transactions, databases and blockchains. Blockchains are named explicitly there, and not as a footnote to a banking topic.
The sentence that carries the urgency is a different one: the risks could materialise faster than any commercially viable application. In other words, the supervisors expect the ability to break old encryption to arrive before the economic benefit with which quantum computers are otherwise advertised.
Three weak points in one paper
The quantum topic does not stand alone. The ESAs name three fields: dependence on providers and infrastructure outside the EU, new technologies involving artificial intelligence and quantum computing, and the rapidly grown market for private credit. For crypto investors the first two fields are relevant, and they interlock. On the same September 23 ESMA additionally declared digital innovation a new supervisory priority from 2027, which shows that this is more than a one-off remark.
“Harvest now, decrypt later”: why intercepted data becomes a problem later
Harvest now, decrypt later describes an approach in which an attacker records encrypted data today and stores it, in order to decrypt it only once the necessary computing power exists. The attack therefore happens in two steps that can lie years apart.
For banking data, health records or contract documents that is the core of the problem, because their value does not expire. With a public blockchain the case is different and in one respect more uncomfortable: there, nobody has to intercept anything. The data lies open, permanently and retrievable by anyone. Whoever stores a copy of the chain today has everything they would need in ten years.
That is precisely why the distinction in the next section matters. The transaction history is always open. What decides the question is whether the public key belonging to a particular address is open as well.
Post-quantum cryptography: the migration deadline of end-2026 and who it binds
Post-quantum cryptography, abbreviated PQC, covers encryption and signature schemes that cannot be broken even by a powerful quantum computer. It rests on different mathematical foundations, and it is not about longer passwords.
The European timetable for this was not set by the Joint Committee. It comes from the NIS Cooperation Group, in which the member states work together. In June 2025 the group adopted a roadmap that the states endorsed. It provides for three stages: by the end of 2026 all member states should have begun the migration, meaning national strategies, inventories of the schemes in use and first migration steps. High-risk applications, which expressly include the financial sector, should be protected as early as possible and by 2030 at the latest. By 2035 the migration should reach as far as is practically feasible.
One point matters for placing this correctly: these deadlines bind member states, operators of critical infrastructure and supervised financial firms. As a private individual you are bound by no deadline. That is a relief, and at the same time it is the reason you have to look for yourself, because nobody migrates your self-custody on your behalf.

Elliptic curves, public keys and Bitcoin addresses: where the attack surface sits
Bitcoin and Ethereum sign transactions with schemes based on elliptic curves. A public key is computed from a private key, and that computation is easy in one direction and practically impossible in reverse. A sufficiently large quantum computer would make the reverse direction attackable, because a known method from quantum computing solves exactly this problem.
Here is the message for holders. With the address formats common today, the chain does not hold the public key itself, only its hash. The key becomes visible only when you spend from that address for the first time. As long as an address has only received, the information needed for this attack is not public.
That leaves two groups with a clearly raised attack surface. First, very old holdings from the early days, where the public key sits directly in the chain. Second, addresses that were used again and refilled after a spend, because from the first spend onwards the key stays permanently visible.
On the question of how far the hardware is from that point there is no reliable year, and this article deliberately names none. What is documented is that the estimates are moving towards lower effort: work published by Google Quantum AI in March 2026 concluded that breaking the 256-bit curves in use should require considerably fewer physical qubits than older models had assumed, by roughly a factor of twenty according to the reporting on that work. That is a correction to an estimate, not a date.
Regulated crypto exchanges comparedDependence on non-EU service providers: the second finding that hits your exchange
The finding that takes up more room in the paper than the quantum topic is dependence on providers outside Europe. The ESAs identify a persistently strong dependence on IT service providers and payment systems outside the EU, and point out that it remains visible in the financial infrastructures as well, where clearing, repo business and ratings are predominantly handled by entities outside the EU.
For you this is not an abstract subject, because a trading platform is first and foremost software. The servers, the custody system, the identity checks and often the settlement sit with service providers whose names appear in the terms and conditions rather than on the front page. When supervisors expect cryptographic migration, that whole stack has to move with it, and the migration is only as fast as the slowest supplier.
In practical terms: a platform licensed in the EU gives you a counterparty bound by European rules, and a supervisor able to ask questions. If the choice is still ahead of you, the comparison of regulated crypto exchanges breaks down the licences, the registered seat and the custody model for each provider. That does not replace reading the terms yourself, but it shortens the job considerably.
AI-assisted attacks: why phishing is the nearer risk than the quantum computer
In the same chapter the ESAs write that the rapid development of advanced AI systems could make cyberattacks more effective and harder to control, because attackers could find and exploit weaknesses at unprecedented speed. For insurers they expect more frequent and more severe claims as a result.
That ordering is worth holding on to, because public debate often runs it the other way round. Quantum risk is significant, and it has no date. Automatically generated phishing pages, convincingly written support messages and cloned voices on the phone are circulating today and cost holdings today. The same precaution works against both, and it is unspectacular: the private key never leaves the device on which it was created, and an approval is confirmed on a screen that does not belong to the sender of the message.
That is exactly the purpose of a hardware wallet: the signature is created inside the device, and the content of the transaction is displayed there. A compromised computer can then propose a false payment, but it cannot approve one unnoticed.
Exchange balance, hardware wallet or self-custody: what supervisors do not settle for you
The obligations arising from the risk picture are addressed to supervised firms. Where your coins sit therefore decides who carries the migration burden.
If the balance sits with a regulated exchange or a custodian, that provider carries the migration of its systems, and the supervisor can question it about them. In return you depend on its diligence and on its insolvency risk. If you hold the keys yourself, you carry the migration yourself, and in return nobody stands between you and your coins. A third variant is the split, in which an actively traded portion stays on the exchange while the long-term holding sits in self-custody.
What you can ask your provider
- Is there a published roadmap for post-quantum migration, and does it name years?
- Which parts of custody sit with service providers outside the EU, and who is your contact if something fails?
- Are deposit addresses generated fresh for each transaction or permanently reused?
- Can withdrawal addresses be locked and approvals tied to a second device?
- When was custody last audited, and is the result available to read?
The last three points take effect immediately, independently of any quantum debate. If the first question goes unanswered, that is no proof of negligence, but it does indicate how far the planning has got.

MiCA licence and custody duties: what you find in your provider's terms and conditions
Since the European regulation on markets in crypto-assets applies in full, service providers need an authorisation as a crypto-asset service provider, CASP in the wording of the regulation, in order to offer trading and custody. The authorisation brings duties that bite at exactly the point at issue here: client holdings have to be segregated from the firm's own funds, custody has to be documented, and there are reporting and contingency duties for outages and attacks.
These duties are the lever through which a supervisory finding reaches the provider. An ESA risk picture is not a law and sets no deadline for an individual firm. It does feed into supervisory practice, and that is where an observation turns into a question in an examination report. Which duties apply in detail and when the transitional rules run out is set out in our overview of the MiCA obligations for crypto firms.
For your own records one point matters more in practice than any debate about the regulation: write down which provider holds which assets and under which authorisation. If a provider changes its offering or leaves the market, you need that overview immediately.
Hardware wallets comparedMoving wallets and the holding period: why a transfer between your own wallets is not a sale
Anyone who takes this as the occasion to move holdings from an old address to a new one, or from the exchange into self-custody, rightly asks the tax question. The basic rule in Germany is clear: a transfer between two wallets that both belong to you is not a disposal. There is no sale, so no gain arises, and the one-year holding period keeps running. Only a sale, a swap into another coin or a payment made with it is a taxable event.
In practice this rarely fails on the law and often on the documentation. A portfolio tracker that does not recognise a self-transfer as such books the outgoing leg as a sale and the incoming leg as a purchase. A gain that never existed then shows up in the report, and the holding period starts again inside the software. So anyone moving holdings marks the event in their tool as an internal transfer and keeps the transaction IDs. Which programs merge self-transfers reliably is shown by the comparison of crypto tax tools.
A second point concerns the sequence. If you are consolidating several addresses anyway, it is better done calmly than under time pressure, because every move is an operation in which an address can be copied down wrongly. The most common loss in this area has nothing to do with cryptography.
“Quantum-safe” coins and wallets: how to spot dubious offers
Every supervisory announcement carrying a technical buzzword produces offers that lean on it. The pattern is predictable, and so are the markers.
- An offer promises protection and asks you to enter your existing recovery words for it, for a migration or a check, say. That is a theft attempt in every case, without exception.
- A new token is advertised as quantum-safe and is therefore supposed to rise in value. The security properties of a protocol say nothing about the price of a token.
- A year is named from which existing schemes are said to be broken. No such figure is reliable at present, including in the supervisors' papers.
- There is time pressure, a countdown or an offer valid only today. A genuine protocol migration is announced and debated over months.
The protocols themselves work on this seriously, and visibly so. Proposals for quantum-resistant signature schemes are debated in open development processes, with specifications, testnets and objections. A migration of that size will surprise nobody who follows the developer channels of their own coin.
Quantum risk and custody: what to take away
The EU supervisors have moved a long-term risk into an ongoing supervisory process. That is good news, because it creates accountability where there was only debate before. Three steps follow for you, and none of them is urgent.
- Sort your addresses. Check whether you hold balances on addresses that have already been spent from, and whether you manage very old holdings from the early days. Those are the parts that are affected at all. If everything sits with a provider, first check who holds the keys there, and compare the custody model in the overview of regulated crypto exchanges.
- Harden your approvals. The nearer risk is the attack on you rather than on the mathematics. Tie withdrawals to a second device, fix address book entries and sign larger amounts on a device kept for that purpose alone. The differences between the devices are set out in the comparison of hardware wallets.
- Book your moves cleanly. When you reorder addresses, mark every self-transfer as such and keep the transaction IDs, so that the holding period does not restart in the report. Which programs handle that reliably is shown by the comparison of crypto tax tools.
And the sentence for calm: if the ability to break elliptic curves ever exists, your wallet will not be the first target. Ahead of it stand bank connections, government communications and the signatures that hold the internet together. That is why the topic appears in the risk picture of a financial supervisor and not in a warning notice to retail investors.
(As of September 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Ethereum and Quantum Computers: Are Your ETH Affected?
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- Bitcoin and the Quantum Computer: Which Addresses Already Expose Their Keys
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- Bitcoin's Quantum Problem: Why 6.7 Million Coins Could Be Frozen Forever






























