European Union regulators warned that quantum computing threats could emerge earlier than commercial applications, urging financial entities to move away from legacy cryptography. An expert says protocols must replace vulnerable elliptic-curve proofs with hash-based STARKs and upgrade key wrapping immediately to protect sensitive long-term data.
Key Takeaways
- European Supervisory Authorities warn quantum computing threats could compromise EU blockchain data by 2026.
- Bitcoin, Ethereum, and Solana face signature upgrades as bad actors harvest data today for future decryption.
- Cysic founder Leo Fan urges Web3 protocols to deploy automated onchain circuit breakers against AI threats.
EU Regulators Issue Post-Quantum Cryptography Warning
European Union regulators have warned that advanced quantum computers could undermine cryptographic systems widely used to secure databases and blockchains. In a Joint Committee update, the regulators, known as European Supervisory Authorities (ESAs), added that threats posed by such computers “could materialize earlier than any viable commercial application.”
Officials also believe threat actors are actively engaging in “harvest now, decrypt later” strategies, intercepting and storing encrypted onchain traffic today to decrypt once quantum hardware scales. To stay ahead of these risks, the EU’s Digital Operational Resilience Act (DORA) mandates that financial entities “adopt state-of-the-art cryptography against new threats.”
Consequently, regulators are calling on financial entities to begin transitioning away from legacy cryptographic solutions and toward quantum-resistant algorithms. Additionally, the EU NIS Cooperation Group recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026.
Layer 1 Blockchains Face Urgent Migration Deadlines
Although the precise timeline for quantum computing to break standard blockchain encryption remains a subject of debate, regulators’ warnings serve as an urgent wake-up call for developers. The risk is particularly acute for networks that pair exposed public keys with rigid upgrade paths, including major Layer 1 blockchains such as Bitcoin, Ethereum, and Solana.
Leo Fan, founder of Cysic, pointed out the extended timeline required to safely implement quantum-resistant schemes across these blockchain networks.
“The highest-risk designs combine exposed, quantum-vulnerable public keys with difficult upgrade paths. Bitcoin, Ethereum, and Solana all need signature upgrades; proof-of-stake networks must also address validator signatures,” Fan told Bitcoin.com News. “Post-quantum signature standards already exist, so deployment can begin now. Migrating entire networks is a multi-year project, not a switch to flip when quantum attacks arrive.”
Zero-Knowledge Frameworks Require Immediate Action
Asked whether decentralized storage protocols and privacy-focused blockchains should alter their zero-knowledge proof frameworks or encryption standards today given the early arrival of decryption risks, Fan urged immediate action on long-term data.
“Yes, prioritize data that must remain confidential for years,” Fan emphasized, noting that protocols must upgrade vulnerable key exchange and key wrapping using vetted post-quantum schemes while evaluating proof systems independently. “Elliptic-curve-based proofs can be vulnerable; properly designed hash-based STARKs offer a path forward. ‘Zero knowledge’ does not automatically mean ‘quantum safe,’ and future upgrades cannot rescue vulnerable ciphertext already harvested.”
AI-Driven Exploits Demand Onchain Circuit Breakers
Meanwhile, the ESAs’ update also flags rapid advances in artificial intelligence (AI) as potentially enabling cybercriminals to exploit system weaknesses at unprecedented speed, making it harder for market players to respond in time. While the report recommends maintaining strong operational resilience and cybersecurity controls, Fan urged Web3 and decentralized protocols to move beyond basic dashboards for incident response.
“Design custody so one convincing message [alone] cannot move funds. Use hardware-backed keys, independent multisig signers, and transaction verification outside the requesting chat or app,” Fan advised, warning against using familiar voices or faces for authorization.
However, as AI models become more sophisticated, they are increasingly capable of bypassing standard security measures. Consequently, protocols must implement automated, onchain defenses to contain autonomous exploits before funds are drained.
“Put the limits in contracts, not prompts. Give agents narrowly scoped, expiring permissions and cumulative spending caps. Add protocol-wide outflow limits and circuit breakers that reject limit-breaching transactions,” the Cysic founder said, warning that off-chain alerts alone cannot stop an exploit that drains a pool in a single transaction.

1 hour ago
13







English (US) ·