-+ 0.00%
-+ 0.00%
-+ 0.00%

There’s a blind spot in quantum readiness?

The Star·09/13/2026 23:00:00
語音播報

BANKS are preparing years ahead of the Q-Day deadline to avert a quantum disaster.

Blockchains, however, are at a different pace.

Q-Day is the not-so-distant future when quantum computers become powerful enough to break the public-key encryption (such as RSA and ECC) used in modern finance, from Swift messages to interbank transfers.

If bad actors can get their hands on financial data archives and decrypt them with quantum, the fallout could be straight out of a dystopian movie.

They could expose customer identities and trade secrets, forge digital signatures in agreements, and manipulate data for analysis.

Markets will be destabilised with loss of confidence in basic things like who approved a transaction and whether a document is authentic.

Blockchains (which run mainly on ECC) will be harder hit.

Private keys could be compromised and wallets drained en masse, crushing the digital asset industry overnight!

Governments have started to put firm dates around this: US requires all federal highvalue assets and high-impact systems to switch to post-quantum cryptography (PQC) by Dec 31, 2030, while the European Union (EU) demands its critical financial infrastructure to do so by the same year.

Some watchdogs like the Quantum Doomsday Clock set a much earlier deadline of March 8, 2028!

Here’s the rub: Since blockchains are decentralised globally and self-governed, there’s no supranational or transnational body to monitor their readiness timelines.

It is intentionally deregulated, or an overlooked blind spot, depending on how you see it.

In the United States, the Clarity Act leaves them to “voluntary, market-driven measures” without binding mandates, while digital assets are a mere workstream in the Treasury Taskforce.

The EU’s Dora Act also does not prescribe a specific timetable or algorithm, for the sake of tech neutrality.

The industry is decidedly on its own. None of the top 20 blockchains has implemented PQC to date, according to a Reuters investigation. At best, we may get a well-defined but technically complex roadmap, as ethereum has, requiring seven ‘hard forks’ (permanent protocol changes).

But bitcoin remains stuck at proposal stage with debates on what to fix, when to move, and might even take a decade!

Meanwhile, banks can count on centralised regulatory coordination despite trudging along.

For instance, Hong Kong’s HKMA found that 66% of its financial institutions have not assessed their quantum exposure, and the sector’s PQC readiness score is just 2.3 out of 10 (July 2026).

Switzerland’s Financial Market Supervisory Authority showed that only 28% have board-level strategies and 20% with project execution.

Singapore’s Monetary Authority of Singapore is rolling out supervisory expectations this year to close the gap between awareness and action.

In other words, an industry-aligned compliance manual will be operational in banks long before classical computers give way to quantum ones.

Managing a public blockchain is much tougher in comparison. No government can unilaterally order it to change its digital signature scheme.

A transition requires timely response and consensus among developers, miners, validators, delegates, users and so forth – each with different incentives, interests, and performance tradeoffs.

Blockchains aren’t subject to formal reporting mechanisms, and you can’t enforce uniform processes of risk assessment and inventory management across their IT estates, or ensure their controls and assurance are on the same recognised Fips (US) or ACM (EU) standards.

Local policymakers will therefore face a tricky position since tokenised finance is only as safe as its blockchains.

Malaysia is already on the glide path of tokenisation, which means quantum-vulnerable blockchains are going to be embedded deeper into banking infrastructure – with divergent PQC timelines and resilience methods.

A comprehensive National Migration Plan has been launched. So far, local backbone Zetrix has published its hybrid measures on GitHub, and a new institutional-grade ledger MerdekaL1 that’s purpose-built for sovereign security will beta in 2027. Foreign-based enterprise chains have to conform to our revised data residency, control, and recovery time objectives.

Notably, if a “native token” model is adopted for securities (which regulators mulled last year), the blowback would be more severe as it lacks offchain backup of ownership records.

Further responses are guided by containment to prevent failures from spilling into the crucial banking sector.

Priority targets such as digital asset custodians and omnibus exchange wallets, whose admin keys unlock large pools of assets, should add Q-safe signing and identity attestation layers first.

Same goes for stablecoin issuers with minting and redemption authorisation.

Yet PQC is only half the battle as it’s less tested in production, so the focus is on ‘cryptoagility’ (ability to swap defences quickly) against dynamic threats.

We’ve been here before. Remember the existential panic that “Y2K” would shut down the Internet, and the spectre of “Cybergeddon” after the WannaCry and Mirai attacks?

There was no global authority to direct a unified response then, either.

We came together under pressure nevertheless and survived. Banks and blockchains now stand on the same side, and that collective resolve must be summoned before a disaster forces our hand.

Edmund Yong is a director of the Generative AI Association of Malaysia and ambassador of the Global Blockchain Business Council founded in Davos. The views expressed here are the writer’s own.