Opinion
Digital Assets and the Regulatory Challenge of Preparing for an Uncertain Threat
Share

NP
Head of Legal & Regulatory • Trustyfy
Nicole Purin argues that digital asset institutions should begin assessing quantum computing exposure and migration requirements now, even though regulators need not yet mandate specific post-quantum standards or deadlines.
Digital assets are built on cryptography. The ownership and transfer of Bitcoin, Ethereum and other virtual assets depend on mathematical problems that, using conventional computing, are considered practically impossible to reverse. Quantum computing has the potential to challenge that assumption.
This does not mean that quantum computers are about to “break” Bitcoin or render blockchain technology obsolete. The threat remains uncertain and uneven. Yet it raises a regulatory question that is becoming increasingly difficult to ignore: how early should institutions be expected to prepare for a technological risk before that risk becomes immediate?
For digital assets, the answer may lie between two extremes. Regulators may not yet need to prescribe specific post-quantum technologies or migration deadlines, but institutions should already be expected to understand their exposure, assess migration requirements and maintain the ability to adapt. Waiting until the threat is immediate may mean waiting too long.
The challenge is particularly significant for digital assets. Changing a cryptographic standard within a conventional financial institution is difficult enough. Migrating a decentralised network, its wallets, infrastructure and users to new cryptography presents an altogether different governance problem.
Quantum computers operate differently from classical computers. Whereas a classical computer processes information using bits represented as either zero or one, quantum computers use quantum bits, or qubits, which can exist in combinations of states and interact in ways that have no direct classical equivalent.
Their significance does not simply lie in being faster computers. Sufficiently capable quantum computers could perform certain calculations dramatically more efficiently than today’s machines.
Two quantum algorithms are particularly relevant to cryptography. Shor’s algorithm could, in principle, solve the mathematical problems underlying RSA and elliptic-curve cryptography. The latter is especially important to digital assets because elliptic-curve cryptography is widely used to generate the digital signatures through which ownership and transactions are authenticated.
Grover’s algorithm presents a different and more limited challenge. It can accelerate certain search problems, reducing the effective security of symmetric encryption and cryptographic hash functions. It does not simply “break” SHA-256 or blockchain hashing. The distinction matters because these risks are often treated as interchangeable when they are not.
Nor would a sufficiently powerful quantum computer necessarily cause a blockchain to stop operating. The more immediate concern is whether it could undermine the assumption that only the holder of a private key can authorise a transaction once the corresponding public key is exposed.
The nature of that exposure differs between networks. In Bitcoin, the position depends on the type of output used. Some structures conceal the underlying public key until funds are spent, while others make a public key visible from the outset; address or key reuse can create additional exposure. In Ethereum, the public key associated with an externally owned account can be recovered once that account has signed and sent a transaction. Ethereum also faces separate questions around validator signatures and other cryptographic components of the protocol.
The risk is therefore not uniform, and neither is the solution.
Cybersecurity professionals frequently describe the quantum threat through the concept of “harvest now, decrypt later”: an adversary collects encrypted information today with the intention of decrypting it once sufficiently capable quantum technology becomes available.
Public blockchains present a subtly different problem. There may be nothing to harvest and nothing to decrypt. Relevant information can already be sitting in plain sight on-chain, permanently available to anyone who wishes to examine it. What is missing is the computational capability to exploit it.
This makes migration particularly important.
In August 2024, the US National Institute of Standards and Technology finalised its first three post-quantum cryptographic standards, including standards for digital signatures. The development was significant, but having quantum-resistant algorithms does not mean entire financial and technological ecosystems can be migrated to them immediately.
For conventional financial institutions, migration is already a substantial exercise. Systems must be identified, vendors assessed, software and hardware updated, and interoperability maintained. Digital assets add another layer of difficulty.
A bank can decide to replace a cryptographic system and establish an implementation timetable. A decentralised protocol cannot necessarily do the same. Developers may propose an upgrade, but exchanges, custodians, wallet providers, validators and users may all need to adapt. Consensus may be required across participants with no obligation to move at the same time.
Dormant wallets create an additional problem. Some assets sit in addresses that have not moved for years; others may be controlled by holders who are unaware of the risk. In some cases, the private keys have simply been lost. Those assets cannot voluntarily be migrated at all.
This is why crypto-agility may prove as important as selecting any particular post-quantum algorithm. Institutions cannot know with certainty which standards will ultimately prevail or how they may evolve. Durable preparedness therefore means building systems capable of adapting as standards and risks change.
Good governance lies less in predicting the eventual technological winner than in ensuring that an institution can move when necessary.
Financial regulators and cybersecurity authorities are not ignoring quantum risk. Their response, however, remains largely focused on recognition and preparedness rather than technology-specific prescription.
The EU provides an example. The Digital Operational Resilience Act (DORA) establishes a broad framework for managing ICT and operational risk across financial services. Its supporting regulatory standards recognise threats arising from quantum developments within the cryptographic landscape that financial entities should monitor. Yet DORA does not require firms to adopt a particular post-quantum algorithm or prescribe a quantum migration deadline.
The UK’s National Cyber Security Centre has taken a more explicit planning approach. Its 2025 guidance envisages organisations completing discovery and initial planning by 2028, undertaking priority migration by 2031 and completing migration by 2035. These are not digital-asset-specific regulatory obligations, but they illustrate a shift toward treating preparation as necessary before the threat becomes immediate.
The same question arises in the UAE. The Virtual Assets Regulatory Authority’s (VARA) Technology and Information Rulebook already addresses the management of cryptographic keys, wallets and associated technology risks. It does not impose a quantum-specific requirement. As quantum capabilities develop, however, it is reasonable to ask whether foreseeable cryptographic obsolescence may increasingly fall within the technology risks that regulated virtual asset businesses are expected to manage.
This may ultimately be more useful than creating a separate body of “quantum regulation”. Existing principles of technology governance, cybersecurity, operational resilience, safeguarding and custody can accommodate emerging technological risks. The question is when and how those principles should be applied.
My own view is that quantum governance is needed now, while quantum prescription can wait.
Regulating too early carries risks. Requiring firms to adopt a specific post-quantum technology could lock the industry into standards that remain relatively young and continue to evolve. A universal migration deadline could also overlook differences between institutions, technologies and levels of exposure.
But uncertainty is not a reason for inaction.
A major custodian whose business materially depends upon cryptographic security should already understand where vulnerable cryptography exists within its infrastructure, how long migration could take and which third parties or systems it depends upon. It should monitor developments and maintain sufficient flexibility to respond as the risk assessment changes.
That does not necessarily require new legislation. Initially, it may be achieved through existing obligations relating to technology risk and operational resilience, supported by proportionate supervisory expectations.
The regulatory response can then evolve with the threat: from recommended good practice to supervisory guidance, risk-management expectations and, if the threat becomes sufficiently foreseeable, potentially binding requirements.
The difficult question is when that transition should occur.
One useful way of thinking about the problem comes from cryptographer Michele Mosca. In simplified terms, if the period for which something must remain secure, together with the time required to migrate it, exceeds the time before a sufficiently capable quantum computer arrives, preparation has begun too late.
Mosca’s approach is a technical risk-management concept, not a legal standard. Its logic nevertheless has regulatory relevance. A board does not need to predict the precise date on which a cryptographically relevant quantum computer will exist. It can ask how exposed its systems are, how long adaptation would take and what the consequences would be if migration began too late.
This also provides a basis for proportionality. A major custodian holding substantial customer assets should not necessarily face the same preparedness expectations as a smaller firm with incidental cryptographic exposure. Decentralised protocols present an additional challenge: there is no Bitcoin board or CISO whom a regulator can require to implement an upgrade.
Regulation can impose obligations on intermediaries. It cannot simply regulate away the decentralised characteristics of the underlying technology.
Liability may eventually provide the most difficult test.
Suppose that several years from now a sufficiently capable quantum computer can compromise a cryptographic system used by a regulated custodian and customer assets are stolen. The legal question should not simply be whether a regulator had previously mandated migration by a particular date.
A more relevant question may be whether, given what was known at the time, the institution had taken reasonable steps to identify, assess and prepare for a foreseeable cryptographic risk.
That assessment must cut both ways. An institution should not face liability merely because a low-probability technological risk eventually materialised. Standards may not have been sufficiently mature, migration may not have been reasonably practicable, and regulatory expectations may still have been developing.
But the converse also matters. If a risk becomes increasingly foreseeable, credible technical standards exist and migration is known to require several years, an institution that has undertaken no assessment or preparation may find it harder to argue that the absence of a specific regulatory mandate justified inaction.
This raises a broader question for technology regulation. Law frequently responds to technological developments after their consequences become apparent. Cryptographic migration may not afford regulators that luxury because the time needed to respond is itself part of the risk.
Quantum computing should not be viewed solely through the lens of cybersecurity. Financial institutions are also examining its potential use in areas including portfolio optimisation, derivatives pricing, trading and risk modelling. Major banks have established research programmes, and experimental work using quantum and hybrid quantum-classical systems is already under way.
For now, much of this remains experimental. The commercial opportunities should therefore be treated with the same caution as the security threat: neither should be exaggerated simply because the technology is compelling.
What matters is that both are moving from theory toward practical institutional consideration.
Nobody can say with precision when a quantum computer capable of materially compromising today’s digital-asset cryptography will exist. That uncertainty is likely to remain for some time.
What institutions can assess with considerably greater confidence is their own position: which cryptographic systems they depend upon, where vulnerabilities may arise, how difficult migration would be and how much time they would require to respond.
That is why the regulatory debate should not begin with mandatory algorithms or arbitrary deadlines. It should begin with awareness, preparedness, crypto-agility and proportionality.
There may eventually be a point at which guidance is no longer sufficient and minimum standards become necessary. That point should be informed by the maturity of the technology, the credibility of the threat and the practical time required for institutions to adapt.
Quantum computing therefore presents regulators with an unusual challenge. Acting too early risks prescribing solutions before the technology has settled. Acting too late risks discovering that the period needed for an orderly transition has already disappeared.
The real task is not to predict precisely when the quantum clock will run out. It is to recognise when the time required to prepare becomes greater than the time available to wait.
This contribution is part of UNLOCK Leadership. The views expressed are those of the author and do not necessarily reflect the editorial position of Unlock Blockchain.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks
In the Same Space

U.S. Weighs Global Stablecoin Push as Issuers Near $200B in Treasury Holdings
News Desk
Sep 28, 2026
3 min

EEMEA SMEs Turn to Crypto and Stablecoins as Digital Adoption Accelerates
News Desk
Sep 28, 2026
5 min

Bitget Begins Phased Withdrawals After $387.5M Security Breach
News Desk
Sep 28, 2026
3 min

Kazakhstan Plans to Turn Oil-Field Gas Into Crypto Mining Power
News Desk
Sep 28, 2026
3 min