• About
  • FAQ
  • Earn Bitcoin while Surfing the net
  • Buy & Sell Crypto on Paxful
Newsletter
Approx Foundation
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Approx Foundation
No Result
View All Result
Home Regulation

Ethereum’s post-quantum roadmap puts banks on a 2027 deadline

Moussa by Moussa
August 14, 2026
in Regulation
0
Ethereum’s post-quantum roadmap puts banks on a 2027 deadline
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Ethereum’s post-quantum migration could create a problem for regulated banks years before any quantum computer poses a real threat to validator keys.

Thomas Brunner, Sygnum Bank’s Head of Custody and Staking, thinks differently about quantum risk in crypto than most people do.

Ethereum’s Post-Quantum team says layer-1 upgrades could be completed by 2029, though it stresses there is no fixed date and the roadmap can still shift. The plan starts with a post-quantum validator-key registry before eventually replacing today’s BLS validator signatures with hash-based alternatives such as leanXMSS.

Ethereum shows why bank backups become the danger

BLS is the signature scheme that Ethereum validators use today, and it carries no state to manage, allowing a validator to sign as many times as needed. leanXMSS is built from a structure of one-time keys, and signing twice with the same index hands an attacker the material needed to forge a signature.

Ethereum’s massive fee shock: New post-quantum signatures are 40x larger, threatening to crush network throughput and user costsEthereum’s massive fee shock: New post-quantum signatures are 40x larger, threatening to crush network throughput and user costs
Related Reading

Ethereum’s massive fee shock: New post-quantum signatures are 40x larger, threatening to crush network throughput and user costs

Coinbase, Solana, Polkadot, and Bitcoin all moved on PQ planning, but wallet UX and aggregation may decide the winner.

Jan 27, 2026 · Gino Matos

NIST’s SP 800-208 standard requires stateful hash-based signing to occur within a hardware module, bars the export of private key material, and expects the private key to exist in one instance.

Brunner said that the standard is blunt about the consequences and lacks a backup copy, which directly conflicts with how banks normally build resilience.

Backup, replication, hot standby, failover, and disaster recovery all either duplicate the signing environment or roll it backward in time. Restoring from an old snapshot reuses the index, and failing over to a standby that has been advancing its own counter does as well.

NIST is already working on a future revision that would allow controlled key export with mitigations, which would ease the non-export rule creating this conflict, but that update does not exist yet.

Bank resilience control Normal purpose XMSS/stateful-signature risk
Backup Preserve recoverability if infrastructure fails Restoring an old copy can roll the signing index backward
Replication Keep duplicate systems available across sites Two copies can diverge or reuse the same signing state
Hot standby Allow rapid failover during outage Standby signer may not share the exact current key state
Failover Move signing to another system after disruption A stale failover target can reuse one-time signing material
Disaster recovery testing Prove the bank can recover critical systems Testing can accidentally create live duplicate signing states

The multi-year runway banks need

Brunner said a full cryptographic inventory, mapping every place a key lives and what depends on it, typically takes six months to a year on its own, before a bank touches anything.

Banks sign inside hardware security modules, and Brunner said the bank cannot move faster than its vendors ship and certify post-quantum support with reliable state handling, a validation cycle it does not control.

Key ceremonies and dual-control procedures then need to be redesigned, followed by internal risk approval, external audit and, where relevant, supervisory review. Put those steps in series, and the arithmetic alone produces a multi-year timeline.

A bank beginning its inventory in 2027 would be roughly on time for a 2029 target.

Migration step Why it matters Timing pressure
Cryptographic inventory Map every key, dependency, vendor, and control path 6–12 months before changes begin
HSM/vendor readiness Banks depend on certified signing hardware and state handling Outside the bank’s direct control
Key ceremony redesign Existing dual-control and recovery procedures may not fit XMSS Requires operational rewrite
Risk approval Internal control owners must approve the new model Adds governance lead time
External audit Auditors must retest the custody-control description Cannot happen at the last minute
Supervisory review Regulators may need to understand the changed custody process Adds uncertainty before launch

Regulators are already flagging the planning gap

Switzerland’s FINMA surveyed 60 financial institutions on quantum computing risk between November 2025 and January 2026 and found most understood the danger but lacked a clear migration roadmap.

The regulator’s July report found that 72% of institutions had neither planned nor implemented measures for quantum-safe encryption, and only 8% had a specific roadmap.

FINMA’s findings describe a broader planning gap across traditional finance, one Brunner said is the cheapest part of the problem to close because a roadmap alone would fix it.

Ethereum’s proposed validator-key registry would cap the number of post-quantum keys the network processes per slot, with researchers currently using 16 registrations per slot as a representative parameter to spread the transition over weeks or months.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

Ethereum Research has warned that a last-minute rush to register could overload the queue and leave validators unable to sign once BLS is deprecated, threatening finality itself.

Brunner’s point about the queue is that a bank arriving late registers alongside every other latecomer and cannot control where it lands in line. Being early is the only way a bank can gain any real influence over its place in that queue.

What breaks first

Brunner’s sequence for how a bank runs into trouble starts with the audit itself. If the signature scheme underneath a bank’s custody process moves to something new but its documented controls have not been redesigned and retested, the attestation no longer describes what the bank is doing. Auditors rely on that description holding.

A validator that cannot produce signatures accepted under the prevailing consensus rules stops performing its duties, and any resulting penalties are borne directly by client positions.

Brunner said a bank that cannot describe and evidence a compliant custody process should not keep onboarding client assets into it. Cryptographic compromise, the scenario most people picture first, arrives last in his sequence.

Failure stage What happens Why it matters
1. Audit/attestation breaks Documented controls no longer match how keys are actually handled The bank can no longer evidence control of client assets
2. Validator operations degrade Validators fail to produce accepted signatures Staking performance and penalties affect client positions
3. New onboarding slows or stops The bank cannot evidence a compliant custody process Business impact arrives before cryptographic compromise
4. Cryptographic compromise Quantum or state-reuse attack becomes practical This is the last risk in Brunner’s sequence, not the first

Ethereum can show how the transition could go from here

The bull case has hardware vendors shipping state-aware signing modules in time, with monotonic counters and atomic state updates giving auditors a clean pattern to test against.

NIST’s anticipated revision to its export rules gives banks a safer way to build redundancy without duplicating usable key material, and Ethereum’s registry incentives keep registration spread out as intended. Banks that started their inventories in 2027 clear internal and external review with room to spare.

The bear case has a bank starting its inventory in 2028 or later, discovering validator keys embedded across vendor stacks, staking providers, and disaster-recovery procedures it cannot fully map in time.

Auditors issue a qualified finding once they realize that the documented controls no longer align with how keys are handled, and that new staked-ETH onboarding slows or stops. The bank still has to join Ethereum’s registration queue behind everyone else who waited too.

Reaching an ordinary audit day without being able to prove control of validator keys is enough to fail Ethereum’s quantum transition, with or without a working quantum computer anywhere in sight.

Related articles

Bit Digital pledged 74% of its staked Ethereum position to a loan that can trigger a 24-hour collateral call

Bit Digital pledged 74% of its staked Ethereum position to a loan that can trigger a 24-hour collateral call

August 14, 2026
$25.9M pool vs. $12.1M notes

$25.9M pool vs. $12.1M notes

August 13, 2026



Source link

Share76Tweet47

Related Posts

Bit Digital pledged 74% of its staked Ethereum position to a loan that can trigger a 24-hour collateral call

Bit Digital pledged 74% of its staked Ethereum position to a loan that can trigger a 24-hour collateral call

by Moussa
August 14, 2026
0

Bit Digital funded the majority-owned AI infrastructure company WhiteFiber without selling Ethereum or issuing new shares, but the route added...

$25.9M pool vs. $12.1M notes

$25.9M pool vs. $12.1M notes

by Moussa
August 13, 2026
0

GameSquare Holdings reported stronger second-quarter operations alongside a $7.83 million crypto-linked accounting loss. The gaming and creator-economy company ended June...

FG Nexus dumped all its Ethereum at a $45 million loss

FG Nexus dumped all its Ethereum at a $45 million loss

by Moussa
August 13, 2026
0

FG Nexus has abandoned its Ethereum treasury strategy less than a year after launch, redirecting its focus toward real estate...

Russia picks Bitcoin, Ethereum and USDT for public trading as retail faces $58,000 cap

Russia picks Bitcoin, Ethereum and USDT for public trading as retail faces $58,000 cap

by Moussa
August 12, 2026
0

The Bank of Russia has proposed opening public organized crypto trading with only Bitcoin, Ethereum, and Tether’s USDT eligible for...

SharpLink posts $1B loss as its $1.7B Ethereum treasury could take 90 days to fully convert to cash

SharpLink posts $1B loss as its $1.7B Ethereum treasury could take 90 days to fully convert to cash

by Moussa
August 10, 2026
0

Ethereum treasury company SharpLink reported a $1.08 billion net loss for the six months ended June 30. Its Aug. 7...

Load More

youssufi.com

sephina.com

[vc_row full_width="stretch_row" parallax="content-moving" vc_row_background="" background_repeat="no-repeat" background_position="center center" footer_scheme="dark" css=".vc_custom_1517813231908{padding-top: 60px !important;padding-bottom: 30px !important;background-color: #191818 !important;background-position: center;background-repeat: no-repeat !important;background-size: cover !important;}" footer_widget_title_color="#fcbf46" footer_button_bg="#fcb11e"][vc_column width="1/4"]

We bring you the latest in Crypto News

[/vc_column][vc_column width="1/4"][vc_wp_categories]
[/vc_column][vc_column width="1/4"][vc_wp_tagcloud taxonomy="post_tag"][/vc_column][vc_column width="1/4"]

Newsletter

[vc_raw_html]JTNDcCUzRSUzQ2RpdiUyMGNsYXNzJTNEJTIydG5wJTIwdG5wLXN1YnNjcmlwdGlvbiUyMiUzRSUwQSUzQ2Zvcm0lMjBtZXRob2QlM0QlMjJwb3N0JTIyJTIwYWN0aW9uJTNEJTIyaHR0cHMlM0ElMkYlMkZhcHByb3gub3JnJTJGJTNGbmElM0RzJTIyJTNFJTBBJTBBJTNDaW5wdXQlMjB0eXBlJTNEJTIyaGlkZGVuJTIyJTIwbmFtZSUzRCUyMm5sYW5nJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1maXJzdG5hbWUlMjIlM0UlM0NsYWJlbCUyMGZvciUzRCUyMnRucC0xJTIyJTNFRmlyc3QlMjBuYW1lJTIwb3IlMjBmdWxsJTIwbmFtZSUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1uYW1lJTIyJTIwdHlwZSUzRCUyMnRleHQlMjIlMjBuYW1lJTNEJTIybm4lMjIlMjBpZCUzRCUyMnRucC0xJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0MlMkZkaXYlM0UlMEElM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1lbWFpbCUyMiUzRSUzQ2xhYmVsJTIwZm9yJTNEJTIydG5wLTIlMjIlM0VFbWFpbCUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1lbWFpbCUyMiUyMHR5cGUlM0QlMjJlbWFpbCUyMiUyMG5hbWUlM0QlMjJuZSUyMiUyMGlkJTNEJTIydG5wLTIlMjIlMjB2YWx1ZSUzRCUyMiUyMiUyMHJlcXVpcmVkJTNFJTNDJTJGZGl2JTNFJTBBJTNDZGl2JTIwY2xhc3MlM0QlMjJ0bnAtZmllbGQlMjB0bnAtcHJpdmFjeS1maWVsZCUyMiUzRSUzQ2xhYmVsJTNFJTNDaW5wdXQlMjB0eXBlJTNEJTIyY2hlY2tib3glMjIlMjBuYW1lJTNEJTIybnklMjIlMjByZXF1aXJlZCUyMGNsYXNzJTNEJTIydG5wLXByaXZhY3klMjIlM0UlQzIlQTBCeSUyMGNvbnRpbnVpbmclMkMlMjB5b3UlMjBhY2NlcHQlMjB0aGUlMjBwcml2YWN5JTIwcG9saWN5JTNDJTJGbGFiZWwlM0UlM0MlMkZkaXYlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1idXR0b24lMjIlM0UlM0NpbnB1dCUyMGNsYXNzJTNEJTIydG5wLXN1Ym1pdCUyMiUyMHR5cGUlM0QlMjJzdWJtaXQlMjIlMjB2YWx1ZSUzRCUyMlN1YnNjcmliZSUyMiUyMCUzRSUwQSUzQyUyRmRpdiUzRSUwQSUzQyUyRmZvcm0lM0UlMEElM0MlMkZkaXYlM0UlM0NiciUyRiUzRSUzQyUyRnAlM0U=[/vc_raw_html][/vc_column][/vc_row]
No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2024 APPROX FOUNDATION - The Crypto Currency News