Liminal Prime is Live ! Built for exchanges, OTC desks, and cross-border stablecoin businesses. Explore Liminal Prime

What is Post Quantum Cryptography Banks

Share this article

What Is Post-Quantum Cryptography and How Does It Help Banks?

Banks and financial institutions are asking a new question: Is our digital asset infrastructure ready for quantum computers?

It’s a fair question. Quantum computing is advancing fast enough that regulators, central banks, and custody providers have all started planning for it. This guide explains what post-quantum cryptography (PQC) is, why it matters for banks, and what to ask your custody provider today.

What Is Post-Quantum Cryptography?

Post-quantum cryptography (PQC) is a set of encryption and digital signature methods built to stay secure even against quantum computers.

Today’s financial systems rely on cryptography like RSA and elliptic curve cryptography (ECC). These methods are secure against classical computers. But a sufficiently powerful quantum computer could break them, using mathematical shortcuts (like Shor’s algorithm) that classical computers can’t perform.

PQC replaces the underlying math. Instead of problems quantum computers can solve quickly, it uses problems believed to stay hard even for quantum computers, such as lattice-based or hash-based problems. The U.S. National Institute of Standards and Technology (NIST) has already finalized several PQC standards, including ML-DSA, SLH-DSA, and FN-DSA, giving the industry a common reference point to build toward.

In short: PQC is cryptography designed for a world where quantum computers exist.

Why Should Banks Care About Quantum Computers?

No quantum computer today can break bank-grade cryptography. That’s the reassuring part. Here’s the part that requires action anyway:

  1. Quantum computers are getting closer, faster than expected. Recent research (including a widely discussed 2026 Google whitepaper) has narrowed estimates for how much quantum computing power it would take to break the elliptic curve cryptography behind Bitcoin, Ethereum, and most blockchains. The hardware to do this doesn’t exist yet. Current machines are years away in qubit count and error correction. But the gap is closing faster than earlier estimates suggested.
  2. “Harvest now, decrypt later” is already a risk today. An attacker doesn’t need a working quantum computer today to cause damage later. They can record encrypted data or exposed public keys now, and decrypt them once quantum computers mature. For banks, this means old wallet addresses, signed transactions, and long-lived records carry risk today, not just in the future.
  3. Migration takes years, not months. Upgrading cryptography across a financial institution’s infrastructure (key management systems, signing protocols, custody platforms, third-party integrations) is a multi-year undertaking. Waiting until quantum computers arrive means starting the clock too late.
  4. Regulators are already moving.
    • The Bank for International Settlements (BIS) published a 2025 roadmap calling for coordinated, phased PQC migration across the financial system.
    • The Hong Kong Monetary Authority has built quantum readiness into its Fintech 2030 strategy.
    • Singapore’s MAS and the Association of Banks in Singapore launched a taskforce in 2026 covering quantum-accelerated cyber risk.
    • The EU’s DORA framework includes crypto-agility provisions relevant to PQC.
    • Cross-border pilots are already underway: in 2026, banks and regulators from multiple jurisdictions tested PQC signature schemes on quantum-resistant blockchain testnets.The direction is clear: PQC readiness is moving from “nice to have” to a compliance expectation.

How Does PQC Help Banks Specifically?

For banks working with digital assets, PQC readiness protects three things:

  • Custody integrity: ensuring wallet keys and signing infrastructure can’t be broken retroactively once quantum computers mature.
  • Long-term data confidentiality: protecting transaction records and signed data that need to stay confidential for years, not just today.
  • Regulatory standing: getting ahead of mandates before they become binding deadlines, rather than scrambling under a compliance clock.

Importantly, PQC for digital assets isn’t just about swapping an algorithm. Blockchains themselves need to adopt quantum-safe signature schemes before custody providers can fully implement PQC signing on-chain. This is why the current focus across the industry is on preparation and cryptographic agility: building systems that can adapt as blockchain-level standards mature, rather than a single flip-of-a-switch fix.

What Is Liminal Doing About PQC?

Liminal is treating PQC as a strategic priority, not a future problem.

  • We are actively monitoring the PQC landscape, tracking NIST-standardized algorithms, blockchain-level PQC proposals (such as Bitcoin’s BIP 360), and regulatory guidance from bodies like BIS, HKMA, and MAS, and building our roadmap around what the industry converges on.
  • Our recovery kit is PQC-ready today. This is one part of Liminal’s infrastructure where quantum-resistant protection is already in place, independent of blockchain-level upgrades.
  • We are engaging with the research community. Dr. Sharmila S, Principal Scientist at Liminal Custody, published a guest article on The Quantum Insider in February 2026, “Quantum Computing and the Future of Digital Asset Custody: What Institutions Should Prepare for Now.” Her argument: quantum readiness isn’t about predicting exactly when quantum computers will arrive. It’s about building crypto-agile systems, adaptable authorization models, and modular security frameworks that can evolve without disrupting operations or compliance.

We’ll continue to share updates as blockchain ecosystems and PQC standards mature further.

What Should Banks Ask Their Custody Provider Right Now?

If you’re evaluating quantum readiness with your custody or wallet infrastructure provider, ask:

  1. Do you have a documented PQC roadmap, and what is it tied to (NIST standards, specific blockchain upgrades)?
  2. Which parts of your infrastructure are PQC-ready today, and which depend on blockchain-level changes outside your control?
  3. How do you handle “harvest now, decrypt later” risk on existing wallets and historical transaction data?
  4. What is your approach to cryptographic agility? Can your systems adopt new signature schemes without a full infrastructure rebuild?

The Bottom Line

Post-quantum cryptography isn’t an immediate threat to banks today, but it is an immediate planning requirement. Quantum computers capable of breaking current cryptography don’t exist yet, and estimates still put that capability years away. What does exist today is regulatory momentum, “harvest now, decrypt later” exposure, and a multi-year migration runway that institutions can’t afford to start late.

Banks that start asking the right questions now, about crypto-agility, roadmap clarity, and vendor readiness, will be the ones migrating on their own timeline instead of a regulator’s.

Frequently Asked Questions

Is post-quantum cryptography the same as quantum computing?

No. Quantum computing is the technology that poses the future threat. Post-quantum cryptography (PQC) is the defense: new cryptographic methods designed to stay secure even after quantum computers become powerful enough to break today’s encryption.

Not yet. Today’s quantum computers lack the scale and error correction needed to break RSA, ECC, or blockchain signature schemes. Estimates vary, but most experts agree this capability is still years away. The risk is real but not immediate.

Two reasons. First, “harvest now, decrypt later” attacks mean data encrypted today could be exposed once quantum computers mature. Second, migrating cryptography across a bank’s infrastructure takes years, so preparation has to start well before the threat becomes urgent.

Not necessarily. PQC is a software and protocol-level change, and many modern HSMs are designed to be crypto-agile, able to support new algorithms through updates rather than hardware replacement. The bigger dependency for digital assets is blockchain-level adoption of PQC signature schemes.

More on Crypto

Banks and financial institutions are asking a new question: Is our digital asset infrastructure ready for quantum computers?…
October 5, 2026
Kazakhstan has rebuilt its crypto market as a state-managed system that is restrictive for retail and deliberately open to regulated foreign institutions. …
September 23, 2026
Kazakhstan runs two parallel regulatory frameworks for crypto businesses: the AIFC/AFSA offshore track and the National Bank’s onshore regime. …
September 23, 2026

Find out what is the Ideal Custody Solution for you