Guest Post: Why Financial Infrastructure Needs Post-Quantum Security

Ryan Kirkley, Founder & CEO of Global Settlement Network
Hub Hub

Guest Post By Ryan Kirkley, Founder & CEO, Global Settlement Holdings.

A temporal asymmetry lies at the heart of financial infrastructure. Settlement systems and payment rails are built to run for thirty to fifty years, and most of what moves the dollar today was last built forty years ago. Fedwire settled an average of $4.6 trillion a day in 2025, CHIPS another $2 trillion, and a stablecoin market that did not exist fifteen years ago now holds more than $300 billion of dollar liabilities on public blockchains. All of it authenticates itself with two families of mathematics, RSA and elliptic-curve cryptography, and quantum computers able to run Shor’s algorithm against production key sizes now sit within a decade. Any infrastructure deployed today on classical-only cryptography is born obsolete.

Harvest-now, decrypt-later campaigns, in which adversaries record encrypted traffic today to decrypt once the hardware arrives, are passive, undetectable and, per NIST and CISA guidance, already underway. Sovereign positions and central bank flows carry decades-long confidentiality requirements. The breach has arguably already occurred, but we just can’t read the ransom note.

The standard reassurance is that fault-tolerant quantum computing remains a distant fantasy. The last year has killed it; accelerated by artificial intelligence. In late 2024, Google’s Willow processor demonstrated below-threshold error correction, logical error rates that fall exponentially as code distance grows (Google Quantum AI, Nature 638). AlphaQubit, Google DeepMind’s AI decoder, then beat the best human-designed decoders by roughly 30%. Better decoders lower qubit overhead, and lower overhead pulls hardware targets years closer: the AlphaFold dynamic, aimed at the one technology that breaks public-key cryptography.

Introducing TQI 2.0Introducing TQI 2.0

The attack-cost curve tells the same story. In 2019, factoring RSA-2048 was estimated to need 20 million noisy qubits; in May 2025, Craig Gidney cut that to under one million through algorithmic improvements alone. For finance, the more consequential number arrived in March 2026, when Google Quantum AI put a 256-bit elliptic-curve break, the primitive under Bitcoin, Ethereum and every dollar stablecoin on them, at under 500,000 physical qubits running for minutes. Google judged the circuits sensitive enough to publish a zero-knowledge proof instead of the circuits, and set a 2029 migration deadline for its own systems; AWS has announced a fault-tolerant machine for 2028. When the companies building the hardware accelerate their own defensive timelines, that is the market speaking.

Precision here separates infrastructure builders from hype merchants. Shor’s algorithm breaks ECDSA, RSA and BLS catastrophically: full key recovery, not degradation. Grover’s algorithm merely halves symmetric and hash security. Distributed ledgers face the unforgiving version: public keys are permanently exposed on-chain, and a ledger cannot be quietly re-keyed the way a TLS endpoint can. A future quantum capability becomes retroactive theft, and the assets behind those keys are, increasingly, the dollar.

The stablecoin market holds roughly $310 billion, led by Tether’s USDT and Circle’s USDC. Under the GENIUS Act, effective January 2027, these instruments become federally regulated money. The statute is exhaustive about the asset side: one-to-one reserves, monthly disclosures, redemption rights. It is silent about the cryptography that controls the liability side, where the quantum exposure lives, in three layers.

On Ethereum, an account that broadcasts a single transaction reveals its public key. Recover the private key and the ledger records the theft as a valid transfer. Glassnode puts 30 percent of Bitcoin supply in already-exposed addresses; Citi estimates more than 65 percent of Ethereum holdings are exposed the same way. Stablecoin balances in exchange hot wallets, DeFi vaults and issuer treasuries inherit that arithmetic, and a stolen stablecoin needs no exit liquidity.

A dollar stablecoin is a smart contract with privileged roles: a master minter, a blacklister that freezes addresses, a proxy administrator that can replace the contract’s logic. Each is an ECDSA key or a multisignature of them. Project Eleven’s 2025 analysis of USDC found the blacklister and master-minter roles held by single keys at the time and mapped the escalation: break the cheapest role, mint billions of unbacked tokens or freeze the exchanges holding the supply, then take the upgrade key and rewrite balances outright. None of it touches the reserves. The Treasuries in the custodian’s account are safe; the claim on them has been forged. A reserve attestation describes the asset side of the ledger. Quantum computing attacks the ledger.

USDC circulates on dozens of blockchains held together by bridges and custodial wallets whose security reduces to a handful of signing keys. Bybit’s $1.5 billion loss in 2025 was a key compromise achieved by deception; a quantum computer turns key compromise into a computation. Circle’s post-quantum roadmap, the Ethereum Foundation’s post-quantum devnets and the $15 million Bitcoin Security Consortium show the market is pricing this in. They are also retrofits, and retrofits are the problem.

A bank treasurer may read that as a crypto problem. It is not. Every Fedwire, CHIPS and Swift instruction is authenticated by public-key infrastructure: certificates, HSM-held signing keys, TLS sessions. The 2016 Bangladesh Bank heist showed what forged Swift credentials are worth: $81 million of $951 million attempted. A quantum adversary does not steal the credentials; it derives them. An estimate from the Hudson Institute, since carried into Atlanta Fed and Citi analyses, puts the indirect losses from a quantum-enabled disruption of one major bank’s Fedwire access at $2 trillion to $3.3 trillion, 10 to 17 percent of U.S. GDP. In December 2025 the BIS Innovation Hub, three Eurosystem central banks and Swift completed Project Leap Phase 2, running post-quantum signatures on liquidity transfers and reporting the frictions this article is about: performance, interoperability, agility.

Every online-banking session and interbank VPN negotiates its keys with elliptic-curve Diffie-Hellman or RSA: recorded today, readable later. Every payment card’s EMV chip authenticates offline with RSA or ECC, and EMVCo’s June 2025 view that quantum poses no threat before 2040 predates the March 2026 result. Banks are also importing the stablecoin problem into the regulated perimeter: JPMorgan piloted its JPMD deposit token on Base in 2025, and JPMorgan, Bank of America and Citigroup announced a shared tokenized deposit network for 2027. If those tokens sign with ECDSA, the control-plane exposure above now sits inside FDIC-insured institutions.

In August 2024, NIST finalized FIPS 203, 204 and 205. Essential work, widely misread as the finish line. It is the starting gun, for four reasons.

FIPS publications give you vetted mathematics, nothing about key lifecycle, HSM support, certificate chains, or how a stablecoin issuer rotates the keys behind a contract on dozens of chains. Every major cryptographic failure in history has lived in the gap between sound algorithm and deployed system.

Lattice cryptography is young; its side-channel literature is a fraction of what three decades gave RSA and ECC, and KyberSlash-class timing bugs have already surfaced. The defensible posture is hybrid composition, ML-DSA-65 paired with BLS12-381 and ML-KEM-768 with classical key exchange, so security holds if either family survives. That is the architecture we chose for the Global Settlement Network.

SIKE was a NIST alternative until it was broken on a laptop in 2022. A stablecoin contract that hard-codes secp256k1 and a core banking system that hard-codes RSA share the same defect: neither rotates without a migration program. The requirement is versioned, negotiable cryptographic suites at the protocol layer.

NIST deprecates RSA-2048 and ECC-256 by 2030 and disallows them after 2035; the EU roadmap demands PQC on critical financial infrastructure by 2030. The GENIUS Act’s effective date lands inside that window without a word on cryptographic durability. A realistic migration for legacy rails runs four to seven years, and Swift’s ISO 20022 move alone took seven, so for existing infrastructure the window to start has closed. For new infrastructure, stablecoin settlement layers, tokenized deposit networks, CBDC systems, there is no excuse for anything but post-quantum security as a day-one constraint.

For infrastructure entrusted with sovereign and institutional settlement, quantum resilience is not a feature to be roadmapped; it’s a fiduciary obligation. A stablecoin issuer that attests to its reserves monthly while its mint key sits behind a curve with a published break is not a “stable coin”. A bank that tokenizes deposits onto a classical-signature chain has moved its balance sheet onto infrastructure it knows to be at risk. Building it in today costs kilobytes of signature overhead, amortized to irrelevance by modern consensus design. Retrofitting it mid-decade, against an AI-compressed timeline, will be paid in systemic trust. That is why the Global Settlement Network was built quantum-safe from genesis: a settlement layer holds the keys to everything above it trusts, and it cannot afford to be the layer that has to migrate.

The standards, the hardware results, the AI acceleration and the regulatory deadlines have converged. The only missing input is the decision to build for the era the infrastructure will actually live in. 

Keep track of everything going on in the Quantum Technology Market. In one place.

Share

Stay Ahead of Quantum

Get the latest research, company news, and market intelligence every week.

MENTIONED IN THE ARTICLE

More in Research

Related Articles