The Quantum Asymmetry Every Bank Now Faces

Dr. Kris Naudts, Zeynep Koruturk (Founding & Managing Partners) & Donald Harmitt (Associate) at Firgun Ventures.

For financial institutions, quantum computing is no longer a distant research question. It is becoming a strategic question about timing, risk and advantage, and two documents published by Google in March 2026 brought it forward sharply. The first set an internal deadline of 2029 for migrating the company's infrastructure to post-quantum cryptography, years ahead of the UK National Cyber Security Centre's 2035 horizon and the 2035 target embedded in the U.S. National Security Memorandum 10. The second was a 57-page whitepaper from Google Quantum AI showing that the resources required to break the elliptic curve cryptography encryption approach underpinning Bitcoin, Ethereum and a large share of digital authentication, had fallen by a significant order of magnitude.

In recent years we have witnessed the financial services sector's posture shift from curiosity to commitment quickly. As discussed in Dr. Kris Naudts’, Founding and Managing Partner at Firgun Ventures, podcast, Time to Talk Quantum: Inside Banking’s Future with Lloyd’s Banking Managing Director, Clare Schramm Fergus, research from the benchmarking platform Evident found that nearly 80% of the world's 50 largest banks are now actively engaging with quantum technology, pointing to a sector-wide pivot from experimentation toward strategic investment.

Quantum computing presents financial institutions with an asymmetry of consequences that has no real precedent in recent enterprise IT history. Being late to quantum-enhanced Monte Carlo (computational technique used to model the probability of various outcomes by running thousands of randomised scenarios) or portfolio construction costs a bank some alpha (measure of an investment's performance that indicates its ability to generate returns in excess of its benchmark) or operational efficiency. Being late to post-quantum cryptography can cost the institution itself, including historical data already harvested under “harvest now, decrypt later” assumptions. The risk case will likely pull quantum into financial enterprises first, but the pace of progress across the stack suggests the opportunity side will arrive faster than most enterprise roadmaps assume.

The cryptographic clock is ticking for financial institutions

Modern finance rests on a small number of cryptographic methods. Public key systems encryption methods such as Rivest-Shamir-Adleman (RSA) and elliptic curve cryptography (ECC) secure payments, authentication, digital signatures and most of the trust layer beneath digital markets. These standards were designed to withstand classical computers, where the underlying mathematical problems are effectively unsolvable in any reasonable timeframe. Shor's algorithm, proposed in 1994, showed that a quantum computer could solve those problems exponentially faster. A cryptographically relevant quantum computer (CRQC), i.e. one powerful enough to run Shor’s algorithm, once it exists, collapses a problem that takes classical machines billions of years into one that runs in minutes.

Of the two public key systems, ECC is expected to fall first. ECC achieves security with shorter keys than RSA, efficient on classical hardware and widely deployed across mobile, web and blockchain infrastructure, but leaving a smaller mathematical fortress for quantum algorithms to scale. It is, in effect, a finely engineered lock built around a structure a future quantum tool is designed to pick. The Google whitepaper estimates that breaking the 256-bit elliptic curve discrete logarithm problem could be achieved with between 1200-1450 logical qubits, which is well within the roadmap of major quantum players such as IonQ within the next three to five years.

What appears most underappreciated at the commercial scale is the “harvest now, decrypt later” (HNDL) dimension. The term Q-Day refers to the moment a quantum computer can break public key cryptography, and it is tempting to treat that as when the problem begins, when in reality it is not. Encrypted financial traffic intercepted today can be stored and decrypted retrospectively once a CRQC exists, and the impact radius of that retrospective break would not respect geographically or enterprise borders. A Coinbase-convened panel of six leading cryptographers recently concluded that a quantum computer powerful enough to break blockchain encryption will eventually be built, with roughly 6.9 million Bitcoin sitting in wallets that have exposed public keys.

Post-quantum cryptography migration is by no means a simple software patch. The candidates finalised by the US National Institute of Standards and Technology (NIST), including ML-KEM for public-key establishment, ML-DSA for digital signatures and SLH-DSA for hash-based signatures, require new key infrastructure, longer signature sizes and significant changes to performance assumptions across payment rails, custody and identity. Practitioners estimate full migration takes 5-7 years for a smaller institution and 12-15+ years for a large institution, with the range depending on a number of factors including tech stack complexity. Against a 2035 regulatory horizon and Google's 2029 internal target, that runway is much narrower than it looks.

When the defensive quantum playbook turns offensive

The defensive case may be the first budget line, but it does not define the whole story. Several institutions are already converting compliance work into capability. HSBC has explored quantum key distribution (QKD), where the laws of quantum mechanics make any interception of an encryption key detectable, which led to piloting quantum-secure technology into foreign exchange and tokenised gold trading. JPMorgan Chase, arguably the leading financial services pioneer in quantum, and accounting for roughly two-thirds of quantum job postings across the 50 banks tracked by Evident, has built a quantum-secured network connecting its data centres and demonstrated quantum speedups for optimisation problems relevant to financial modelling. The same procurement decisions that satisfy a cryptographic mandate today are, in many ways, building the substrate for tomorrow's alpha-generating workflows.

The offensive case is moving faster than conventional enterprise framing suggests. Quantum methods are positioned to make the scenario simulations (Monte Carlo) behind bank’s risk modelling far less computationally expensive, which could let institutions run many more "what if" scenarios for Value at Risk (the potential loss a portfolio could face under adverse conditions), credit exposure and economic capital, capturing the rare events that classical models tend to gloss over. Given that false declines (transactions falsely flagged as fraudulent by overly aggressive filters) cost U.S. online retailers over $11 billion in 2021 according to Aite-Novarica, even modest precision gains translate into commercial value.

Portfolio, pricing, and improving financial benchmarks

Portfolio construction is the use case showing the earliest quantitative signals, and the results are increasingly hard to dismiss. Infleqtion's Q-CHOP algorithm, developed with JPMorgan Chase and NVIDIA on the CUDA-Q platform, was tested on 14 years of S&P 500 data and built portfolios that earned more return for each unit of risk than an equal-weighted benchmark, running up to 42 times faster on accelerated hardware. HSBC's bond pricing collaboration with IBM delivered up to 34% improvements in prediction accuracy. Joint research between Quantum Motion, a Firgun Ventures portfolio company, and Goldman Sachs on options pricing, currently in peer review, extends the same pattern into derivatives.

Not every result has been demonstrated at full production scale, and fault-tolerant hardware capable of running these algorithms across the largest problem sizes is still being built. What has changed materially is the rate at which the gap is closing, given qubit counts are rising, error rates are falling and hybrid quantum-classical software stacks are maturing in parallel. The window for offensive applications is likely to open earlier, and across more workflows, than enterprise planners forecasted.

The compounding case for early financial quantum adoption

The asymmetry of consequences is what makes quantum unusual as an enterprise technology decision within finance. Most strategic bets in financial services involve symmetric trade-offs, where the cost of being too early roughly mirrors the cost of being late. Quantum does not work that way. The defensive cost of inaction is potentially terminal, while the offensive cost compounds subtly until competitors with better infrastructure begin to pull ahead.

Institutions are being drawn into capability building at a tempo set by cryptographic risk, but the marginal cost of pursuing alpha applications is falling sharply at the same time. As hardware improves and hybrid workflows become easier to test, the opportunity side could become strategically material faster than enterprise decision-makers assume. The question ultimately becomes how to sequence the spend so that defensive obligations compound into offensive capability.

Banks that treat the 2029 to 2035 window purely as compliance will arrive at the end of the decade quantum-safe but quantum-naive. Those that use the same period to build the talent, partnerships and computational fluency required for portfolio, pricing and risk applications will arrive with a structural head start on the use cases where quantum delivers measurable alpha. The cryptographic clock is the same in both these cases, but what differs is what gets built underneath it.

Insights