
Imagine how easy it would be for one computer to crack the encryption protecting our money. That is the threat Central Bank Digital Currencies (CBDCs) face due to quantum computing, and the quest to protect them is already underway.
Quantum computers pose a huge threat to the encryption used by Central Bank Digital Currencies (CBDCs) and other digital infrastructure. This is because the mathematics that currently underpins encryption technologies like public-key cryptography (RSA and ECC) relies on problems that are nearly unsolvable for a traditional computer, but which would be effortlessly shattered by a powerful quantum computer using an algorithm like Shor’s algorithm.
How a Quantum Attack Would Work
Most digital security, such as a CBDC, is built on a public-key infrastructure (PKI) where an individual has a public key and a private key. The public key is used to encrypt data or verify a digital signature, and the private key is used to decrypt the data or create the signature. Security depends upon the inability to compute the private key from the public one with an ordinary computer.
A sufficiently powerful quantum computer, however, would be a tremendous advantage. It would be able to use Shor’s algorithm, invented by Peter Shor in 1994, to quickly compute the private key from the public key. This would allow an attacker to:
- Forge fake transactions: The hacker could impersonate a user, creating phony transactions and stealing money.
- Decrypt stored information: Data encrypted and “harvested” today would remain secure until a quantum computer in the future can decrypt it. This is also known as a “harvest now, decrypt later” attack.
- Compromise system integrity: An attacker could dismantle the entire CBDC system by undermining its cryptographic basis, resulting in a loss of trust and disorder
The Solution: Post-Quantum Cryptography
Governments and the banking industry are aware of this threat and are working on finding a solution in the form of post-quantum cryptography (PQC). PQC defines new cryptographic schemes that are resistant to both quantum and classical computing attacks.
International bodies, such as the U.S. National Institute of Standards and Technology (NIST), are leading the charge to standardize PQC algorithms. Their goal is to construct a “quantum-safe” financial environment by moving critical infrastructure, including CBDCs, onto these new standards before quantum computers become powerful enough to pose a significant threat.
The transition to PQC will not occur overnight and will likely happen through an interim “hybrid” approach, where both classical and post-quantum algorithms are used simultaneously to offer seamless security.
Post-quantum cryptography (PQC) algorithm design and standardization is already underway, and we currently find ourselves in the first stage of implementation.
The US National Institute of Standards and Technology (NIST), coordinating the process globally, has completed the first round of its selection process and finalized standards for three key algorithms:
- ML-KEM (previously CRYSTALS-Kyber), for key agreement (encryption).
- ML-DSA (previously CRYSTALS-Dilithium), for digital signatures.
- SLH-DSA (previously SPHINCS+), also for digital signatures, as an alternative due to its unique mathematical foundation.
These specifications were finalized and made available by NIST in August 2024. A fourth algorithm, FALCON, was released later in 2024, and a fifth, HQC, in 2026. This suggests that the final, ratified designs for building quantum-safe systems are now available.
Implementation Timeline and Challenges
Although the standards are released, the wholesale rollout of PQC will take decades. Governments and large organizations have made roadmaps with projected dates:
- Now to 2028: This is discovery and planning time. Organizations are being urged to locate all cryptographic dependencies within their systems and develop a migration plan.
- 2028–2031: This is the high-priority migration window. Organizations ought to move their most critical systems and long-lived data to the new standards.
- 2035: This is the completion phase. The objective is for all systems to have completed migrating to PQC. The U.S. National Security Agency (NSA) has set 2035 as the deadline for U.S. federal agencies to finish their transition.
Installing PQC is a massive undertaking, and it is not a matter of “flipping a switch.” Some of the biggest challenges are:
- Complexity: New algorithms are more complex and require new software and hardware.
- Interoperability: Devices will need to communicate in both existing and new cryptography for transition mode, adding complexity.
- Performance: PQC algorithms often have larger key and signature sizes, impacting performance, especially on resource-constrained devices.
- Supply Chain: Firms need to ensure their vendors and suppliers are also using PQC to eliminate vulnerabilities.
By 2035, a Central Bank Digital Currency (CBDC) will be safe, but not by a simple means. That is the desired timeline to fully shift to quantum-safe cryptography. If it is not completed by then, the system would be in great danger.
The central question is not whether we have the appropriate tools, but whether the financial infrastructure complex and global as it can be fully overhauled on schedule.
The “Harvest Now, Decrypt Later” Threat
The most dangerous threat is not a cataclysmic one-day attack when a quantum computer becomes powerful. The most dangerous threat is the “harvest now, decrypt later” threat. Even if today there is no powerful quantum computer, attackers can be gathering massive amounts of encrypted data such as CBDC transactions and warehousing it. Then, with a powerful enough quantum computer in the future, they can decrypt all that warehoused data in bulk using Shor’s algorithm.
That is why this transition is not just a technical upgrade; it is a security necessity. If the world’s financial systems, including future CBDCs, do not make this switch before a large quantum computer is operational, all of that data would be at risk.
In short, a CBDC in 2035 will be safe only if the global financial community is committed to and capable of effectively implementing its PQC migration plans. The danger lies not in the technology’s presence, but in the inability to adopt it on schedule.
✓ Verified: This entry was personally compiled and reviewed by Milan Ignjatovic using primary sources.
Founder & Sole Curator, Bankinfobook | Master Manager of ICT · Graduated Economist
Last Data Review: September 16, 2025
