Skip to content
    Skip to content

    Moody's Warns Quantum Computers Could Trigger $3 Trillion Financial ShockMoody's Warns Quantum Computers Could Trigger $3 Trillion Financial ShockMoody's Warns Quantum Computers Could Trigger $3 Trillion Financial ShockMoody's Warns Quantum Computers Could Trigger $3 Trillion Financial Shock

    AL
    Aria Lin

    May 20, 2026

    A new sector report from Moody's Ratings warns that a quantum-enabled disruption of payment infrastructure connected to Fedwire could generate between $2 trillion and $3 trillion in indirect economic losses, according to analysis from the Citi Institute cited within the report.

    Moody's Warns Quantum Computers Could Trigger $3 Trillion Financial Shock

    A new sector report from Moody's Ratings warns that a quantum-enabled disruption of payment infrastructure connected to Fedwire could generate between $2 trillion and $3 trillion in indirect economic losses, according to analysis from the Citi Institute cited within the report. The number buried in that finding is harder to dismiss than most: Fedwire processes hundreds of millions of transfers totaling more than one quadrillion dollars annually, according to Federal Reserve data. What makes this a financial stability story rather than a physics story is timing: the most dangerous quantum attack vector, "harvest now, decrypt later" (HNDL), may already be underway, silently accumulating encrypted financial data for decryption once capable quantum hardware matures.

    What Happened

    Moody's Ratings published a sector report this week assessing quantum computing risk across digital finance. The report frames quantum risk not as a distant technology curiosity but as a systemic concern requiring near-term institutional action, even though quantum computers capable of breaking current encryption remain years away from demonstrated capability.

    The backdrop the report establishes matters. Recent attacks on digital finance infrastructure have already been damaging at scale: the Bybit exchange suffered a theft of approximately $1.5 billion disclosed in 2025, and Coinbase disclosed a major data breach in late 2024. Neither attack exploited quantum computing. Both exploited operational weaknesses: third-party vendor access, key management failures, software dependencies. Moody's uses these incidents to establish the baseline threat environment into which quantum capability will eventually arrive.

    The report's central analytical move is a distinction between what quantum computers threaten and what they do not. Blockchain consensus mechanisms are assessed as less immediately vulnerable. The cryptographic controls surrounding blockchain infrastructure -- including the public-key systems securing wallets, custody platforms, transaction signatures, APIs, and inter-institutional communications -- are where the exposure concentrates.

    Moody's analysts wrote: "As digital finance markets attract a growing share of institutional clientele, cyber risk linked to blockchain-based platforms has evolved from a niche risk to one that is mainstream." The report positions this as a sector-wide concern rather than a risk any single institution can manage in isolation.

    close-up of a cryogenic quantum processor suspended inside a dilution refrigerator, gold superconducting circuit traces visible on the chip surface, cool blue ambient light, macro lens

    The Technical Threat

    The cryptographic systems underpinning modern financial infrastructure -- primarily RSA and elliptic curve cryptography (ECC) -- derive their security from mathematical problems that classical computers cannot solve at scale within any practical timeframe. RSA security depends on the difficulty of factoring the product of two large prime numbers.

    Shor's algorithm, designed for quantum computers, is the best-known cryptanalytic method against RSA. A sufficiently powerful, error-corrected quantum computer running Shor's algorithm could derive private cryptographic keys from public information, enabling unauthorized access to wallets, custody systems, and the digital signatures used to authorize financial transactions. It would not require attacking blockchain consensus directly. It would attack the keys.

    As of 2026, quantum computers lack the processing power to execute this attack against real-world key sizes. The threat remains constrained by hardware limitations including error correction rates, qubit scalability, and engineering talent shortages. But Moody's does not treat that gap as comfortable. The report's concern centers on the long replacement cycles of financial infrastructure: systems deployed today may still be operating when capable quantum hardware arrives.

    HNDL is the bridge between today and that future. Adversaries can collect encrypted financial data now and store it until decryption becomes feasible. For data with long confidentiality lifetimes, the attack is already relevant. In 2024, NIST released the first three finalized post-quantum cryptography (PQC) standards, including ML-KEM (Kyber) and ML-DSA (Dilithium), providing the algorithmic foundation institutions need for migration.

    JPMorgan Chase is testing PQC algorithms alongside existing systems and building what the report describes as "crypto-agile" infrastructure: systems engineered to rapidly swap out vulnerable encryption methods as standards evolve. HSBC has conducted quantum key distribution (QKD) trials, including quantum-secure communications for internal systems and simulated foreign exchange transactions. QKD exploits quantum mechanics properties -- including the no-cloning theorem and measurement-disturbance -- to make eavesdropping physically detectable, a fundamentally different security model from classical cryptography.

    Why It Matters for Industry

    The $2 trillion to $3 trillion indirect loss estimate from the Citi Institute represents the downstream economic damage from a quantum disruption of Fedwire-connected infrastructure, not just direct theft. Fedwire is the United States Federal Reserve's real-time gross settlement system and the backbone of institutional dollar transfers. A sustained disruption of systems dependent on its connected cryptographic infrastructure would propagate losses across counterparties, payment chains, and collateral positions far beyond any single institution's balance sheet.

    Moody's framing is explicit that the risk is systemic. Custodians, exchanges, stablecoin issuers, and tokenization platforms face greater quantum exposure than the underlying blockchain consensus systems because their operations are more directly tied to cryptographic key control. Cross-chain bridges, APIs, and oracles are identified as additional high-value concentration points connecting private and public financial infrastructure.

    An additional structural asymmetry compounds the risk for digital finance specifically: public blockchain transactions are effectively irreversible once finalized. The freeze-and-reversal options available to traditional financial institutions following a cyberattack do not exist in the same form on most blockchain infrastructure. A successful quantum-enabled theft of a private key is not recoverable through the same mechanisms that contained the Bybit and Coinbase incidents.

    Moody's analysts stated: "Delayed investment in cyber resilience or cryptographic preparedness could translate into higher remediation costs, greater supervisory pressure, or erosion of market trust as institutional exposure grows."

    Mosca's Theorem, a framework for estimating migration urgency, compares the time required to complete a cryptographic transition (X), the duration over which the data must remain secure (Y), and the estimated time until a capable quantum computer arrives (Z). When X plus Y exceeds Z, migration is urgent. For financial data with multi-year confidentiality requirements, that calculation already produces concerning outputs even with conservative quantum timeline assumptions.

    close-up of fiber optic cables inside an active financial data center server rack, dense bundled cables carrying live data traffic, cool blue and white ambient light, shallow depth of field

    Competitive Landscape

    JPMorgan Chase and HSBC are the two institutions Moody's names as early movers. Their positions are instructive not because their specific technical implementations are detailed in the report but because of the framing Moody's applies to them: institutions inventorying cryptographic dependencies and testing PQC are described as building toward resilience, while institutions that have not begun that work face growing exposure as institutional digital finance adoption scales.

    Moody's positions cryptographic preparedness as a credit and reputational differentiator. That framing carries weight for the industry. When a major ratings agency incorporates a preparedness dimension into its sector risk assessments, the signal reaches beyond IT departments to treasury, compliance, and board risk committees.

    The sector report drew parallel coverage from Industrial Cyber, which noted the transition to PQC "will be long and costly" and acknowledged the quantum threat to asymmetric encryption remains currently mitigated by hardware limitations. Tech Monitor covered the enterprise unpreparedness angle, describing enterprises as broadly unprepared for quantum computing risk. Neither the quantum threat nor institutional unpreparedness is a new observation. What is new is its presence in a Moody's sector report with a systemic loss figure attached.

    Independent analyst commentary specifically on this announcement was not publicly available at publication time.

    The Bigger Picture

    Regulatory momentum across three jurisdictions reinforces Moody's risk framing. The EU's Digital Operational Resilience Act (DORA) took effect in January 2025, covering a broad range of financial entities including crypto-asset service providers, credit institutions, and investment firms. Its ICT risk management, incident reporting, resilience testing, and third-party risk requirements create an institutional framework within which cryptographic dependency assessments will increasingly surface, even though DORA does not currently mandate PQC migration specifically.

    The Monetary Authority of Singapore has been encouraging institutions to assess their cryptographic dependencies and develop PQC migration plans. The Bank for International Settlements (BIS) and G7 nations are participating in financial institution quantum preparedness initiatives, though the specific scope of those initiatives is not detailed in the Moody's report.

    Moody's positions this regulatory momentum as a leading indicator. No jurisdiction is currently mandating immediate PQC migration. But the report's framing suggests that preparedness will shift from voluntary to supervised as institutional crypto adoption continues to grow and as the timeline to capable quantum hardware shortens.

    The systemic risk framing matters for how institutions should classify this internally. This is not an IT refresh cycle. The replacement of RSA and ECC across financial infrastructure requires inventorying every system that uses public-key cryptography, including:

      • Wallet and custody platform key management systems
      • API authentication between institutions and infrastructure providers
      • Software signing and update verification pipelines
      • Inter-institutional communication channels
      • Cross-chain bridges, oracles, and third-party data feeds

    close-up of a rack-mounted hardware security module inside a financial data center, blinking status LEDs on encrypted network appliances, cool blue ambient light, shallow depth of field

    What's Next

    For financial institutions, the report's actionable implication is a cryptographic inventory. Before any institution can build crypto-agile infrastructure of the kind JPMorgan Chase is developing, it needs to know which systems rely on RSA or ECC and on what timeline those systems can be migrated to NIST-standardized PQC algorithms such as ML-KEM and ML-DSA.

    The HNDL threat makes that inventory time-sensitive in a way that classical cybersecurity threats do not. A conventional data breach exposes data that exists at the moment of compromise. An HNDL adversary is collecting encrypted data that becomes readable later. Sensitive financial communications, custody records, and transaction data encrypted today under vulnerable algorithms carry forward a latent exposure that no future migration will retroactively eliminate.

    The institutions best positioned are those that begin migration planning now, before capable quantum hardware exists, because the infrastructure replacement cycles involved are measured in years, not months. JPMorgan's crypto-agile architecture and HSBC's QKD trials represent the early end of that adoption curve. The majority of custodians, exchanges, and tokenization platforms have not yet reached that stage.

    For IT decision-makers and risk officers at financial institutions: The Moody's report signals that quantum cryptographic risk is moving from a research budget line to a balance sheet line. The concrete action items are: (1) inventory all public-key cryptographic dependencies across systems, vendors, and third-party integrations; (2) assess which data currently encrypted under RSA or ECC has a confidentiality lifetime extending past a plausible quantum horizon; (3) begin testing NIST PQC standards (ML-KEM, ML-DSA) in non-production environments; and (4) build toward crypto-agile architecture capable of algorithm substitution without full system replacement. Regulatory pressure from DORA and MAS will intensify. The cost differential between proactive migration and reactive remediation, once supervisory action is involved, will be substantial.

    The $2 to $3 trillion figure from the Citi Institute is the one that should focus institutional attention. That estimate does not describe what quantum computers will steal. It describes what breaks downstream when the infrastructure that moves money stops working. The attack surface is not a blockchain. It is the cryptographic layer that nobody sees until it fails.

    -- Aria Lin, Enterprise Technology Analyst


    Sources: The Quantum Insider -- Moody's Report Warns Quantum Threat Could Reshape Digital Finance Risk

    More on Revuzia