Ethereum post-quantum plan sets de facto 2027 deadline for banks

Sygnum custody head Thomas Brunner urges banks to start full cryptographic inventories by 2027 ahead of a possible 2029 Ethereum layer‑1 post‑quantum upgrade.

Thomas Brunner, head of custody and staking at Sygnum Bank, warned that banks may need to begin full cryptographic inventories by 2027 to prepare for a possible Ethereum layer‑1 upgrade in 2029. He said delays could lead to audit failures and operational disruption long before any quantum computer can break validator keys.

Ethereum Research has proposed replacing current BLS validator signatures with stateful, hash‑based schemes such as leanXMSS and building a post‑quantum validator‑key registry to manage the transition. BLS signatures are stateless and allow repeated signing. leanXMSS uses one‑time keys; reusing an index can reveal material that enables forgery.

U.S. National Institute of Standards and Technology guidance SP 800‑208 requires stateful hash‑based signing to occur inside hardware security modules, forbids export of private key material and expects a single instance of the private key. Those rules conflict with standard bank backup and recovery models that duplicate signing environments or restore earlier system snapshots.

Bank resilience practices-backups, replication, hot standby, failover and disaster‑recovery testing-can duplicate signing state or roll state backward. Restoring an old snapshot or failing over to a standby system can cause two systems to reuse the same one‑time signing index, which would break security assumptions for schemes like leanXMSS. NIST is working on a future revision that could allow controlled key export with mitigations, but that change is not yet available.

Brunner described a multi‑year program for banks to adapt. A complete cryptographic inventory, mapping every location where a key exists and its dependencies, typically takes six to 12 months. Banks then depend on hardware security module vendors to ship and certify post‑quantum support with reliable state handling, a process outside the bank’s control. After vendor readiness, banks must redesign key ceremonies and dual‑control procedures, obtain internal risk approvals, undergo external audits and, where required, seek supervisory review. Taken in sequence, those steps extend the timeline into multiple years; beginning an inventory in 2027 would align a bank roughly with a 2029 upgrade schedule.

Swiss regulator FINMA surveyed 60 financial institutions between November 2025 and January 2026 and found 72% had neither planned nor implemented measures for quantum‑safe encryption, while 8% had a specific roadmap. Brunner said creating a roadmap would address much of the coordination and timing risk.

Ethereum’s proposed validator‑key registry would cap the number of post‑quantum key registrations the network processes per slot to spread registrations over weeks or months; researchers have used 16 registrations per slot as a representative parameter. Ethereum Research warned that a last‑minute rush could overload the queue and leave validators unable to sign once BLS is deprecated, which could threaten finality. Brunner noted that a bank that arrives late would join the same queue as other late registrants and could not control its position.

Brunner laid out a likely sequence of failures that begins with audit and attestation breakdowns rather than immediate cryptographic compromise. If documented controls are not redesigned and retested, auditors may be unable to evidence how the bank handles client keys. That can lead to validator operations degrading or failing to produce signatures accepted by consensus, triggering staking penalties and halting onboarding of new staked ETH. Cryptographic compromise from state reuse or a future quantum attack would come later. He warned, ‘A bank that cannot describe and evidence a compliant custody process should not keep onboarding client assets into it.’

Possible outcomes depend on vendors, auditors and standards. One outcome would see hardware vendors deliver state‑aware HSMs with monotonic counters and atomic state updates, auditors accept redesigned custody controls and standards allow controlled redundancy. An alternative outcome would see banks start inventories too late, receive qualified audit findings, pause onboarding and join Ethereum’s registration queue behind other late registrants.

Articles by this author