Hong Kong Banks Score Low on Quantum Security Readiness

Regulator sets sectorwide migration target as tokenized finance expands
TL;DR
- Hong Kong’s banking sector received a quantum-preparedness score of 2.3 out of 10.
- The Hong Kong Monetary Authority wants banks to reach full preparedness by 2030.
- The initiative comes as banks expand tokenized deposits, digital-asset custody and blockchain settlement infrastructure.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Hong Kong’s banking sector remains at an early stage of preparing for quantum-computing threats, receiving an overall readiness score of 2.3 out of 10 as the city moves more deposits, securities and settlement activity onto cryptography-dependent financial infrastructure.
The Hong Kong Monetary Authority published a white paper on July 27, 2026, introducing the banking industry’s first Quantum Preparedness Index during the eighth FiNETech conference. The assessment was based on a survey conducted earlier in the year and measured institutions across four stages: awareness, planning, pilot implementation and practical preparedness.
The HKMA wants the banking sector to reach a score of 10 out of 10 by 2030, representing full sectorwide preparedness for risks associated with quantum computing. The current result indicates that most institutions are still identifying their exposure, educating decision-makers or developing initial plans rather than deploying operational post-quantum protections.
Quantum-related risks had reached board-level discussions at approximately half of the surveyed institutions, but those discussions had not produced widespread technical implementation. Most banks remained focused on establishing governance, identifying affected systems and building institutional knowledge rather than conducting full cryptographic migrations.
The index does not indicate that banks are currently being breached by quantum computers. It measures whether institutions have identified their cryptographic dependencies, created migration road maps, tested replacement technologies and developed the ability to respond before quantum systems become capable of compromising widely used encryption and digital-signature methods.
HKMA pushes banks toward post-quantum migration
The HKMA is developing a post-quantum cryptography toolkit with the Hong Kong University of Science and Technology’s business school. The toolkit is intended to give banks practical guidance for evaluating existing cryptographic infrastructure and preparing systems for algorithms designed to withstand quantum attacks.
The regulator also plans to organize workshops and skills-development programs aimed at improving technical expertise and supporting responsible experimentation. The findings suggest that limited hands-on experience remains a significant obstacle because awareness of quantum risks is more common than active testing or implementation.
A central part of the initiative is cryptographic agility, or the ability to identify and replace vulnerable algorithms without rebuilding entire technology systems. Banks are being encouraged to inventory encryption protocols, digital-signature systems, authentication mechanisms, certificates, keys, network connections and dependencies on external technology providers.
The HKMA urged institutions to begin risk assessments and migration planning before a sufficiently powerful quantum computer becomes available. Cryptography is embedded across payment networks, customer authentication, transaction authorization, confidential communications, stored data, hardware modules and connections with external service providers, making migration a multiyear operational undertaking.
Banks may need to coordinate changes across internal applications, cloud platforms, payment networks, hardware manufacturers, software vendors and financial counterparties. Institutions could also need to operate traditional and post-quantum algorithms at the same time during the transition so upgraded systems remain compatible with counterparties that have not completed their own migrations.
Hybrid cryptographic systems may provide an interim approach by combining existing algorithms with post-quantum methods. The most urgent priorities include systems protecting long-lived confidential information, high-value payment instructions, institutional custody operations and digital signatures that cannot easily be replaced after exposure.
Banks must also distinguish between data requiring short-term protection and records that must remain confidential for many years. Information with long-term sensitivity faces greater exposure to attacks in which encrypted data is stolen now and retained until more powerful computing systems can decrypt it.
We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!
Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.
Existing cryptography faces a future structural threat
Modern financial infrastructure relies heavily on RSA and elliptic-curve cryptography. A sufficiently capable quantum computer using Shor’s algorithm could theoretically undermine those systems by deriving private cryptographic keys from publicly available information.
Such an attack could allow a malicious actor to decrypt confidential information, impersonate an authorized party or forge the digital signatures used to approve financial transactions. Those signatures help banks verify identities, authorize payments, validate instructions, protect communications and establish trust between institutions.
Distributed ledgers and tokenized assets face related exposure because they use cryptographic signatures to establish ownership and authorize transfers. If those protections were defeated, attackers could potentially falsify approvals, gain control of assets linked to exposed keys or damage confidence in blockchain-based financial infrastructure.
The white paper said payment systems and distributed-ledger applications rely on cryptography for essential functions and could face serious disruption if those protections were compromised. No practical, large-scale quantum computer capable of breaking the cryptography used by banks or major public blockchains currently exists.
Estimates cited in the coverage suggested that a practical threat could emerge as early as 2029, although the timing depends on major advances in hardware and engineering.
Another risk is the “harvest now, decrypt later” model, under which attackers collect encrypted information and retain it until future quantum systems can read it. That threat makes preparation relevant before a cryptographically capable quantum computer exists because financial information stolen today may remain sensitive for years.
Potentially exposed records include customer information, transaction histories, internal communications, authentication records, legal documents and other confidential material with long-term value. The Bank for International Settlements’ Project Leap has characterized this collection strategy as an immediate threat to the financial system.
Public blockchains such as Bitcoin and Ethereum rely on digital signatures to prove ownership and authorize transactions, exposing them to the same underlying category of cryptographic risk. The available information did not indicate that either network had been compromised by quantum computing.
Early testing begins as tokenization grows
One surveyed Hong Kong institution completed a proof of concept applying post-quantum cryptography to distributed-ledger connectivity. The project provided an early example of how quantum-resistant protections could be tested within blockchain-linked banking systems.
The white paper also cited HSBC’s 2024 use of quantum-safe technology to transfer tokenized gold across distributed ledgers. That implementation showed that post-quantum controls were beginning to move from theoretical research into controlled financial applications.
Hong Kong’s preparedness initiative comes as the city expands the use of tokenized deposits, digital-asset custody, tokenized securities and blockchain settlement. That growth increases the amount of financial activity dependent on encryption, digital signatures, private keys and distributed-ledger transaction validation.
The HKMA launched its Fintech 2030 strategy in 2025, naming tokenization as one of four strategic pillars in a program containing more than 40 initiatives. The authority intends to expand real-world asset tokenization, make tokenized government-bond issuance a regular activity and examine tokenized Exchange Fund papers.
Planned settlement infrastructure is expected to incorporate the e-HKD, tokenized commercial-bank deposits and regulated stablecoins. The quantum-preparedness program therefore supports the security of a wider financial strategy rather than operating as a standalone technology project.
Hong Kong has issued three batches of tokenized green bonds since 2023, with a combined value of HK$16.8 billion, or approximately $2.1 billion. The issuances show that distributed-ledger infrastructure is already being used for institutional capital-market activity.
Project Ensemble is also advancing wholesale tokenization and interoperability between tokenized money and tokenized assets. The initiative could connect banks, tokenized deposits, real-world assets and distributed-ledger platforms through shared cryptographic infrastructure.
Hong Kong Financial Secretary Paul Chan disclosed those banking-sector figures during a February 11, 2026 speech. The growth in custody and tokenized deposits means banks are becoming responsible for larger pools of assets whose ownership, movement and settlement depend on cryptographic controls.
A successful quantum-related compromise could affect confidential records, custody arrangements, settlement instructions, token ownership records and digitally signed transactions. The HKMA’s migration timetable gives institutions a limited period to identify vulnerable cryptography, classify risks, select replacement standards, coordinate with suppliers and test compatibility.
Smaller banks may face particular challenges because they have fewer cybersecurity specialists, greater reliance on external service providers and less capacity to conduct independent post-quantum research. Larger institutions may have more technical resources but operate broader legacy environments containing more systems and counterparties that require assessment.
Third-party concentration could create additional exposure if multiple banks depend on the same cloud platforms, payment processors, hardware-security modules or software vendors. Sector readiness therefore depends on technology suppliers, infrastructure operators and cross-border counterparties adopting compatible standards alongside individual banks.
Hong Kong banks also connect with international payment networks and financial institutions that may follow different migration schedules. A bank could complete its own upgrades while remaining exposed through counterparties or providers that continue using vulnerable algorithms.
Cross-border coordination will be particularly important for digital signatures, certificates, interbank messaging and tokenized-asset settlement. Cryptographic systems must remain compatible across institutions to prevent security upgrades from interrupting legitimate financial transactions.
Governments establish parallel migration timelines
Hong Kong’s approach is developing alongside similar government initiatives overseas. President Donald Trump signed two executive orders addressing quantum computing and post-quantum security.
One order was intended to accelerate U.S. quantum-computing development and reportedly targeted a machine capable of scientific research by 2028. The second directed the federal government toward a post-quantum cryptography migration during 2030–2031.
The overlapping schedules place the late 2020s and early 2030s at the center of government preparation efforts. The immediate policy issue is whether institutions can complete complex cryptographic migrations before quantum systems become capable of defeating protections used across financial networks.
Hong Kong’s challenge is particularly direct because its financial authorities are expanding tokenized bonds, deposits, regulated digital assets and blockchain settlement while the banking sector remains near the beginning of its quantum-readiness process.
The HKMA’s response centers on establishing a shared benchmark, documenting cryptographic dependencies, creating formal migration plans, running technical pilots, training specialists and moving institutions toward operational preparedness.
No quantum-computing attack against a Hong Kong bank was identified, and no evidence indicated that RSA, elliptic-curve cryptography, Bitcoin, Ethereum or Hong Kong’s tokenized financial infrastructure had already been broken in practice.
FAQ
What does the Quantum Preparedness Index measure?
It measures banks’ progress across awareness, planning, pilot implementation and practical preparedness.
Why does tokenization increase quantum-security concerns?
Tokenized financial systems depend on digital signatures, encryption and cryptographic keys.
What is “harvest now, decrypt later”?
Attackers steal encrypted data today and retain it until future technology can decrypt it.
How is the HKMA supporting banks?
It is developing a toolkit, workshops and skills programs for post-quantum migration.
This article has been refined and enhanced by ChatGPT.