Singapore Regulator Tells Banks to Report Their “Cryptos”

Ledger
Bybit



All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.

Singapore’s financial regulator wants banks to report their “cryptos,” but the instruction has nothing to do with disclosing Bitcoin, Ethereum or other digital-asset holdings.

TL;DR

  • Banks must catalogue their cryptographic assets.
  • “Cryptos” does not mean cryptocurrencies.
  • Phased requirements arrive later in 2026.
  • Vulnerable systems will migrate by priority.
  • Crypto networks face similar security risks.

In this case, “cryptos” refers to cryptographic assets: the encryption keys, digital certificates, signatures and algorithms protecting customer information, payment instructions and communication between financial institutions.

The Monetary Authority of Singapore will issue formal supervisory expectations later in 2026, according to Channel News Asia. Banks will receive progressive deadlines for identifying their cryptography, ranking vulnerable systems and preparing replacements that can resist future quantum attacks.

What Banks Will Need to Report

MAS is not asking banks to publish their cryptocurrency portfolios. It wants each institution to maintain an internal inventory showing where cryptography is used across its operations.

okex

That could include mobile banking systems, payment authorization, customer databases, internal communications, cloud platforms and services supplied by external technology companies.

Banks will also need to identify which systems rely on algorithms that powerful quantum computers may eventually be able to break. The most sensitive infrastructure can then be moved to the front of the migration queue.

MAS first outlined this approach in its advisory on quantum-related cybersecurity risks, which encouraged financial institutions to map their cryptographic solutions, assess vulnerable assets and review their ability to adopt new security standards.

The new supervisory expectations will turn that preparation into a more structured process with defined timelines.

The Most Exposed Systems Will Move First

Not every system carries the same risk. Infrastructure used to authorize payments or protect long-lived customer records will require more urgent attention than information that loses its value quickly.

Banks must also account for encryption built into software, hardware and services operated by outside vendors. A financial institution may understand its own systems but still depend on a technology provider that cannot support newer algorithms.

MAS expects institutions to develop the expertise and governance needed to manage those dependencies. That means assigning responsibility, coordinating with suppliers and planning for older infrastructure that cannot be upgraded easily.

The regulator is aiming for Singapore’s financial institutions to become quantum-resilient before the end of the decade. MAS managing director Chia Der Jiun said experts estimate that quantum computers capable of breaking current encryption could emerge within five to 10 years, while a safe migration may itself take years.

Why Quantum Computers Threaten Encryption

Modern banking security depends on mathematical problems that conventional computers cannot solve within a practical amount of time. These calculations protect encryption keys and digital signatures from unauthorized access.

A sufficiently powerful quantum computer could handle some of those problems far more efficiently, weakening widely used forms of public-key cryptography. Financial transactions, confidential communications and stored customer data could then become exposed.

That capability does not exist at the scale needed today. The concern is that banks cannot wait for the threat to become practical before finding and replacing cryptography spread across thousands of systems.

There is also a risk that attackers collect encrypted information now and attempt to unlock it years later. Data that must remain confidential for a long time may therefore require earlier protection.

Singapore’s Quantum-Safe Migration Handbook describes the transition as a multi-year process involving system discovery, risk assessment, testing and gradual deployment.

There Will Be No Single Quantum Upgrade

Encryption is built into almost every layer of banking infrastructure, so replacing it through one large update would create its own operational and security risks.

The transition will instead happen in phases. Banks must test how post-quantum algorithms affect processing speed, system compatibility and connections with other financial institutions before using them in live services.

They will also need crypto-agility—the ability to replace algorithms and keys without rebuilding the systems around them. Institutions with rigid or outdated infrastructure may need to modernize those systems before adding quantum-resistant protection.

The first post-quantum standards finalized by NIST provide algorithms for encryption and digital signatures, but adopting them across complex financial networks will take considerably longer than publishing the standards themselves.

Why Crypto Networks Face the Same Problem

The MAS requirements apply to financial institutions, but the underlying threat also matters to cryptocurrency networks. Blockchains depend on cryptographic signatures to prove ownership, authorize transactions and prevent funds from being moved without the correct private key.

Parts of the crypto sector are already exploring possible responses. Bitcoin developers have discussed a multi-year migration away from quantum-vulnerable wallet signatures, while a BNB Chain post-quantum test reportedly reduced cross-region throughput by about 40%, showing that stronger protection can create significant performance costs.

Banks and blockchains therefore face a similar trade-off. A new algorithm may offer stronger security, but it must still process transactions efficiently and work with existing wallets, applications and infrastructure.

Singapore Has Already Tested the Technology

Singapore’s preparation has moved beyond policy guidance. MAS and the Banque de France completed a cross-border post-quantum cryptography experiment using quantum-resistant algorithms to sign and encrypt communications over conventional internet infrastructure.

The test showed that post-quantum protection can work across existing international communication channels. Wider deployment will still require banks to update certificates, key-exchange systems and technical standards shared with other institutions.

MAS is expected to publish its detailed supervisory expectations later in 2026. The progressive timelines will cover cryptographic inventories, migration priorities and the governance needed to oversee the transition.

For crypto readers, the headline may initially sound like Singapore is asking banks to disclose their digital-asset holdings. The real policy reaches further: the regulator is preparing the security behind digital finance for a threat that could eventually affect banks, payment networks and blockchains alike.

Quantum computers cannot break modern financial encryption at scale today. Singapore is acting now because replacing that security safely may take most of the decade.





Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*