Financial regulators from three separate jurisdictions have started directly testing a live implementation of a newly finalised US post-quantum cryptography standard on bank wallets and cross-border digital asset transfers, in a pilot that moves the quantum-security debate from policy papers into working code.
The pilot, announced 23 August 2026 by the nonprofit Responsible Fintech Institute (RFI) and digital-asset security firm Safeheron, runs a multi-party computation protocol built to support ML-DSA-65, the NIST FIPS 204 digital signature standard that the US National Institute of Standards and Technology finalised in August 2024 as one of its first algorithms designed to resist attack from a sufficiently powerful quantum computer.
Testing covers wallet generation and on-chain transfer activity, run on a quantum-resistant version of the NEAR blockchain’s testnet rather than on production infrastructure or real customer funds.
Three regulators are named as current participants: Abu Dhabi Global Market (ADGM), Malta’s Financial Services Authority (MFSA) and the Gelephu Financial Services Office (GFSO), a financial centre established in Bhutan. Two banks, Portugal’s Bison Bank and DK Bank, are also taking part, with RFI saying additional institutions are in discussion to join.
Safeheron leads the pilot’s protocol and engineering work, and RFI leads governance and cross-jurisdiction coordination between participants. Regulators sit as observers in this first phase, moving into a governance workstream only in a later stage rather than supervising live transactions now, and the initiative plans to publish a whitepaper on its research and testing findings once complete.
Jag Foo, Safeheron’s chief security and policy officer, said the pilot integrates the NIST standard with the firm’s multi-party computation technology to build infrastructure his company intends to publish openly. “We intend to open-source our PQC code,” he said. “Cryptography securing institutional assets should stand up to independent scrutiny, not ask for trust.”
Chia Hock Lai, RFI’s chairman, framed the pilot as a shared technical reference rather than any single company’s product. “No single bank, vendor, or regulator solves this alone,” he said. “By bringing policymakers and financial institutions across jurisdictions together to test the same post-quantum architecture, and transparently sharing that research with every participant, we are building a compliance and security reference the whole industry can stand on.”
Alan Decelis, MFSA’s head of supervisory ICT risk and cybersecurity, said taking part gives the regulator a way to build its own understanding of the operational and governance questions quantum-safe migration raises before it has to supervise the transition for real.
The pilot lands alongside a wider regional focus on frontier-technology risk. On 28 July 2026, the Monetary Authority of Singapore and the Association of Banks in Singapore announced a taskforce addressing AI-driven cyber risk, a separate initiative that doesn’t cover quantum computing.
What the pilot hasn’t yet produced is independent evidence that the approach works at scale beyond a testnet, or a firm date for the open-source release Safeheron has promised.