G7 Quantum Warning: What It Means for Crypto Financial Statements
The G7 has put the crypto industry on formal notice: quantum computing is no longer a distant theoretical risk, and firms that hold or report on digital assets need to start acting now. For accounting practices, CFOs, and auditors working with crypto financial statements under IFRS or US GAAP, that notice translates into a concrete set of disclosure, valuation, and audit questions that cannot wait for quantum computers to actually arrive.
What the G7 Actually Said
G7 finance and technology bodies issued a coordinated warning in early September 2026 stating that advances in quantum computing represent a credible medium-term threat to the cryptographic protocols that underpin public blockchain networks, digital wallets, and the transaction-signing mechanisms that give crypto assets their fundamental security properties.
The warning stopped short of setting a hard deadline, but it was explicit that the window for migration to post-quantum cryptographic standards is shorter than many industry participants assume. Governments within the G7 are already moving: several member states have either adopted or are actively piloting post-quantum cryptography frameworks aligned with the National Institute of Standards and Technology (NIST) standards finalised in 2024.
Why This Is a Financial Reporting Event, Not Just a Technology Event
The instinct in accounting circles is to treat quantum risk as an IT or operational matter. That instinct is wrong, at least partially. The moment a recognised standard-setter or a multilateral body of the G7's authority characterises a risk as credible and material, preparers of financial statements have an obligation to consider whether that risk needs to be reflected in their reports. Ignoring a G7-level warning in your next set of accounts is a position that will be hard to defend to auditors or regulators.
Three specific areas of crypto financial reporting are directly in scope: fair-value measurement of crypto assets, the adequacy of risk disclosures, and the assessment of custody arrangements underpinning asset recognition.
IFRS Crypto Assets and the Quantum Disclosure Gap
Under current IFRS, most crypto assets held by entities are accounted for either as intangible assets under IAS 38 or, where an entity is a broker-trader, as inventory under IAS 2. The IASB's dedicated crypto asset project has been progressing slowly, and in the interim preparers rely on IAS 1 for presentation and IFRS 7 for financial instrument-style risk disclosures where applicable.
IAS 1 and Material Uncertainty
IAS 1 requires disclosure of information about assumptions and estimation uncertainty that carry a significant risk of causing a material adjustment to carrying amounts in the next financial year. A G7-level warning about the structural security of blockchain infrastructure is precisely the kind of assumption-affecting event that IAS 1 paragraph 125 is designed to capture. If your entity holds crypto assets at a carrying amount that would be materially affected if quantum attacks became feasible within, say, five years, that needs to be articulated in the notes.
This does not mean you need to impair assets today. It means the nature of the risk, the entity's exposure, and the steps being taken to mitigate it should be disclosed in a way that is specific rather than boilerplate. Generic "technology risk" language in a treasury note will not satisfy an auditor who has read the G7 statement.
IFRS 7 and Concentration of Custodial Risk
Where entities apply IFRS 7 by analogy to their crypto holdings, the standard requires qualitative and quantitative disclosures about the nature and extent of risks. Quantum risk introduces a new dimension to custodial risk: the possibility that private keys held in custody arrangements relying on current elliptic-curve cryptography could, in a post-quantum environment, be exposed. Preparers should consider whether their IFRS 7 disclosures adequately describe the custodian's roadmap for post-quantum migration and any contractual protections in place.
For firms following the ESMA's 2026 crypto monitoring priorities and what they signal for IFRS preparers, the regulator's increased focus on the robustness of crypto disclosures makes this even more timely.
US GAAP: ASC 350-60 and Fair Value Under Quantum Uncertainty
US entities holding crypto assets now account for them at fair value through net income under ASC 350-60, the FASB standard that took effect for fiscal years beginning after 15 December 2024. Fair value under ASC 820 is an exit-price concept: what a market participant would pay in an orderly transaction at the measurement date.
What Quantum Risk Does to the ASC 820 Analysis
A Level 1 fair-value input for Bitcoin or Ether is typically the quoted price on an active exchange. In the short term, that price already incorporates market participants' collective assessment of all known risks, including quantum. If the G7 statement causes market-wide repricing, that reprices your crypto financial statements automatically. The more nuanced question is whether the unit of account and the valuation premise still hold if the underlying cryptographic security of the asset is genuinely called into question by a credible authority.
The FASB's own guidance on ASC 820 notes that market participants are assumed to be knowledgeable about the asset. A G7 warning is the kind of publicly available information that a knowledgeable market participant would factor in. Preparers should document that their fair-value process considered this information, even if the quoted price did not move materially at the measurement date.
ASC 350-60 Disclosure Requirements
ASC 350-60 requires disclosure of the cost basis of crypto assets held, realised and unrealised gains and losses, and the nature of restrictions. The standard does not yet have explicit quantum-risk disclosure requirements, but the general financial statement disclosure requirements under ASC 275 (risks and uncertainties) are relevant. ASC 275 requires disclosure of certain significant estimates and of concentrations of risk from particular technologies. Quantum risk arguably fits both categories for any entity with material crypto holdings.
The FASB stablecoin cash-equivalent proposal and its GAAP implications is another live standard-setting thread that US preparers should track alongside the quantum discussion, given that stablecoins rely on the same cryptographic infrastructure.
Audit Implications: What Auditors Need to Challenge
Auditors of entities with material crypto holdings face a specific challenge when a multilateral body of the G7's standing issues a warning of this nature. The auditor's responsibility under ISA 570 (or its US PCAOB equivalent) is to consider whether management has appropriately identified risks that could affect the going-concern assessment. Quantum risk is unlikely to trigger a going-concern qualification for most entities in the near term, but it is the kind of risk that should feature in the auditor's risk assessment and be evidenced in the audit file.
Key Audit Matters and Enhanced Procedures
For entities where crypto assets are a significant line item, auditors should consider whether quantum risk warrants inclusion as a key audit matter (KAM) under ISA 701, or a critical audit matter (CAM) under PCAOB AS 3101. The threshold is whether the matter involved especially challenging, subjective, or complex auditor judgment. Assessing the adequacy of post-quantum migration disclosures, and evaluating whether the custodian's infrastructure is fit for purpose against a credible multi-government threat assessment, clearly meets that bar for large crypto holdings.
Practically, enhanced procedures could include obtaining representations from custodians about their post-quantum cryptography roadmap, reviewing any third-party assurance reports (SOC 2 or equivalent) for references to quantum resilience, and assessing whether management's disclosures are specific enough to be useful to a reader of the financial statements.
Custody Arrangements and Asset Recognition
One underappreciated accounting question is whether the quantum threat affects the recognition of crypto assets on the balance sheet at all. Asset recognition under both IFRS and US GAAP requires that the entity controls the asset. Control of a crypto asset is exercised through possession of the private key. If the private key could, in theory, be compromised by a quantum-capable adversary within a timeframe that is no longer remote, does that affect the control assertion?
Near-Term vs. Remote Risk
The honest answer is that current expert consensus still places practical quantum attacks on widely used elliptic-curve cryptography at least several years away, even under optimistic assumptions about hardware progress. The G7 warning does not contradict this; it urges preparation precisely because migration takes time. So derecognition of crypto assets on quantum grounds is not a live issue today. What is live is the disclosure of the pathway: has the custodian committed to migrating to post-quantum standards, and by when?
Accounting firms advising clients should be asking custodians for written confirmation of their post-quantum migration timelines and ensuring that this is documented in client files. This protects both the client and the firm in any future regulatory review.
Practical Steps for Accounting Firms and CFOs
The G7 warning creates an immediate action list, even before any standard-setter formally updates guidance on crypto financial statements.
Disclosure Review
Review all existing risk disclosure language in crypto-related notes. Replace any generic technology-risk boilerplate with specific language that acknowledges the quantum threat, describes the entity's current cryptographic exposure, and references the steps being taken to monitor and respond to post-quantum standards development. Where the entity relies on a third-party custodian, disclose that custodian's stated approach to post-quantum migration.
Custodian Due Diligence
Request documentation from all crypto custodians on their post-quantum cryptography roadmap, including planned adoption timelines for NIST-approved post-quantum algorithms. Confirm whether existing custody agreements contain any provisions addressing cryptographic standard obsolescence. If they do not, consider whether amendments or additional contractual protections are warranted before the next contract renewal.
Internal Accounting Policy Updates
Accounting policies for crypto assets, whether under IFRS crypto assets guidance or ASC 350-60 for US GAAP, should be updated to include quantum risk as a named risk factor in the entity's internal risk register. This feeds directly into the financial statement disclosure process and ensures the risk is formally considered at each reporting date rather than treated as a one-off disclosure event.
Engagement with Standard-Setters
Both the IASB and FASB have active crypto asset projects. The G7 warning is the kind of development that is likely to accelerate requests for explicit quantum-risk disclosure guidance. Accounting firms with the capacity to do so should consider submitting comment letters or participating in consultations to shape how this guidance develops, rather than waiting to apply whatever standard eventually emerges.
Frequently Asked Questions
Does the G7 quantum warning require immediate impairment of crypto assets under IFRS?
No. The G7 warning does not indicate that quantum attacks on current blockchain cryptography are imminent in the short term. Impairment of intangible assets under IAS 36 requires evidence that the recoverable amount is below the carrying amount at the reporting date. What the warning does require is a careful assessment of whether the risk needs to be disclosed under IAS 1 as a source of estimation uncertainty, and whether existing risk disclosures are sufficiently specific to be useful to readers of the financial statements.
How does quantum risk interact with ASC 350-60 fair-value measurement under US GAAP?
Under ASC 350-60, crypto assets are measured at fair value using quoted market prices where available (Level 1 inputs under ASC 820). Quantum risk is a factor that market participants are assumed to consider, so if it causes market-wide repricing, fair value adjusts automatically. The key documentation requirement is that preparers evidence their fair-value process considered publicly available information, including the G7 statement, even if quoted prices did not move materially at the measurement date. Separate qualitative disclosure under ASC 275 on concentrations of technology risk is also worth reviewing.
Should auditors include quantum risk as a key audit matter or critical audit matter?
For entities where crypto assets are a significant balance-sheet item, auditors should actively consider whether quantum risk meets the threshold for a KAM under ISA 701 or a CAM under PCAOB AS 3101. The assessment turns on whether evaluating the adequacy of post-quantum migration disclosures and custodian infrastructure involved especially challenging or subjective judgment. For material crypto holdings, that bar is likely met, and the matter should at minimum be evidenced in the audit file regardless of whether it appears in the audit report.
What should accounting firms do when reviewing client custody arrangements in light of the G7 warning?
Firms should request written confirmation from custodians of their post-quantum cryptography migration timeline, including planned adoption of NIST-approved post-quantum algorithms. They should also review whether existing custody contracts contain any provisions on cryptographic standard obsolescence. If contracts are silent, firms should advise clients to seek amendments or clarifications at the next renewal. All of this should be documented in client files to support both the audit opinion and any future regulatory review of the entity's risk management disclosures.
Which NIST post-quantum cryptography standards are relevant to blockchain and digital asset custody?
NIST finalised its first set of post-quantum cryptographic standards in 2024, covering lattice-based and hash-based algorithms designed to resist attacks from quantum computers. Blockchain networks and custodians will eventually need to migrate transaction-signing and key-derivation mechanisms to these or equivalent standards. The migration is technically complex and time-consuming, which is precisely why the G7 is urging early preparation. Accounting firms and CFOs should ask custodians specifically whether their roadmaps reference NIST post-quantum standards and what testing or implementation phases they have completed.
Source: Decrypt
