A BIS team successfully tested post-quantum cryptographic signatures inside TARGET2, Europe’s central bank settlement system processing over two trillion euros daily, rejecting forged transfers while valid ones cleared. However, replacing RSA-2048 signatures with CRYSTALS-Dilithium equivalents expanded signature sizes roughly thirteenfold, overrunning legacy message headers and slowing verification.
The wholesale digital euro infrastructure, branded Pontes, is scheduled for launch in Q3 2026 and will bridge private tokenised asset platforms with central bank settlement. Separately, longer-term efforts under the Appia roadmap target a fully integrated European tokenised financial ecosystem by 2028, though its governance and standards questions remain unresolved.
Sometime last December a small team at the BIS pushed post-quantum signatures through TARGET2, the Eurosystem settlement backbone that moves north of two trillion euros a day between Europe’s central banks. Every test passed. Signed transfers went through, forged ones got rejected, the lattice math did its job. Then they measured what it cost to run, and that is the part worth your time.
This is the half of Europe’s money overhaul almost nobody outside finance is tracking. The retail digital euro soaks up all the political oxygen, the holding caps, the privacy fights, the surveillance panic, which I pulled apart in a separate piece on the retail digital euro. Meanwhile the wholesale rails and the quantum-resilience work are quietly further along and, for my money, the more interesting story if you care about the silicon and the cryptography underneath rather than the Brussels theatre on top.
What actually broke in Project Leap
Project Leap Phase 2 was the Eurosystem, with Banca d’Italia, Banque de France, the Bundesbank, Nexi-Colt and Swift, swapping the classical digital signatures on TARGET2 liquidity transfers for post-quantum ones. They ran it hybrid, meaning the old RSA signature and the new quantum-safe one side by side, belt and braces, so that if one scheme falls the other still stands. Sensible. Also expensive.
Here is the bit that bites. Replacing an RSA-2048 signature, all of 256 bytes, with a CRYSTALS-Dilithium one blew the signature up to roughly 3,300 bytes. About thirteen times bigger, sitting inside a message header that TARGET2’s legacy ESMIG connector was never built to carry, and which only accepts one cryptographic algorithm at a time anyway. Headers overran their buffers. Verification ran meaningfully slower, partly because the hybrid hedge means doing the whole signature dance twice. Chunks of the plumbing had to be redeveloped before any of it ran clean. And they couldn’t even test the newer standardised ML-DSA variant yet, which matters more than it sounds, because ML-DSA is the leaner, finalised version of exactly the thing they were stress-testing.
None of that is a failure. It is precisely what you run a controlled trial in 2025 to discover, instead of finding out on the day a quantum computer makes RSA worthless. The uncomfortable read is just that the financial system’s pipes were laid in an era when 256-byte signatures were the whole world, and quantum-safe crypto does not fit through them without surgery.
The part that’s actually my lane: making the crypto small and fast enough
This is where I stop caring about monetary policy and start caring, because the bottleneck stops being legal and becomes a silicon problem, and that I can talk about.
ML-DSA is the standardised name for Dilithium, written into NIST’s FIPS 204. At its smallest parameter set, ML-DSA-44, you get a 1,312-byte public key and a 2,420-byte signature. Leaner than the Round 3 Dilithium that choked ESMIG, but still an order of magnitude past RSA, and the verification cost is real. In most implementations 60 to 80 percent of the time is spent inside the hash function, not the lattice math, which is the kind of detail that tells you where to push.
So people are pushing there. The sharpest example I have seen is ML-DSA-B, a variant out of Project Eleven and Taurus, with the BLAKE3 designers in the room, that does one thing: rip out ML-DSA’s internal SHAKE hashing and drop in BLAKE3 instead. Preliminary benchmarks have message pre-hashing up to 60 times faster, signing around 20 percent quicker, verification roughly 30 percent. Same security assumptions, just a faster hash doing the heavy lifting. I want to be clear this is a research initiative, not a standard and absolutely not something the ECB has blessed for the euro. But it is the shape of how the latency gap closes, and it closes fast.
The other half is hardware. Dedicated PQC cores, the kind you drop into an FPGA or burn into an ASIC, already exist in two flavours that map perfectly onto this problem: a “fast” profile chewing through thousands of signatures a second for settlement-scale verification, and a “tiny” profile for constrained secure elements. That second one is the interesting one, because the offline digital euro stores its bearer tokens in exactly those secure elements, the AVA_VAN.5 high-assurance chips, and those have brutal limits on key size, signature size and power budget. A compact, constant-time PQC core, constant-time meaning its runtime does not leak the secret through timing, is more or less the only way you get post-quantum signing into a phone’s secure enclave without wrecking the battery or opening a side channel. This is the quiet reason the Eurosystem keeps hammering “cryptographic agility” as a design principle. They are not committing to an algorithm. They are building the system so they can swap whatever wins, once the optimisation race settles, without ripping the architecture apart. Given they can’t even name the algorithm yet, that is the only honest way to build it.
Pontes: the wholesale euro that ships first
Forget 2029. The wholesale euro lands in Q3 2026, and it has a name: Pontes. It is the Eurosystem’s bridge between private DLT platforms, where tokenised securities and collateral increasingly live, and TARGET Services, where central bank money actually settles. They stitched it together from the three solutions trialled in 2024: the Bundesbank’s trigger approach, the Banque de France’s full-DLT DL3S, and the Banca d’Italia’s TIPS Hash-Link.
Mechanically it runs a dual model. A participant parks real central bank money in a TARGET account, gets matching cash tokens minted into a Dedicated Cash Wallet on the Eurosystem’s permissioned DLT, and spends those tokens to settle the cash leg of a tokenised trade. Final legal settlement still lands back in T2, which is what keeps it bulletproof. The Hash-Link protocol ties the asset leg and the cash leg together so they either both complete or neither does, which is the entire point of delivery-versus-payment and the thing private stablecoins cannot credibly offer against a central bank balance sheet. The 2024 exploratory run that fed all this settled about 1.6 billion euros across 64 participants, so this is not a whiteboard exercise. User testing with the market is slated to start around August 2026, just ahead of go-live.
Why bother? Same reason as the retail euro, aimed somewhere far more consequential. If tokenised bond and collateral markets take off settling in dollar stablecoins or on foreign rails, Europe loses its grip on the safest layer of its own financial system. Pontes is the move to keep that settlement anchored in central bank money while the market is still small enough to steer.
Appia: the 2028 promise I’m not betting the farm on
Pontes is the bridge you cross now. Appia is the road being paved behind it, and it is much further out. The Eurosystem dropped the Appia roadmap in March, ran a consultation that closed in late April, and is aiming to publish a full blueprint in 2028. The pitch is a genuinely integrated European tokenised ecosystem: shared DLT infrastructure, or interoperable networks, carrying central bank money, commercial bank money and tokenised assets together, with programmability and atomic settlement and round-the-clock operation baked in rather than bolted on. They named it after the Via Appia, the Roman road, and Cipollone keeps calling it a road from today’s system to tomorrow’s tokenised markets. Cute, and the etymology actually works, since Pontes is Latin for bridges.
The real fight inside Appia is not technology, it is standards and governance. Whether Europe ends up with one shared ledger or a mesh of interoperable ones, who governs that network layer, and whether the standards are open enough to avoid quietly handing the keys to a foreign infrastructure provider. That is where the strategic-autonomy argument lives or dies. But it is a 2028 blueprint, which in practice means a vision document followed by years of building, and I have watched enough central-bank DLT pilots get quietly shelved to keep my enthusiasm on a leash until there is running code. I’m not getting into the cross-border interoperability angle here, how Appia would talk to other jurisdictions’ systems is its own tangle and its own post.
Where this leaves us
The quantum work and Pontes are the competent, shipping, unglamorous part of this whole effort, and they barely make the news because there is no surveillance scare to hang a headline on. The retail digital euro is the loud one, but it is capped, walled inside the eurozone, and three years out. The wholesale rails move real money this year, and the crypto-resilience testing is ahead of almost everyone, warts and all.
What I keep turning over is which threat actually arrives first. The politics could stall the retail euro indefinitely, and a sufficiently large quantum computer could turn every legacy RSA signature in the system into confetti. Project Leap is a bet that the second problem is worth solving years before it bites. Watching the signatures balloon and the old connectors choke, I think they’re right to be early, and I also think the gap between “we proved it works” and “it runs at two trillion euros a day without a hitch” is wider than the press releases let on. Ask me again when Pontes has a few months of real settlement behind it.