On October 6, the Banca d'Italia is hosting the annual Financial Cryptography in Rome conference (FCiR26) at Rome's Centro Carlo Azeglio Ciampi, co-organized with the association De Cifris. The event brings together academics, researchers, and experts from central banks and international institutions to examine applied cryptography in finance. Among the declared topics: the transition to post-quantum cryptography, quantum risks for public blockchains, and privacy-preserving encryption techniques in the public sector. This matters to crypto investors and developers. The framing deserves care: FCiR26 is a scientific conference, not a policy statement by the central bank on Bitcoin or digital assets.
What Was Announced, and What Was Not
The source is a page published by the Banca d'Italia on September 30. It names the date, the organizers, and the objective: gathering scholars, academics, and central bank experts to present recent advances in cryptography applied to finance. The event takes place at the Centro Carlo Azeglio Ciampi in Rome. As of the time of writing, no agenda, speakers list, or conference materials have been published, and the central bank has issued no statement on Bitcoin or any other digital asset.

It's worth drawing a clear line between what we know and what would be overreach. We know that post-quantum cryptography and risks to public networks are on the agenda. What we don't know is what will actually be said, by whom, or whether any operational guidance will emerge. A scientific conference is a venue for comparing research, not for setting rules.
A Recurring Conference, with a Thread on Privacy
FCiR is an annual fixture. The 2025 edition was held on October 1 at the same Centro Ciampi, with a welcome address by Giuseppe Zingrillo, Director General for Information Technology at the Banca d'Italia, published on the institution's website the same day. That edition was chaired by Michela Iezzi for the Banca d'Italia and Massimiliano Sala for De Cifris. The scientific committee included experts from Ripple, J.P. Morgan, BNP Paribas, and Offchain Labs. The 2024 edition was a joint workshop held inside the CIFRIS24 conference in Frascati. De Cifris (short for De Componendis Cifris) is a nonprofit Italian scientific association dedicated to promoting cryptography. Separately, on October 5, Rome Tre University hosted CIFRIS26, the fourth national conference of De Cifris, with a representative of Italy's National Cybersecurity Agency among the chairs.

Privacy has been a recurring theme for the Banca d'Italia. On September 29, the bank published Working Paper No. 93 on privacy and verifiability in digital payments, which we covered in our deep-dive on zero-knowledge proofs. The paper's authors include Matteo Nardelli, Francesco De Sclavis, and Michela Iezzi. Iezzi chaired FCiR25, and Nardelli served on its scientific committee. Whether those two bodies of work are formally connected in today's agenda isn't known. What is clear is that the same names appear across the Banca d'Italia's applied cryptography research.

Why the Quantum Threat Matters for Blockchains
The risk analysts discuss isn't that a quantum computer would break mining. The concern is more specific: that a sufficiently powerful quantum machine could forge the digital signatures that prove ownership of funds. On Bitcoin, those are elliptic curve signatures using ECDSA and Schnorr. Ethereum uses analogous schemes. The exposure is greatest for coins whose public keys are already visible on-chain. No quantum computer today is capable of mounting that kind of attack, and expert estimates on when one might be vary widely.

On the standards front, NIST published its first three post-quantum cryptography standards in August 2024 and, per its transition roadmap, plans to retire algorithms vulnerable to quantum computers from its approved list by 2035, with high-risk systems expected to migrate considerably earlier. On the network side, Bitcoin has BIP-360, which entered the official BIP repository on February 11, 2026 but has not yet been activated; it introduces a quantum-resistant output type. A companion draft, BIP-361, published April 14, outlines a phased migration away from current signature schemes. Bitcoin has no network-wide deadline. Ethereum has set December 2029 as its target for making the base layer quantum-resistant. CoinDesk clarifies, though, that none of this implies a quantum computer capable of stealing bitcoin or ether is expected by 2029: migrating already-exposed wallets and keys could itself take years.
The European Framework: The Supervisory Authorities’ Report
The issue has now reached official supervisory documents. On September 23, the three European financial supervisory authorities, EBA, EIOPA, and ESMA, published their autumn update on risks and vulnerabilities in the EU financial system (document JC 2026 29), the same report that produced the alert on dependence on non-EU digital providers we covered previously. In the section covering cyber risks, AI models, and quantum computing, the authorities write that quantum computing presents opportunities, but that the potential threats justify early action on existing systems. According to CoinDesk’s account of the report, the document warns that an advanced quantum computer could compromise cryptographic systems widely used to protect communications, transactions, databases, and blockchains, and that threats could materialize before any useful commercial application emerges.
[CHART 2, see note below]
FCiR26 at a Glance
What is confirmed and what is not. Source: Banca d’Italia, September 30, 2026
- Confirmed: conference on October 6, Banca d’Italia with De Cifris; topics: post-quantum cryptography, quantum risks for public blockchains, privacy in the public sector.
- Not yet available: agenda, speakers, and materials had not been published at the time of writing.
- Not the case: this does not represent an official central bank position on Bitcoin or crypto assets.
The Bigger Picture
Quantum risk has moved, within a matter of months, from developer forums to supervisory risk registers and standardization body timelines, and now holds a place on a central bank conference agenda. That Banca d’Italia is co-hosting the event alongside a scientific association says something about how the institution approaches the technology: as a subject for research, before it becomes one for regulation.
Two distinct lessons emerge for observers. First, separate the topic from any specific timeline: no quantum computer today can break these signature schemes, and even the nearest stated target, Ethereum’s 2029 goal per its own roadmap, concerns preparation rather than an imminent threat. Second, notice that the conversation has shifted from “whether” to “how”: with NIST standards already published, concrete proposals like BIP-360 in the repository, and supervisors citing the issue in formal documents, the open question is who migrates, when, and at what cost, including the practical burden of much larger signature sizes. We will follow any interventions or materials Banca d’Italia releases over the course of the event.





