On August 26, 2026, StarkWare researcher Avihu Levy and engineer Tomer Giladi mined the first quantum-resistant Bitcoin transaction on mainnet — transaction `305a24ff…ab07`, confirmed in block 964,199 — moving 3.1 BTC using hash-based cryptography instead of elliptic-curve signatures. The method,...
"This amazing feat should not be viewed as a message saying 'Bitcoin is prepared for the quantum threat.' Far from it." — Eli Ben-Sasson, CEO, StarkWare
On August 26, 2026, StarkWare researcher Avihu Levy and engineer Tomer Giladi mined the first quantum-resistant Bitcoin transaction on mainnet — transaction 305a24ff…ab07, confirmed in block 964,199 — moving 3.1 BTC using hash-based cryptography instead of elliptic-curve signatures. The method, called Quantum Safe Bitcoin (QSB), operates within Bitcoin's existing consensus rules and requires no soft fork.
The transaction cost $75–$150 in GPU compute, required approximately six hours of processing across eight Nvidia RTX PRO 6000 cards, and had to be submitted directly to MARA's Slipstream mining service because standard Bitcoin nodes do not relay its non-standard format. StarkWare positions QSB as an interim "lifeboat" for high-value holdings, not a systemic fix. A March 2026 Google Quantum AI paper estimated that breaking Bitcoin's secp256k1 curve requires roughly 1,200–1,450 logical qubits — an order of magnitude fewer than prior estimates — pushing the post-quantum migration timeline from "someday" toward "this decade."
Approximately 6–7 million BTC ($483–$560 billion at current prices) sit in addresses with exposed public keys, according to analyses from Chaincode Labs and Coinbase's quantum advisory council. The Bitcoin Security Consortium — formed in July 2026 by BlackRock, Coinbase, Strategy, Fidelity Digital Assets, ARK Invest, Block, Blockstream, Anchorage Digital, and Galaxy — has pledged $15 million over three years to fund post-quantum research. The race between quantum hardware advancement and Bitcoin's cryptographic migration is now a measurable, funded contest.
At its core, the event is simple: StarkWare moved 3.1 BTC from one address to another on August 26, 2026. The difference is in the cryptography. Standard Bitcoin transactions rely on the Elliptic Curve Digital Signature Algorithm (ECDSA) over the secp256k1 curve. A sufficiently powerful quantum computer running Shor's algorithm could derive a private key from its corresponding public key, rendering ECDSA-secured holdings spendable by an attacker. QSB replaces this vulnerable step with hash-based security.
Transaction 305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07 was confirmed by MARA's mining pool via its Slipstream service, which accepts non-standard transaction formats that the broader Bitcoin mempool would reject. Levy first published the QSB concept and open-source code in April 2026, inspired by Robin Linus's Binohash technique. The August 26 transaction moved the project from whitepaper to working implementation.
"People have long assumed that protecting Bitcoin holdings from a quantum adversary would require changing the Bitcoin protocol," Levy stated in StarkWare's announcement. The transaction demonstrated otherwise, at least for individual holdings.
QSB employs two core techniques: Lamport-style hash-based signatures and signature grinding.
Hash-based signatures. Instead of relying on the difficulty of the elliptic curve discrete logarithm problem (which Shor's algorithm efficiently solves), QSB uses Lamport-style signatures that derive their security from hash functions. Hash functions are not susceptible to known quantum attacks. The scheme provides approximately 118-bit quantum resistance, according to StarkWare's technical documentation.
Signature grinding. This is the computationally expensive step. The method repeatedly generates signature candidates until one appears with specific mathematical properties that limit exposure of public-key material while the transaction waits in Bitcoin's mempool. This brute-force search is what demands hours of GPU time. The grinding process ensures that an adversary — even one with a quantum computer — cannot extract usable cryptographic material from the broadcast transaction before it is confirmed.
Protocol compatibility. QSB operates within Bitcoin's existing 201-opcode and 10,000-byte script limits. No consensus rule change is required. This is both its strength and its limitation: it works today, but the workarounds impose significant cost and complexity penalties.
Critical constraint. QSB protects coins only after they are moved into a special output. It does not retroactively protect ordinary ECDSA- or Schnorr-secured holdings. Addresses with previously published public keys remain vulnerable until funds are manually transferred using the QSB method.
| Parameter | Value | |-----------|-------| | GPU compute cost per transaction | $75–$150 | | Processing time | ~6 hours | | Hardware required | 8x Nvidia RTX PRO 6000 GPUs | | Quantum resistance level | ~118-bit | | Protocol change required | None | | Standard mempool relay | Not supported | | Mining pathway | Direct submission (MARA Slipstream) |
At $75–$150 per transaction, QSB is economically viable only for large holdings. A Bitcoin whale moving $10 million in BTC pays a negligible fraction of a percent. An everyday user sending $500 pays 15–30% of the transaction value in quantum-proofing costs alone, before standard network fees.
The requirement to submit transactions directly to a cooperating mining pool — bypassing the standard peer-to-peer mempool — introduces centralization risk and counterparty dependency. Only MARA's Slipstream currently supports the non-standard format.
There is also a race-condition vulnerability: when moving coins from a quantum-vulnerable address to a QSB-protected output, the original public key may be briefly exposed during the broadcast-to-confirmation window. A quantum adversary with sufficient speed could theoretically derive the private key and broadcast a competing transaction in that interval.
The timeline for cryptographically relevant quantum computers (CRQCs) has compressed significantly in 2026.
Google Quantum AI's March 2026 paper demonstrated that breaking secp256k1 requires roughly 1,200–1,450 logical qubits and 70–90 million Toffoli gates — approximately 10x fewer resources than prior estimates. Independent researchers have since improved on Google's optimization. Current hardware (Google's Willow chip: 105 physical qubits; IBM's systems: ~1,000+ physical qubits) remains far short of this threshold, but the gap is narrowing.
DARPA stated in March 2026 that it now "seems more likely than not" that someone will build a utility-scale quantum computer by 2033.
Physical-to-logical qubit conversion remains the key bottleneck. Each logical qubit requires 100–1,000 physical qubits for error correction. Breaking secp256k1 at 1,200 logical qubits therefore requires 120,000–1.2 million physical qubits with current error-correction techniques. Current machines operate at approximately 1,000 physical qubits — a gap of 100–1,200x.
The threat acts on signatures, not on mining. Grover's algorithm could theoretically accelerate SHA-256 mining, but the speedup (quadratic, not exponential) is insufficient to break Bitcoin's proof-of-work at practical scales.
Not all Bitcoin is equally vulnerable. The risk depends on whether an address's public key has been exposed on-chain.
| Category | BTC Exposed | % of Supply | Primary Risk | |----------|-------------|-------------|--------------| | P2PK addresses (early Bitcoin) | ~1.72M BTC | ~8.2% | Public key permanently on-chain | | Reused addresses (various types) | ~4.9M BTC | ~23.3% | Public key revealed upon first spend | | Total estimated exposure | ~6.04–6.7M BTC | ~30–34% | | | Estimated value at risk | $483–$560B | — | At current prices |
According to Chaincode Labs research, approximately 6.26 million BTC could be exposed due to reused public keys. Coinbase's quantum advisory council estimated roughly 7 million BTC as vulnerable, per a June 2024 analysis. Over 1.1 million BTC attributed to Satoshi Nakamoto sit in early P2PK addresses with permanently exposed public keys.
The primary danger, according to StarkWare, is not theft alone but "paralysis, as a cryptographic break could leave vulnerable coins stranded and unable to be spent." If quantum capability emerges suddenly, a scramble to move exposed coins could congest the network and expose more keys in the process.
QSB is one of several approaches competing to address Bitcoin's quantum vulnerability. The others require protocol-level changes.
BIP-360 (Pay-to-Merkle-Root). Merged into Bitcoin's official BIP repository in February 2026, with a live testnet since March 2026. BIP-360 introduces a new output type where the cryptographic key is never visible — not even when funds are spent. Deployable via a new SegWit witness version as a soft fork. This is considered the most comprehensive protocol-level proposal.
SHRINCS. Blockstream Research's Jonas Nick published this BIP on August 27, 2026 — one day after the QSB mainnet transaction. SHRINCS is a concrete post-quantum signature scheme proposal; Blockstream ran a live test transaction on Liquid mainnet in March 2026. The opcode proposal, OP_CHECKSHRINCS, was introduced in May 2026.
BIP-347 (OP_CAT). Proposes reintroducing the OP_CAT opcode (removed by Satoshi in 2010) into Tapscript, enabling Lamport signatures — the same hash-based scheme underlying QSB — natively within Bitcoin's script language.
The proposals are not mutually exclusive. QSB works today without consensus changes. BIP-360 and SHRINCS require soft forks but offer cleaner, more scalable solutions. OP_CAT enables broader programmability beyond quantum resistance.
Ben-Sasson stated: "I still want Bitcoin to choose to do a soft fork and I expect we will get one. What today's successful transaction offers Bitcoin is a reassurance that holdings can be protected before that happens."
The institutional response to Bitcoin's quantum risk has materialized into concrete capital commitments.
Bitcoin Security Consortium (formed July 23, 2026): Nine firms — BlackRock, Coinbase, Strategy, Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets, and Galaxy — pledged $15 million over three years. Each member independently directs its funding toward developers, researchers, or organizations of its choosing. Day-to-day coordination is managed by Mike Schmidt, executive director of Brink (a Bitcoin open-source developer nonprofit), in a volunteer capacity.
Galaxy separately launched a $5 million initiative specifically for quantum-resistant signatures, wallet migration tools, and security audits.
STRK token (Starknet's native token) climbed approximately 4.5% to $0.027 following the QSB announcement before retreating — a modest reaction suggesting markets view the development as technically significant but commercially limited.
Combined declared funding for Bitcoin post-quantum work now stands at $20 million. Whether this is adequate for the scope of the challenge remains an open question. For comparison, the U.S. National Science Foundation alone allocated $40 million for post-quantum cryptography research in fiscal year 2025.
The QSB transaction on block 964,199 is a proof of concept, not a solution. It demonstrates that hash-based cryptography can secure Bitcoin holdings within the existing protocol — but at costs and complexity levels that confine it to emergency use by large holders.
The more consequential developments are structural: Google's 10x reduction in estimated attack resources, BIP-360's arrival on testnet, Blockstream's SHRINCS proposal, and $20 million in institutional capital earmarked for post-quantum defense. These represent the supply side of Bitcoin's quantum migration. The demand side — urgency, consensus, and deployment timelines — remains governed by the pace of quantum hardware development and Bitcoin's historically slow governance processes.
The gap between current quantum hardware (~1,000 physical qubits) and the estimated attack threshold (~120,000–1.2 million physical qubits) provides a window measured in years, not months. DARPA's 2033 estimate for utility-scale quantum computing suggests 7 years or fewer. Bitcoin's last major soft fork (Taproot) took approximately 3.5 years from proposal to activation.
The arithmetic is uncomfortable but not yet critical. Whether Bitcoin's governance can complete a post-quantum migration before the window closes is the central question. QSB buys time. It does not buy certainty.