On August 26, 2026, StarkWare researcher Avihu Levy mined the first quantum-resistant transaction on the Bitcoin mainnet — transaction 305a24ff…ab07, confirmed in block 964,199. The transaction used hash-based cryptography instead of the elliptic-curve digital signature algorithm (ECDSA) that sec...
"This amazing feat should not be viewed as a message saying 'Bitcoin is prepared for the quantum threat.' Far from it." — Eli Ben-Sasson, CEO, StarkWare
On August 26, 2026, StarkWare researcher Avihu Levy mined the first quantum-resistant transaction on the Bitcoin mainnet — transaction 305a24ff…ab07, confirmed in block 964,199. The transaction used hash-based cryptography instead of the elliptic-curve digital signature algorithm (ECDSA) that secures all standard Bitcoin transactions, requiring no soft fork, no new opcodes, and no changes to Bitcoin's consensus rules. The method, called Quantum-Safe Bitcoin (QSB), ran entirely within Bitcoin's existing legacy Script constraints of 201 opcodes and 10,000 bytes.
The achievement is narrow in scope. QSB protects only coins moved into its special output format going forward. It does not retrofit quantum resistance onto the estimated 6.7 million BTC — roughly one-third of circulating supply — that already sit in addresses with exposed public keys. At current compute costs of several hundred dollars per transaction, the method is impractical for everyday use. A protocol-level upgrade remains necessary.
This report examines the technical mechanics of the QSB transaction, the state of Bitcoin's quantum vulnerability, competing mitigation strategies across major blockchains, and what these developments mean for the $1.56 trillion Bitcoin network.
Transaction ID 305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07 was mined on August 26, 2026, combining a 39,179-satoshi and 10,000-satoshi input into one 44,000-satoshi output, paying a 5,179-satoshi fee. The transaction was 1,403 bytes.
The method was designed by Avihu Levy, StarkWare's General Manager of Applications and the company's first employee, with engineering support from Tomer Giladi. Levy published the underlying research in April 2026 and described the idea as originating from a personal insight outside work hours. According to StarkWare CEO Eli Ben-Sasson: "Avihu took this on after hours, as a passion project, and has now shown that Bitcoin has no expiration date."
Because the transaction uses a nonstandard format, ordinary Bitcoin nodes will not relay it through the mempool. StarkWare submitted it through MARA Slipstream, a service operated by Marathon Digital Holdings that allows nonstandard transactions to be included directly by a miner.
Standard Bitcoin transactions prove ownership by producing an ECDSA or Schnorr signature derived from a private key. A sufficiently powerful quantum computer running Shor's algorithm could derive the private key from the public key exposed during signing, breaking this scheme entirely.
QSB replaces this mechanism with a technique called signature grinding, inspired by the Binohash algorithm developed by BitVM creator Robin Linus. The sender performs extensive off-chain computation — grinding through millions of candidate transactions — until the transaction's hash itself takes the mathematical form of a validly formatted signature. The result is a transaction that Bitcoin's Script interpreter accepts as valid without ever exposing public-key material in the mempool.
The security guarantee shifts from the secrecy of a private key to the computational difficulty of reversing a hash function — specifically RIPEMD-160. This provides approximately 118 bits of resistance against Shor's algorithm, according to StarkWare's analysis. For context, breaking 118-bit hash security with a quantum computer using Grover's algorithm would still require approximately 2^59 operations — well beyond foreseeable quantum capability.
As Levy described the approach: "A quantum computer could solve all the puzzles that secure Bitcoin. The Quantum-Safe Bitcoin method adds a second lock that a quantum computer has no shortcut for."
The vulnerability is not theoretical but has defined boundaries. According to data compiled by CoinShares and referenced by multiple analysts, approximately 6.7 to 6.9 million BTC sit in addresses where public keys have already been exposed on-chain. This represents roughly one-third of Bitcoin's circulating supply, valued at approximately $145 billion based on April 2026 price data reported by CoinDesk.
The exposure breaks down into categories:
According to Coinbase's quantum advisory council, approximately 7 million BTC could be vulnerable due to exposed public keys and address reuse.
However, the practical attack surface is smaller. An analysis cited by CoinShares found that only approximately 10,200 BTC sit in UTXOs large enough to cause appreciable market disruption if stolen, while the remaining ~1.6 million P2PK coins are spread across individual ~50 BTC UTXOs.
In March 2026, Google Quantum AI, in collaboration with Stanford University and the Ethereum Foundation, published a 57-page paper that reduced by 20x the estimated physical resources needed to crack 256-bit elliptic-curve cryptography. The paper found that fewer than 1,200 logical qubits and 90 million Toffoli gates could in principle solve the elliptic-curve discrete logarithm problem underlying Bitcoin's ECDSA signatures.
Translated to hardware: a quantum computer with approximately 500,000 physical qubits could crack a Bitcoin private key in roughly 9 minutes — within Bitcoin's 10-minute block time, according to Forbes' reporting on the paper. Google's Willow chip, its latest 105-qubit superconducting processor, is the first to achieve consistent below-threshold error correction, meaning additional qubits decrease rather than increase the error rate.
The most optimistic hardware projections do not place 500,000-qubit machines before 2033-2035. Blockstream CEO Adam Back estimates the real threat window at 20-40 years. Google has internally moved its post-quantum transition deadline to 2029.
The gap between theoretical feasibility and engineering reality remains wide. But the Google paper compressed the timeline meaningfully, and multiple institutions are now treating preparation as a near-term engineering priority rather than a distant theoretical exercise.
BIP-360, authored by Hunter Beast, was merged into Bitcoin's official repository on February 11, 2026. It introduces Pay-to-Merkle-Root (P2MR), a new output type that functions like Taproot but removes the quantum-vulnerable key-spend path. The signature scheme uses ML-DSA (CRYSTALS-Dilithium), one of the three post-quantum standards finalized by the U.S. National Institute of Standards and Technology (NIST) in August 2024.
BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 with a working BIP-360 implementation featuring P2MR transactions and Dilithium signatures. Near-term work in 2026-2027 focuses on review, refinement, and security audits within Bitcoin Core.
A companion proposal, BIP-361, published April 14, 2026, goes further. Titled "Post Quantum Migration and Legacy Signature Sunset," it proposes phased restrictions: blocking legacy transfers after 3 years and invalidating legacy signatures after 5 years. This is the most aggressive mitigation timeline yet proposed for Bitcoin.
The contrast with StarkWare's QSB approach is instructive. QSB is available today but is expensive, nonstandard, and protects only coins explicitly moved into its format. BIP-360 requires a soft fork and ecosystem-wide adoption but would provide systemic protection. Ben-Sasson has stated plainly: "I still want Bitcoin to choose to do a soft fork and I expect we will get one. What today's successful transaction offers Bitcoin is a reassurance that holdings can be protected before that happens."
The Ethereum Foundation elevated post-quantum security to a top strategic priority in January 2026, forming a dedicated team led by Thomas Coratger. The work is tracked publicly at pq.ethereum.org and involves more than 10 client teams in weekly interoperability devnets.
Ethereum's approach centers on replacing BLS signatures with leanXMSS, a hash-based signature scheme whose security does not depend on mathematical problems that quantum computers are designed to solve. A minimal zero-knowledge virtual machine (leanVM) aggregates the larger post-quantum signatures efficiently.
The timeline: Ethereum's Hegota hard fork, expected in H2 2026, is set to introduce EIP-8141, the transaction format for post-quantum signature agility. Full migration to leanXMSS-based signatures is targeted for approximately 2029.
Other chains have moved earlier:
U.S. federal agencies face an April 2026 deadline to submit post-quantum cryptography transition plans under National Security Memorandum 10 (NSM-10), adding regulatory urgency to private-sector preparation.
The QSB method is not cheap. Each quantum-safe transaction currently costs several hundred dollars in GPU compute, as the sender must grind through millions of candidate hashes off-chain before finding a valid one. Earlier estimates cited $75-$150 per transaction; StarkWare's blog post describes costs as "several hundred dollars."
Processing a single transaction requires hours of computing. The transaction is nonstandard, meaning it cannot propagate through Bitcoin's standard mempool relay network. MARA Slipstream was required for inclusion. These constraints make QSB unsuitable as a mass-migration tool. It is, in Ben-Sasson's framing, a "lifeboat" — proof that coins can be moved to safety under threat, not a fleet-wide retrofit.
BIP-360's approach carries different costs. ML-DSA signatures are larger than ECDSA signatures — public keys range from 1.3 to 2.6 KB, and signatures from 2.4 to 4.6 KB. This increases transaction weight and, by extension, fee pressure on a block-space-constrained network. A full migration could take up to 7 years, according to BIP-361's proposed phasing.
The economics of quantum preparation are unfavorable but not prohibitive. The question is whether Bitcoin's governance mechanism — rough consensus among a decentralized set of developers, miners, and node operators — can coordinate a migration before the threat materializes.
The StarkWare transaction demonstrates that Bitcoin's scripting system is flexible enough to support quantum-resistant spending without consensus changes. That is a meaningful technical finding. It is not, as Ben-Sasson explicitly stated, a declaration that Bitcoin is quantum-safe.
The real work remains at the protocol level. BIP-360 needs review, auditing, and eventual activation through a soft fork. The 6.7 million BTC in exposed addresses need a migration path. The governance question — whether Bitcoin's leaderless development process can coordinate action before the threat becomes concrete — is arguably harder than the cryptography.
The timeline provides some comfort. No quantum computer capable of breaking ECDSA exists today, and the most aggressive projections place one at least 7 years away. But the Google paper's 20x reduction in resource estimates is a reminder that timelines compress. The blockchain industry, which manages over $2.7 trillion in aggregate market capitalization, is now treating post-quantum migration as an engineering priority, not a thought experiment.
The window for preparation is open. Whether it is used effectively depends on execution speed across fragmented governance structures — a problem no amount of cryptographic research can solve.