StarkWare confirmed on August 26 that a quantum-resistant Bitcoin transaction settled in block 964,199 on mainnet — the first such transaction executed without any protocol change. The transaction, which spent a 10,000-satoshi output using the Quantum Safe Bitcoin (QSB) scheme developed by StarkW...
"Levy's method can assist the network until it implements a permanent fork." — Eli Ben-Sasson, CEO, StarkWare
StarkWare confirmed on August 26 that a quantum-resistant Bitcoin transaction settled in block 964,199 on mainnet — the first such transaction executed without any protocol change. The transaction, which spent a 10,000-satoshi output using the Quantum Safe Bitcoin (QSB) scheme developed by StarkWare CPO Avihu Levy, was mined by MARA Pool via its Slipstream direct-submission service. No soft fork, no hard fork, no consensus rule modification was required.
The demonstration arrives five months after a Google Quantum AI paper cut the estimated qubit requirement for breaking Bitcoin's elliptic-curve cryptography by 20x, compressing what was once a multi-decade threat horizon into a plausible single-digit-year window. An estimated 6.2–6.9 million BTC — roughly $490–545 billion at current prices — sit in wallets with exposed public keys, according to figures cited in the Google paper and a January 2026 Citi Institute report. The race to harden crypto's largest network against quantum attack is no longer theoretical.
On August 26, 2026, a Bitcoin transaction protected by Levy's QSB scheme was confirmed in block 964,199. The mechanism combines hash-based one-time signatures with computational searches (signature grinding on RIPEMD-160) that bind authorization to a specific transaction. The construction bypasses Bitcoin's standard ECDSA signature path entirely, offering approximately 118 bits of resistance against Shor's algorithm — the quantum algorithm that threatens elliptic-curve cryptography.
The transaction was nonstandard. Ordinary Bitcoin nodes would not relay it through the mempool. Instead, it was submitted directly to MARA Pool through its Slipstream service, which accepts nonstandard transactions for a fee. StarkWare estimates the cost at $75–$150 in GPU compute per transaction.
At that price point, QSB is not a consumer product. It is a proof of concept demonstrating that Bitcoin's existing consensus rules can accommodate quantum-resistant spending without a protocol upgrade — a significant technical distinction. The practical implication: high-value holders with exposed public keys could, in theory, use QSB to migrate funds to safer outputs today, without waiting for BIP-360 or any fork.
Three papers published between January and March 2026 materially shortened the estimated timeline for a cryptographically relevant quantum computer (CRQC).
Google Quantum AI (March 30, 2026): Researchers from Google, the Ethereum Foundation, and Stanford published "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities," presenting two optimized quantum circuits for solving the 256-bit Elliptic Curve Discrete Logarithm Problem (ECDLP-256) on secp256k1 — the curve underpinning both Bitcoin and Ethereum signatures. The circuits require fewer than 500,000 physical qubits, a roughly 20x reduction from prior best estimates. Runtime on a superconducting architecture: minutes, not hours. The paper models a real-time transaction hijacking attack with a 41% success rate within Bitcoin's 10-minute block confirmation window.
Citi Institute (January 2026): The report "Quantum Threat: The Trillion-Dollar Security Race Is On" estimates a quantum-enabled cyberattack on a major U.S. bank's access to Fedwire could put $2.0–$3.3 trillion of U.S. GDP at risk. For crypto specifically, Citi estimates roughly 25% of Bitcoin supply is quantum-exposed due to on-chain public key visibility.
The Quantum Insider (March 31, 2026): A review of three papers published in three months argued collectively that "Q-Day" — the date a quantum computer can break production cryptography — had moved meaningfully closer, though no source commits to a specific year.
The consensus among researchers cited in these publications: the threat is not imminent in 2026, but it is no longer a multi-decade abstraction. Estimates cluster around the late 2020s to early 2030s, with substantial uncertainty.
Not all Bitcoin is equally vulnerable. The quantum threat via Shor's algorithm targets exposed public keys — those already visible on-chain. This includes:
According to the Google paper, approximately 6.9 million BTC — 32% of total supply — sits in wallets with exposed public keys. At Bitcoin's current price near $78,800, that represents roughly $544 billion in exposed value. The Citi Institute's estimate is slightly lower at 4.5–6.7 million BTC ($355–528 billion), or approximately 25% of supply.
Coins in SegWit and Taproot addresses that have never sent a transaction are not immediately vulnerable, as their public keys remain hidden behind hash functions. However, those hash functions themselves face longer-term quantum risk via Grover's algorithm, which halves their effective security — reducing SHA-256 from 256-bit to an effective 128-bit security level.
BIP-360, authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, was merged into the official Bitcoin BIPs repository on February 11, 2026. Merge signals that the proposal meets documentation standards for formal discussion, not that activation is imminent.
BIP-360 introduces Pay-to-Merkle-Root (P2MR), a Taproot-like output type with the quantum-vulnerable key path removed. The design uses SegWit version 2 outputs and is intended to support post-quantum signature schemes such as CRYSTALS-Dilithium, Falcon, or SPHINCS+.
Implementation status as of August 2026:
The gap between BIP-360's formal documentation status and actual deployment is wide. Bitcoin's consensus change process requires sustained community agreement, extensive testing, and miner signaling — a timeline measured in years, not months.
Ethereum's approach differs structurally. In February 2026, Vitalik Buterin published a roadmap identifying four cryptographic components requiring post-quantum upgrades:
The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026, led by Thomas Coratger. The target for core protocol infrastructure hardening is approximately 2029. Four internal teams and more than ten independent developer groups are working on weekly test networks, according to the Foundation.
Account abstraction gives Ethereum a structural advantage: individual accounts can switch to post-quantum signature schemes without waiting for a protocol-wide hard fork. This opt-in migration path does not exist in Bitcoin's current architecture, which is one reason StarkWare's QSB workaround — however expensive — has drawn attention.
The practical barrier to post-quantum blockchain adoption is not algorithmic — NIST finalized three post-quantum standards in August 2024 (FIPS 203, 204, 205). The barrier is size.
NIST's primary digital signature standard, ML-DSA (formerly CRYSTALS-Dilithium), produces signatures of 2,420–4,627 bytes depending on security level. Bitcoin's current ECDSA signatures are 71–73 bytes. Replacing ECDSA with Dilithium at equivalent block sizes would reduce effective transaction throughput by 80–90%, according to estimates cited by Yellow Research.
SPHINCS+, the hash-based alternative (FIPS 205), is worse: signatures range from 7,856 to 49,856 bytes. Falcon, a lattice-based scheme under NIST consideration, is more compact at roughly 690 bytes but requires careful constant-time implementation to avoid side-channel attacks.
This is not merely a theoretical concern. Block size increases require consensus changes — the same process that produced Bitcoin's 2017 SegWit fork after years of contentious debate. Any post-quantum migration will necessarily reopen the block size question.
The StarkWare QSB transaction is a narrow technical achievement with broad strategic implications. It proves that Bitcoin's consensus rules, as they exist today, can accommodate quantum-resistant spending — but at a cost ($75–$150 per transaction) and complexity (direct miner submission, nonstandard format) that limits practical use to high-value migration scenarios.
The larger picture is that three independent research efforts in early 2026 compressed the quantum threat timeline from "decades away" to "plausibly within this decade." The crypto industry's two largest networks are responding with fundamentally different architectures: Bitcoin through a formal but slow BIP process with no activation date, and Ethereum through modular account abstraction with a 2029 target.
The economic value at stake — $490–545 billion in quantum-exposed Bitcoin alone — makes this the largest single-vulnerability exposure in cryptocurrency history. The solutions exist in draft form. The question is whether governance and deployment can outpace hardware advancement.