Points of Focus
- A quantum-resistant Bitcoin transaction was mined on mainnet for the first time.
- The scheme needs no protocol changes but costs $75-$150 per transaction.
- StarkWare’s own co-founder said Bitcoin still needs an actual soft fork.
A transaction built using StarkWare researcher Avihu Levy’s Quantum-Safe Bitcoin scheme was confirmed in block 964199 on Bitcoin mainnet on Aug. 27.
A few months later – a Quantum Safe Bitcoin tx on mainnet: https://t.co/qbrXRYXTd6
Thanks to StarkWare's @giladi_tom85141 taking this to the finish line and @MARAFoundation_ Slipstream mining this non-standard tx
Also @robin_linus & @Ethan_Heilman on previous work led to QSB https://t.co/cRHzUEOAIk— Avihu Levy ✨🐺 (@avihu28) August 26, 2026
This marks the first real-world test of a transaction structure designed to survive an attack from a quantum computer running Shor’s algorithm, a method capable of breaking the Elliptic Curve Digital Signature Algorithm (ECDSA) that secures ordinary Bitcoin transactions today.
How Bitcoin’s quantum-safe transaction actually works
The scheme, called QSB, requires no changes to Bitcoin’s consensus rules and operates entirely within existing script limits. It builds on an earlier scheme called Binohash, published in April 2026, which secured transactions with a puzzle based on ECDSA signature sizes, a puzzle a working quantum computer could still break.
QSB replaces that puzzle with one based on RIPEMD-160, a hashing algorithm named for the RACE Integrity Primitives Evaluation Message Digest project that created it, since Shor’s algorithm offers no advantage against hash-based problems the way it does against elliptic curve cryptography.
The tradeoff is real. Solving the puzzle costs $75-$150 in cloud graphics processing unit (GPU) compute per transaction, and the resulting transaction exceeds Bitcoin’s standard relay policy, meaning it needs direct submission to a mining pool rather than normal broadcast.
Yesterday’s transaction reached the network through MARA Foundation’s Slipstream service for exactly that reason. The scheme achieves roughly 118-bit security against a quantum adversary, short of the 128-bit-plus threshold the US National Institute of Standards and Technology (NIST) generally targets in its own post-quantum cryptography standards.
Why quantum resistance matters for billions in Bitcoin
The stakes behind this work are already quantified.
As per CoinMarketCap data, roughly a third of all Bitcoin supply sits in addresses with publicly exposed keys, vulnerable in principle to exactly the kind of attack QSB defends against, including an estimated 1.7 million coins in early Pay-to-Public-Key (P2PK) addresses worth $74 billion, some believed to belong to Bitcoin’s creator.
Bitcoin Improvement Proposal (BIP) 360, which introduced a new quantum-resistant address format, merged into Bitcoin’s proposal repository in February 2026. A companion proposal, BIP-361, separately outlined a multi-year plan to migrate or eventually freeze coins in vulnerable addresses that never move to the new format.
What QSB’s creators say it does and doesn’t prove
That broader effort is exactly what StarkWare co-founder Eli Ben-Sasson pointed to in response to yesterday’s transaction. He called it an important achievement but warned it “should not be viewed as a message saying “Bitcoin is prepared for the quantum threat,” arguing instead that the real fix requires the network to “get serious about serious soft forks,” a direct reference to the BIP-360 and BIP-361 track already underway rather than per-transaction workarounds like QSB.
A Quantum Safe Bitcoin tx on mainnet — Amazing!
Two important things about this important tx:
(1) It took a lot of work by Avihu and StarkWare engineers to actually get this tx mined, and thanks to @MARAFoundation_ for their Slipstream service.
This kind of quantum-safe… https://t.co/FC23TPAy9w— Eli Ben-Sasson | Starknet.io (@EliBenSasson) August 27, 2026
QSB proves a quantum-resistant Bitcoin transaction is possible today without waiting for network-wide consensus on a new address format. It doesn’t make that protection available at scale, cheaply, or by default, and its creators are saying so publicly rather than letting mainnet confirmation speak for itself.
Ethereum researchers opened a comparable early-stage proposal for post-quantum validator keys just days ago, using a different approach entirely, a future protocol upgrade rather than a present-day workaround, evidence that this is now a live design question across more than one major blockchain rather than a Bitcoin-specific concern.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


