StarkWare announced on Wednesday that it executed the first Bitcoin transaction built to withstand a quantum computer. The firm moved 3.1 BTC on mainnet, confirmed in block 964,199, using a lock based on hash functions instead of elliptic curves. The demonstration shows a working defense already exists, with zero changes to the Bitcoin protocol. It also shows how expensive and impractical that defense remains for everyday use.
Key Takeaways
- StarkWare moved 3.1 BTC in a quantum-resistant Bitcoin transaction, mined in block 964,199.
- Avihu Levy’s QSB scheme relies on hash functions and works without any protocol change.
- It stays a last-resort tool: hours of GPU grinding and a format standard nodes refuse to relay.
StarkWare Moves 3.1 BTC Inside Block 964,199
The milestone slipped by while the market stayed glued to price charts. StarkWare, the firm best known for its work on cryptographic proofs, executed a Bitcoin transaction whose signature cannot be forged by a quantum computer under Bitcoin’s current rules.
The transfer moved 3.1 BTC and was confirmed in block 964,199. It ran on Quantum Safe Bitcoin (QSB), a scheme designed by Avihu Levy, StarkWare’s chief product officer and co-author of ColliderScript. Levy had published the method in April in the GitHub repository that documents the full QSB scheme.
The stakes are anything but academic. A quantum machine able to crack exposed public keys threatens a meaningful share of existing addresses, a risk we already mapped in our look at the quantum threat hanging over 7 million BTC. A live transaction that closes that attack vector, even as an experiment, moves the debate onto new ground.
The technical shift is easy to frame. A classic signature leans on elliptic curves, which Shor’s algorithm can break once quantum hardware gets powerful enough. The QSB lock leans on the pre-image resistance of hash functions instead. Quantum computers know how to attack the former. They have no shortcut against the latter.
Timing matters here too. The scheme went from an April paper to a mainnet Bitcoin transaction in roughly four months. In an ecosystem where technical proposals routinely spend years stuck in forums and mailing lists, that turnaround is unusually fast.
Hours of GPU Grinding for a Single Spend
Protection at this level carries a heavy price tag. The method relies on brute-force search, testing millions of signature candidates until one emerges that exposes none of the public key material. Levy’s benchmarks show a top-end RTX PRO 6000 card churning through 238 million candidates per second, and the process still demands hours of compute for a single transaction.
The repository estimates that off-chain search at $75 to $150 in cloud GPU costs per spend. The bill keeps growing on-chain: the operation requires two transactions totaling around 11,000 vB, close to 80 times the size of a standard SegWit transaction. Every quantum-proof spend eats a serious chunk of block space.
There is a routing problem on top. The format does not match the standard templates that network nodes agree to relay, so the transaction had to be handed directly to a miner, MARA, through its Slipstream service. The episode is a reminder that block inclusion ultimately sits with the operators who build the blocks, a dynamic already on display in the state takeover of mining pools in Oman.
Two design choices soften the blow. The whole construction fits inside Bitcoin’s existing legacy script constraints, 201 opcodes and 10,000 bytes, which is precisely why no soft fork was needed. And the search itself is embarrassingly parallel: throw more GPUs at the problem and the wall-clock time shrinks in proportion, so the waiting time becomes a budget choice rather than a hard ceiling.
Levy owns those limitations. He framed QSB as a last-resort measure, built for funds prepared in advance, and conceded that the cost and the user experience rule out everyday use. QSB works as an emergency exit rather than a migration path.
Also on Cryptonomic:
- Iran Crypto Becomes a US Sanctions Target
- Solana Votes to Burn Ten Times More Tokens a Day
- Bitcoin Breaks $80,000 in Its Best Week Since 2023
A Last-Resort Tool While Bitcoin Waits for an Upgrade
For holders, nothing changes in the short term. Nobody can date the arrival of a quantum machine strong enough to matter, and today’s hardware remains a lab prototype. The StarkWare spend does not shield the network. It proves a fallback route already works.
Eli Ben-Sasson, StarkWare’s chief executive, framed the demonstration as psychological reassurance the asset itself needed. That message targets treasuries and institutions, where quantum exposure now sits in audit reports right next to custody risk, a lesson hammered home by the Coldcard hack earlier this summer.
The realistic audience for QSB today is narrow and well defined. It suits funds locked for the long haul and prepared in advance, the kind of cold storage a treasury sets up once and touches a decade later. For that profile, paying a three-figure compute bill to guarantee a spend stays safe in a post-quantum world is a rounding error. For an active wallet, it makes no sense at all.
The medium-term picture is where the real work starts. StarkWare noted that a protocol-level upgrade remains necessary to protect the whole network, and migrating millions of addresses to post-quantum schemes is measured in years, not months. Expect the argument over a dedicated soft fork to heat up considerably in the coming months.
Until then, every Bitcoin transaction of this kind doubles as a live stress test. The first one needed hours of grinding, a block footprint 80 times the norm and a cooperative miner willing to take a format the rest of the network ignores. The next will need a little less, and the one after that less still. That is usually how exotic protections turn into boring infrastructure, and boring infrastructure is exactly what a monetary network wants to be.
Follow the story on Cryptonomic.


