Crypto World

StarkWare Runs Quantum-Resistant Bitcoin Spend on Mainnet

Published

on

StarkWare researcher Avihu Levy says he has successfully carried out an experimental, quantum-resistant Bitcoin transaction directly on the Bitcoin mainnet—an onchain test intended to validate a proposal originally outlined earlier this year. StarkWare described the transfer as the first transaction of its kind, using Levy’s “Quantum Safe Bitcoin” (QSB) scheme.

According to StarkWare, the transaction was confirmed Wednesday in Bitcoin block 964,199. Mempool data shows the spend used a 10,000-satoshi output protected by Levy’s QSB authorization, while MARA Pool mined the block after receiving the transaction via its Slipstream service. The test is notable not because it changed Bitcoin’s consensus rules, but because it demonstrates a quantum-resistant spending construction that can be executed within existing Bitcoin infrastructure.

Key takeaways

  • StarkWare reports an onchain QSB transaction was confirmed in Bitcoin block 964,199, marking a move from theory to a mainnet demonstration.
  • QSB is designed to be quantum-resistant without requiring a Bitcoin protocol upgrade, relying instead on transaction-level cryptographic construction.
  • The computation required to create QSB transactions remains expensive, with StarkWare estimating the final test cost in the low hundreds of dollars (around $150–$200).
  • QSB transactions are treated as nonstandard by Bitcoin Core relay policies, meaning typical nodes may not propagate them automatically.
  • Bitcoin developers are already considering protocol-level changes, including proposals such as BIP-360, that aim to reduce quantum exposure for specific spend paths.

From proposal to a confirmed mainnet spend

Levy’s QSB work combines two cryptographic ideas: hash-based one-time signatures and computational searches that bind an authorization to a specific transaction. StarkWare’s research framing is that this construction should prevent forgery even if a future quantum computer undermines the elliptic-curve cryptography used by Bitcoin today.

The onchain test matters because it shows that this specific quantum-resistant mechanism can be expressed under Bitcoin’s current consensus rules—at least in a way that results in a valid, confirmable spend. StarkWare said the demonstration was carried out without a protocol change, moving the project from “paper and code” into a working mainnet transaction.

Levy’s paper and associated code repository describe QSB in more detail, including how the one-time signature and transaction-bound authorization work together to create the security target against quantum-enabled forgery.

Advertisement

Cost and practicality: compute-heavy by design

Quantum-resistant cryptography usually involves a tradeoff: stronger security against future threats often comes with higher computational and operational costs. StarkWare’s spokesperson Nathan Jeffay told Cointelegraph that completing the tested transaction cost “low hundreds of dollars,” estimating roughly $150 to $200. StarkWare also said the overall process involved hours of computation.

This echoes earlier expectations around QSB’s resource intensity. In April, Levy introduced QSB and estimated then that generating a transaction could require between $75 and $150 in GPU computation. In the current test, StarkWare’s final estimate suggests the method is feasible for experimentation, but far from something that can scale as a default spending option for everyday users.

Levy’s approach has also been framed as a “last-resort measure” rather than a full replacement for protocol-level improvements. That distinction is important for readers trying to understand what QSB is solving: not immediate mass adoption, but a credible bridge for security concerns while Bitcoin’s broader roadmap for post-quantum resilience is still being discussed.

Why nodes may not relay QSB transactions by default

Beyond cost, QSB faces a practical integration barrier: Bitcoin Core’s default relay policy. Levy’s repository classifies QSB transactions as nonstandard, and StarkWare said this means ordinary nodes would not automatically propagate them before confirmation.

Advertisement

In other words, a QSB transaction may not travel through the usual network “gossip” path. For the confirmed test, the transaction was submitted through MARA’s Slipstream service so it could reach miners despite its nonstandard status.

This is a reminder that even when a cryptographic scheme is valid under consensus, network policy still shapes real-world usability. Until relay behavior changes—or until spending routes are standardized—quantum-resistant transactions may remain mainly the domain of researchers and specialized operators.

Protocol upgrades are still on the table

QSB’s transaction-level strategy also raises a broader question: what happens as Bitcoin evolves toward quantum readiness at the protocol layer?

In earlier reporting, Google researchers estimated that if a sufficiently capable quantum computer emerged, it could potentially derive a Bitcoin private key nine to 12 minutes after its corresponding public key becomes visible—creating a window where an attacker might replace a pending transaction. The implication is that certain spending constructions may be more vulnerable than others once quantum capabilities arrive.

Advertisement

Levy introduced QSB with the notion that it does not require a network-wide upgrade, but still provides a safety net. StarkWare’s Eli Ben-Sasson indicated in comments to Cointelegraph that he expects a soft fork to eventually happen, describing QSB as a transitional protection while protocol-level safeguards are developed.

Bitcoin developers are separately weighing proposals that target specific spend paths. One example mentioned by StarkWare is BIP-360, a proposed soft fork that would introduce a Pay-to-Merkle-Root output type while removing Taproot’s quantum-vulnerable key-path spend. This kind of proposal differs from QSB by aiming to reduce exposure directly through changes to how certain outputs are constructed and spent, rather than relying on transaction-level workarounds.

Notably, QSB in this test is presented as a validation that one quantum-resistant approach can be executed without a protocol change. The next step for the community will be whether standardized relay and broader compatibility can be achieved, and how that compares with the security and complexity tradeoffs of protocol-level soft forks.

What to watch next

For now, the key uncertainty is scalability and integration: whether future QSB tests can lower compute cost, and whether changes to Bitcoin relay standards—or eventual soft fork designs like BIP-360—will reduce the friction that currently makes these transactions nonstandard. Readers should also look for more mainnet demonstrations that clarify how reliably the method can be used across different mining and submission workflows.

Advertisement

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version