Crypto World
StarkWare Runs Quantum-Resistant Bitcoin Transactions on Mainnet
StarkWare researcher Avihu Levy says he has successfully completed what the company describes as the first quantum-resistant Bitcoin transaction on the mainnet—an onchain test of Levy’s Quantum Safe Bitcoin (QSB) approach.
According to StarkWare, the transaction was confirmed Wednesday in Bitcoin block 964,199, and onchain data indicates it spent a 10,000-satoshi output protected using QSB. Block propagation for the test relied on MARA Pool’s Slipstream service, reflecting that the experiment did not follow Bitcoin Core’s default transaction relay rules.
Key takeaways
- First mainnet demonstration: StarkWare reports QSB was confirmed in Bitcoin block 964,199, moving Levy’s April proposal from concept to live spending.
- No consensus upgrade required: StarkWare says the test was compatible with Bitcoin’s existing consensus rules, without changing the protocol.
- Higher compute costs: StarkWare estimates the transaction required “low hundreds of dollars,” with computation taking hours.
- Relay constraints: QSB transactions are treated as nonstandard under Bitcoin Core default policies, so they required direct submission via Slipstream rather than normal peer-to-peer propagation.
- Stops short of a network-wide fix: QSB hardens individual spending, while broader protocol proposals (including BIP-360) aim to reduce quantum exposure more systematically.
QSB reaches mainnet: hash-based signatures plus transaction-bound authorization
Levy’s QSB combines two ideas intended to counter scenarios where quantum computers undermine Bitcoin’s elliptic-curve cryptography. In StarkWare’s description of the scheme, QSB uses hash-based one-time signatures and pairs authorization to a specific transaction through computational searches.
The goal is to prevent forgery even if a quantum computer eventually breaks the cryptographic primitives underpinning Bitcoin’s typical key-path spending. Rather than replacing Bitcoin’s cryptography across the network, QSB is designed as a construction for individual transactions—effectively a “last-resort” safety net that can be used when quantum risk becomes more urgent.
StarkWare points to Levy’s published paper and code repository as the technical basis for the method, with the repository detailing how transaction-specific authorization is bound into the spending conditions.
What changed vs. earlier proposals—and what remains theoretical
The QSB test is best understood against earlier academic and research milestones. In March, researchers at Google estimated that a sufficiently capable quantum computer could theoretically derive a Bitcoin private key within minutes after an attacker learns the corresponding public key from a pending transaction, potentially enabling key replacement during the confirmation window.
In April, Levy introduced QSB in response to that kind of threat model, describing the approach as costly and intended for rare use rather than routine replacement of existing defenses.
StarkWare’s Wednesday mainnet confirmation therefore marks an important shift: it demonstrates that a quantum-resistant spending construction can be executed under Bitcoin’s current consensus rules, at least in this controlled experiment. That matters for investors and builders because it suggests a path for incremental, transaction-level hardening while longer-term protocol changes are debated and implemented.
Cost, computation time, and the reality of running it on Bitcoin
While the concept is aimed at quantum resistance, the test also highlights the practical trade-off: compute intensity. StarkWare previously estimated that generating a QSB transaction would require between $75 and $150 in GPU computation, framing it as a fallback option rather than a universal tool.
For the confirmed mainnet run, StarkWare’s spokesperson Nathan Jeffay told Cointelegraph that the total cost landed in the “low hundreds of dollars,” estimating around $150 to $200. StarkWare’s release also said the process took hours of computation.
That pricing and time profile is critical context for market participants: even if QSB can be made to work without a protocol update, its cost structure will likely limit how often it can be used in practice until either hardware efficiency improves or alternative constructions reduce compute requirements.
Why it required a special submission path: nonstandard relay policies
Beyond cost, StarkWare’s testing approach underscores another bottleneck: Bitcoin nodes may not relay QSB transactions in the same way they handle standard transfers.
Levy’s repository classifies QSB transactions as nonstandard under Bitcoin Core’s default relay policies. StarkWare says this means ordinary nodes would not propagate the transaction before confirmation, so the test needed to be submitted directly through MARA’s Slipstream service.
In practical terms, that implies a two-stage readiness problem. Even if the spending is valid under consensus rules, the transaction’s ability to spread through the network—at least by default—can affect timing, reliability, and user experience. Observing whether QSB can become easier to submit, relay, or include under broader conditions will likely be one of the next milestones builders watch.
QSB as a bridge while protocol-level protection advances
StarkWare’s leadership also positions QSB as incomplete by design. The method applies to individual transactions rather than upgrading cryptography throughout the Bitcoin network. StarkWare CEO Eli Ben-Sasson said, “A soft fork should happen, and I believe it will,” framing QSB as a safety net while protocol-level protections are developed.
That broader effort is already reflected in public proposals discussed in the Bitcoin ecosystem. One example mentioned by StarkWare is BIP-360, a proposed soft fork that would introduce a Pay-to-Merkle-Root output type while removing Taproot’s quantum-vulnerable key-path spend.
The tension here is straightforward: QSB can demonstrate feasibility today, but protocol changes aim to make quantum-resistant spending practical at scale—potentially without requiring specialized submission routes or heavy computation per transaction.
For traders and long-term holders, this also changes how to think about “quantum readiness.” Instead of a single all-or-nothing moment, the landscape appears to be moving toward layered defenses: transaction-level constructions that prove the mechanics, paired with eventual consensus changes that reduce exposure and simplify use.
Going forward, the key question is whether QSB tests like this can be repeated reliably across different infrastructure and whether future improvements—or soft fork proposals such as BIP-360—make quantum-resistant spending cheaper, easier to relay, and more broadly usable without specialized services.
You must be logged in to post a comment Login