
StarkWare said researcher Avihu Levy tested an experimental quantum resistant Bitcoin transaction on mainnet. It is reported that the TX spent a 10,000-satoshi output in block 964,199 without altering Bitcoin’s consensus rules.
StarkWare described it as the first transaction of its kind. MARA Pool mined the block after receiving the transaction directly through its Slipstream service, since the nonstandard format meant ordinary nodes would not relay it through the public mempool.
StarkWare spokesperson Nathan Jeffay said the transaction cost around $150 to $200 in computation, and StarkWare said the process took hours. The demonstration shows a way to protect a single output under Bitcoin’s current rules, but at a material computational and operational cost.
Discover: The Best Crypto to Diversify Your Portfolio
How StarkWare Quantum Bitcoin Transaction Works
Levy’s Quantum-Safe Bitcoin (QSB) scheme, first proposed in April, combines hash-based one-time signatures with computational searches that bind authorization to a specific transaction. The construction is intended to prevent forgery even if a sufficiently capable quantum computer breaks the elliptic-curve cryptography used by Bitcoin.
In March, Google researchers estimated that a sufficiently capable quantum computer could theoretically derive a Bitcoin private key nine to 12 minutes after a public key becomes visible. Google said this could allow an attacker to replace a pending transaction during Bitcoin’s confirmation window.
Levy’s April proposal estimated that generating a transaction would require $75 to $150 in GPU computation; StarkWare put the cost of the completed transaction at around $150 to $200.
QSB applies to individual Bitcoin transactions rather than upgrading cryptography across the network. It allows coins to be moved into an output with additional protection without changing the Bitcoin protocol, but it does not protect coins whose public keys were exposed before migration. In that case, a potential attacker could have time to analyze those keys before a protected transaction is sent.
The transaction’s nonstandard classification under Bitcoin Core’s default relay policy is a practical constraint. Ordinary nodes do not propagate the transaction before confirmation, so it must be submitted directly to a cooperating miner through a service such as MARA’s Slipstream. The method, therefore, requires prepared transactions and direct miner access.
StarkWare CEO Eli Ben-Sasson said QSB provides a safety net while protocol-level protections are developed. The demonstration establishes a workaround under the existing rules, rather than changing Bitcoin’s underlying cryptography across the network.
Trade Bitcoin on Bybit and Get a Chance to Win Our $1,000 USDT Airdrop
The Protocol-Level Alternative
Bitcoin developers are separately considering proposals, including BIP-360, a proposed soft fork that would introduce a Pay-to-Merkle-Root output type while removing Taproot’s quantum-vulnerable key-path spend. That approach would require network-wide coordination and activation.
QSB does not wait for a protocol change. The mainnet test shows that Bitcoin’s existing consensus rules can accommodate one form of quantum-resistant spending, while broader protocol-level protections remain under consideration.
Discover: The Best Token Presales