Keyboard shortcuts

Aug 27, 2026, 09:27 PM UTC
Crypto // Research

A Quantum-Resistant Bitcoin Transaction Just Confirmed on Mainnet

No fork required. It also cost up to $200 and had to be handed directly to a miner.

peatpost Desk
Aggregated
Aug 27, 2026, 04:14 AM UTC3 min read
A Quantum-Resistant Bitcoin Transaction Just Confirmed on Mainnet
SourceCointelegraph· 17h ago

StarkWare researcher Avihu Levy has tested an experimental quantum-resistant transaction on the Bitcoin mainnet, in what the company describes as the first of its kind.

The transaction was confirmed in Bitcoin block 964,199. On-chain data shows it spent a 10,000-satoshi output protected by Levy's Quantum Safe Bitcoin scheme, with MARA Pool mining the block after receiving the transaction through its Slipstream service.

How the scheme works

Levy's paper and code repository describe QSB as combining hash-based one-time signatures with computational searches that bind an authorisation to a specific transaction. The construction is intended to prevent forgery even if an adversary holds a cryptographically relevant quantum computer.

The significance is that it works within Bitcoin's existing rules. No soft fork, no consensus change, no coordination across the network — which matters enormously, because changing Bitcoin's consensus rules is a multi-year political process with an uncertain outcome.

An abstract representation of quantum computingThe experimental transaction demonstrated quantum-resistant Bitcoin spending without requiring a fork, though it cost up to $200 and needed direct miner submission.

The catch

Two caveats make this a demonstration rather than a solution.

The transaction cost up to $200 in fees. That is roughly the value of the output it was protecting multiplied many times over, and it reflects the size of the data required — hash-based signatures are considerably larger than the elliptic curve signatures Bitcoin normally uses, and Bitcoin charges by the byte.

It also required direct submission to a miner via MARA's Slipstream service, because the transaction would not propagate through the ordinary relay network. Standard Bitcoin nodes apply policy rules that reject non-standard transactions, so this one had to bypass the network to reach a block.

A payment method that costs $200 and requires a personal relationship with a mining pool is not yet a payment method.

Why anyone is doing this now

The threat model is specific and worth stating precisely. A sufficiently large quantum computer could derive a private key from a public key using Shor's algorithm.

Bitcoin addresses do not expose public keys until coins are spent, which provides partial protection for unspent outputs at modern address types. But an estimated several million coins sit at addresses where the public key is already visible on-chain — including, most famously, the earliest coins mined in 2009.

Those are permanently exposed the moment the capability exists, and nobody can move them except whoever holds the keys.

The state of the field

This sits alongside the SHRINCS proposal from Blockstream, which takes the opposite approach: a Bitcoin Improvement Proposal to add post-quantum signatures through a consensus change.

The two efforts illustrate the strategic choice facing Bitcoin. A scheme that works today without a fork is available immediately and impractical at scale. A scheme that requires a fork could be efficient and needs years of consensus-building to deploy.

Which matters depends entirely on a question nobody can answer: how much time there is.

What a demonstration is worth

Proof-of-concept transactions of this kind have a specific value that is easy to overstate and easy to dismiss.

They establish that a construction survives contact with a real network — that the script validates, the miners accept it, and the transaction confirms under actual consensus rules rather than in a simulator. A surprising number of cryptographic proposals fail at exactly that step.

They do not establish that anything is usable, and StarkWare has been notably direct about the limitations rather than presenting this as a solution.

The migration nobody has designed

The harder problem sits beyond either proposal. Even with a working quantum-resistant scheme available, moving Bitcoin's existing supply to it requires every holder to actively spend their coins into new addresses.

That is a coordination problem with no mechanism behind it. Exchanges and custodians could move quickly; individuals holding coins in cold storage might take years, and the holders of the most exposed coins — the earliest addresses with public keys already visible — may not be reachable at all.

Written by
peatpost Desk
Aggregated · @peatpost
Share

Discussion

0 comments
0/2000

No comments yet — be the first to weigh in.

More from peatpost