StarkWare Executes Quantum-Resistant Bitcoin Transaction on Mainnet
A new Bitcoin transaction used hash-based protections to reduce quantum exposure without changing consensus rules, but remains costly and non-standard.
StarkWare says a researcher has executed the first Bitcoin mainnet transaction designed to resist a future quantum-computing attack without changing Bitcoin's consensus rules. The experiment is a technical proof rather than a network-wide security upgrade, but it demonstrates that users may have more than one path for protecting transactions whose public keys become visible before confirmation.
The method, called Quantum Safe Bitcoin, was developed by StarkWare applications head Avihu Levy and tested in collaboration with the MARA Foundation. It uses a technique known as signature grinding. The user generates a very large number of candidate signatures and selects one whose resulting transaction structure satisfies a hash-based condition. That adds a second form of protection that does not depend on the elliptic-curve assumptions used by ordinary Bitcoin signatures.
The transaction was submitted directly through MARA's Slipstream service because it is non-standard and would not pass through the ordinary peer-to-peer relay policy. Public reporting estimates that creating a spend requires several hours of graphics-processor computation and approximately $75 to $150 of cloud resources. Other estimates place the full transaction cost as high as $200. These constraints make the current construction unsuitable for everyday payments.
The risk appears during public-key exposure
Bitcoin addresses that have never spent funds can conceal their public keys behind a hash. Once a conventional transaction is broadcast, however, the public key is revealed while that transaction waits for confirmation. A sufficiently powerful quantum computer running Shor's algorithm could theoretically derive the corresponding private key and forge a competing spend during that interval. No known quantum computer can do this against Bitcoin today, and estimates of when such a machine could exist remain highly uncertain.
The StarkWare experiment focuses on that short exposure window. By adding a hash-based requirement that a forged transaction would also need to satisfy, the method is intended to make theft infeasible even if elliptic-curve cryptography eventually becomes vulnerable. It does not protect every category of Bitcoin holding. Coins in addresses whose public keys are already exposed, including reused addresses and older output formats, still require a broader migration plan.
It also does not remove the need for protocol-level work. StarkWare acknowledged that Bitcoin would need a network upgrade for comprehensive and usable quantum resistance. A durable solution must address wallet support, standard relay rules, output formats, hardware devices, exchange custody, recovery procedures and the treatment of coins that do not migrate before a credible quantum threat emerges.
A useful demonstration with practical limits
The experiment is significant because it turns a cryptographic proposal into an observable mainnet transaction. It shows that Bitcoin's existing scripting and transaction structure can support a limited quantum-defense technique without an immediate fork. That gives researchers another design point when comparing a soft fork, new signature algorithms and application-layer protections.
Still, a successful transaction does not establish production security. The construction needs independent cryptographic review, reproducible tooling and analysis of its economic and operational failure modes. Direct miner submission introduces a dependency that ordinary users do not face. High computational costs could create access and centralization concerns. The use of a non-standard transaction also means normal wallets and nodes do not provide the familiar propagation and monitoring behavior expected by users.
Why it matters
Quantum risk has often been treated as either too distant to prioritize or so severe that it requires an emergency redesign. This test supports a more measured view. The threat is not immediate, but migration research can be tested before it becomes urgent. That is especially important for exchanges, custodians and institutional holders managing long-lived Bitcoin positions and operational systems that cannot be replaced quickly.
The broader lesson is that cryptographic resilience involves more than choosing a new algorithm. A protection must work across transaction construction, network policy, custody, miner behavior and user migration. StarkWare's transaction advances that discussion by proving one narrow mechanism on the live network. Its present cost and non-standard status also make clear how much engineering and governance remain before quantum resistance can become a routine property of Bitcoin rather than an experimental exception.