StarkWare researcher Avihu Levy says he has successfully completed what the company describes as the first quantum-resistant Bitcoin transaction on the mainnetโan onchain test of Levyโs Quantum Safe Bitcoin (QSB) approach.
According to StarkWare, the transaction was confirmed Wednesday in Bitcoin block 964,199, and onchain data indicates it spent a 10,000-satoshi output protected using QSB. Block propagation for the test relied on MARA Poolโs Slipstream service, reflecting that the experiment did not follow Bitcoin Coreโs default transaction relay rules.
Key takeaways
- First mainnet demonstration: StarkWare reports QSB was confirmed in Bitcoin block 964,199, moving Levyโs April proposal from concept to live spending.
- No consensus upgrade required: StarkWare says the test was compatible with Bitcoinโs existing consensus rules, without changing the protocol.
- Higher compute costs: StarkWare estimates the transaction required โlow hundreds of dollars,โ with computation taking hours.
- Relay constraints: QSB transactions are treated as nonstandard under Bitcoin Core default policies, so they required direct submission via Slipstream rather than normal peer-to-peer propagation.
- Stops short of a network-wide fix: QSB hardens individual spending, while broader protocol proposals (including BIP-360) aim to reduce quantum exposure more systematically.
QSB reaches mainnet: hash-based signatures plus transaction-bound authorization
Levyโs QSB combines two ideas intended to counter scenarios where quantum computers undermine Bitcoinโs elliptic-curve cryptography. In StarkWareโs description of the scheme, QSB uses hash-based one-time signatures and pairs authorization to a specific transaction through computational searches.
The goal is to prevent forgery even if a quantum computer eventually breaks the cryptographic primitives underpinning Bitcoinโs typical key-path spending. Rather than replacing Bitcoinโs cryptography across the network, QSB is designed as a construction for individual transactionsโeffectively a โlast-resortโ safety net that can be used when quantum risk becomes more urgent.
StarkWare points to Levyโs published paper and code repository as the technical basis for the method, with the repository detailing how transaction-specific authorization is bound into the spending conditions.
What changed vs. earlier proposalsโand what remains theoretical
The QSB test is best understood against earlier academic and research milestones. In March, researchers at Google estimated that a sufficiently capable quantum computer could theoretically derive a Bitcoin private key within minutes after an attacker learns the corresponding public key from a pending transaction, potentially enabling key replacement during the confirmation window.
In April, Levy introduced QSB in response to that kind of threat model, describing the approach as costly and intended for rare use rather than routine replacement of existing defenses.
StarkWareโs Wednesday mainnet confirmation therefore marks an important shift: it demonstrates that a quantum-resistant spending construction can be executed under Bitcoinโs current consensus rules, at least in this controlled experiment. That matters for investors and builders because it suggests a path for incremental, transaction-level hardening while longer-term protocol changes are debated and implemented.
Cost, computation time, and the reality of running it on Bitcoin
While the concept is aimed at quantum resistance, the test also highlights the practical trade-off: compute intensity. StarkWare previously estimated that generating a QSB transaction would require between $75 and $150 in GPU computation, framing it as a fallback option rather than a universal tool.
For the confirmed mainnet run, StarkWareโs spokesperson Nathan Jeffay told Cointelegraph that the total cost landed in the โlow hundreds of dollars,โ estimating around $150 to $200. StarkWareโs release also said the process took hours of computation.
That pricing and time profile is critical context for market participants: even if QSB can be made to work without a protocol update, its cost structure will likely limit how often it can be used in practice until either hardware efficiency improves or alternative constructions reduce compute requirements.
Why it required a special submission path: nonstandard relay policies
Beyond cost, StarkWareโs testing approach underscores another bottleneck: Bitcoin nodes may not relay QSB transactions in the same way they handle standard transfers.
Levyโs repository classifies QSB transactions as nonstandard under Bitcoin Coreโs default relay policies. StarkWare says this means ordinary nodes would not propagate the transaction before confirmation, so the test needed to be submitted directly through MARAโs Slipstream service.
In practical terms, that implies a two-stage readiness problem. Even if the spending is valid under consensus rules, the transactionโs ability to spread through the networkโat least by defaultโcan affect timing, reliability, and user experience. Observing whether QSB can become easier to submit, relay, or include under broader conditions will likely be one of the next milestones builders watch.
QSB as a bridge while protocol-level protection advances
StarkWareโs leadership also positions QSB as incomplete by design. The method applies to individual transactions rather than upgrading cryptography throughout the Bitcoin network. StarkWare CEO Eli Ben-Sasson said, โA soft fork should happen, and I believe it will,โ framing QSB as a safety net while protocol-level protections are developed.
That broader effort is already reflected in public proposals discussed in the Bitcoin ecosystem. One example mentioned by StarkWare is BIP-360, a proposed soft fork that would introduce a Pay-to-Merkle-Root output type while removing Taprootโs quantum-vulnerable key-path spend.
The tension here is straightforward: QSB can demonstrate feasibility today, but protocol changes aim to make quantum-resistant spending practical at scaleโpotentially without requiring specialized submission routes or heavy computation per transaction.
For traders and long-term holders, this also changes how to think about โquantum readiness.โ Instead of a single all-or-nothing moment, the landscape appears to be moving toward layered defenses: transaction-level constructions that prove the mechanics, paired with eventual consensus changes that reduce exposure and simplify use.
Going forward, the key question is whether QSB tests like this can be repeated reliably across different infrastructure and whether future improvementsโor soft fork proposals such as BIP-360โmake quantum-resistant spending cheaper, easier to relay, and more broadly usable without specialized services.






