Highlights

  • StarkWare says it mined the first Bitcoin transaction designed to survive an attack from a working quantum computer.
  • The method, called QSB, needs no soft fork or change to Bitcoin's consensus rules.
  • Real BTC was moved on mainnet at a cost of roughly $150 to $200 per transaction.
  • The technique only protects coins moved into it going forward — it can't help addresses whose public keys are already exposed on-chain.

Bitcoin's biggest theoretical threat just got its first real-world defense. StarkWare, the zero-knowledge scaling firm behind Starknet, says it has mined the first Bitcoin mainnet transaction built to remain secure even if an attacker had a working quantum computer capable of breaking the elliptic-curve cryptography Bitcoin currently relies on. The transaction, engineered by StarkWare researcher and general manager of applications Avihu Levy, locked real bitcoin into what the company calls quantum-safe storage — without requiring any change to Bitcoin's underlying protocol.

How Quantum-Safe Bitcoin (QSB) Works

Levy's method, first published as research in April 2026 and detailed on StarkWare's blog, adds what the team describes as an extra lock on top of Bitcoin's existing signature scheme. It combines hash-based one-time signatures with a computational search that binds a specific authorization to a specific transaction, using signature grinding to prevent an attacker from exploiting exposed public-key data while a transaction sits in the mempool. Because it works entirely within Bitcoin's existing rules, StarkWare says no soft fork or miner coordination is needed to start using it today — a sharp contrast to the years-long consensus-change proposals that have dominated the quantum-resistance debate in Bitcoin circles.

StarkWare Executes Bitcoin's First Quantum-Safe Transaction on Mainnet
Image via @coinbureau on X

Real Money, Real Limits

StarkWare engineer Tomer Giladi carried the research through to a working mainnet transaction, which the company says cost in the low hundreds of dollars — an estimated $150 to $200 — to execute.

Related: MANTRA's Post-Mortem: Aug 20 Exploit Moved 720.9M Tokens, No Keys Compromised

That price tag matters because it signals the technique is usable today by anyone willing to pay the fee, not just a theoretical construct. But the fix has a hard boundary: QSB only protects coins that are actively moved into protected storage going forward. It does nothing for the large share of circulating Bitcoin already sitting in addresses whose public keys have been exposed on-chain through a prior spend — those remain vulnerable in a genuine quantum-break scenario regardless of this workaround. Estimates of exposed supply vary, but a meaningful share of Bitcoin's roughly 19.9 million circulating coins sits in addresses that have broadcast a public key at least once, meaning a real quantum break would still leave a large attack surface even after QSB adoption spreads.

Why This Still Isn't the Final Answer

StarkWare itself is careful not to oversell the milestone: the company maintains that a protocol-level soft fork remains the better long-term fix for the network as a whole, and QSB is positioned as a stopgap individuals can adopt now rather than a replacement for that effort. With no cryptographically relevant quantum computer yet in existence, the timeline for when this defense becomes necessary is still unknown — but Friday's mainnet transaction is the clearest sign yet that Bitcoin's infrastructure layer is starting to build for that eventuality ahead of time rather than after the fact.