StarkWare mined the first quantum-safe Bitcoin transaction on mainnet Aug. 26, using hash-based cryptography that replaces elliptic-curve signatures. The construction requires no consensus changes but costs $75 to $150 per transaction.
StarkWare mined the first quantum-safe Bitcoin transaction on mainnet Aug. 26, using hash-based cryptography that replaces elliptic-curve signatures. The construction requires no consensus changes but costs $75 to $150 per transaction.

StarkWare mined the first quantum-safe Bitcoin transaction on mainnet Aug. 26, at a processing cost of $75 to $150 per transaction.
Eli Ben-Sasson, chief executive officer at StarkWare, called the initiative a "passion project" that demonstrates Bitcoin holders can protect assets from quantum threats now, at a cost, without waiting for protocol-level changes.
The transaction, ID 305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07, uses Lamport-style hash-based signatures relying on RIPEMD-160 for pre-image resistance. The construction achieves approximately 118-bit second pre-image resistance and fits within Bitcoin's legacy Script limits of 201 non-push opcodes and 10,000 bytes. No consensus rule changes or soft fork were required.
The $75 to $150 per-transaction cost points to where investment attention is likely to flow. Scaling hash-based cryptographic constructions, reducing computational overhead, and making them relay-compatible with standard Bitcoin infrastructure represent a clear research and engineering agenda.
Bitcoin's current security relies on elliptic-curve cryptography, specifically the secp256k1 curve used to generate public-private key pairs. A sufficiently powerful quantum computer running Shor's algorithm could theoretically reverse-engineer a private key from a public key, which would be a catastrophic vulnerability for any exposed Bitcoin address. Hash functions don't have the same mathematical weakness to Shor's algorithm that elliptic curves do, making them a more durable foundation when quantum hardware eventually matures.
The transactions are nonstandard and won't be relayed by regular Bitcoin nodes. Getting one mined required going through MARA Slipstream, a service that allows nonstandard transactions to reach miners without typical mempool relay constraints.
Avihu Levy, StarkWare's general manager of applications, first published the QSB concept alongside an open-source implementation in April 2026. The mainnet version incorporated contributions from StarkWare engineer Tomer Giladi and drew on ideas from Robin Linus's Binohash scheme, an earlier piece of research into hash-based spending conditions.
StarkWare announced a formal post-quantum roadmap for the Starknet ecosystem in June 2026, including collaborative work on BIP 360, a Bitcoin Improvement Proposal focused on quantum-resistant address formats. By operating within existing Script limits and requiring no consensus changes, QSB removes the biggest bottleneck in Bitcoin's upgrade process. A user with a high-value wallet doesn't need to wait for the network to agree on anything. They can move funds into a quantum-resistant construction today, at a cost that is steep but not prohibitive for seven- or eight-figure holdings.
This article is for informational purposes only and does not constitute investment advice.