Catenaa, Friday, September 04, 2026- StarkWare has tested an experimental quantum-resistant Bitcoin transaction on mainnet, demonstrating a method for protecting individual outputs without changing the network’s existing consensus rules.
Researcher Avihu Levy used the technique to spend a 10,000-satoshi output in Bitcoin block 964,199, according to StarkWare.
The company described the transaction as the first Bitcoin-native transaction of its type, although the claim refers specifically to StarkWare’s method and experimental setup.
The test used Levy’s Quantum-Safe Bitcoin, or QSB, construction, which combines hash-based one-time signatures with computational techniques designed to protect authorization if future quantum computers break Bitcoin’s existing signature system.
The transaction was mined by MARA Pool after being submitted directly through its Slipstream service.
That step was necessary because the experimental transaction was classified as nonstandard under Bitcoin Core’s default relay policy.
Ordinary Bitcoin nodes therefore would not propagate it through the public mempool.
The transaction still complied with Bitcoin’s consensus rules, meaning miners could include it in a valid block without requiring a protocol upgrade.
That distinction is central to the experiment.
StarkWare did not replace Bitcoin’s cryptography or introduce new consensus rules. Instead, researchers constructed a transaction that could work within the network as it exists today.
Bitcoin currently relies heavily on elliptic-curve cryptography to prove ownership of coins.
A Bitcoin owner signs a transaction with a private key, allowing the network to verify that the person spending the coins has authority to do so.
Today’s computers cannot realistically derive the corresponding private key from a public key.
A sufficiently powerful quantum computer could alter that assumption.
Quantum algorithms could theoretically solve the mathematical problem protecting elliptic-curve signatures much faster than conventional computers.
If that capability becomes practical, bitcoins whose public keys are exposed could potentially become vulnerable.
Google researchers estimated earlier this year that a sufficiently capable future quantum machine might theoretically derive a Bitcoin private key within roughly nine to 12 minutes after seeing the public key.
That would create a particular risk during the period between broadcasting a transaction and its confirmation.
Many Bitcoin addresses do not reveal their public keys until their coins are spent.
Once a transaction is broadcast, however, the public key needed to verify its signature can become visible.
A future quantum attacker could theoretically attempt to derive the private key while the legitimate transaction remains unconfirmed.
The attacker could then try to create a competing transaction sending the coins elsewhere.
Bitcoin miners would ultimately determine which valid transaction was confirmed.
QSB is designed to reduce that exposure by adding another authorization mechanism that does not depend solely on elliptic-curve cryptography.
Levy proposed the Quantum-Safe Bitcoin approach in April.
It combines hash-based one-time signatures with what StarkWare describes as signature grinding, involving repeated computational searches that bind authorization to a particular transaction.
Hash-based cryptography is generally regarded as more resistant to known quantum attacks than the elliptic-curve signatures Bitcoin currently uses.
The technique therefore creates an additional barrier even if an attacker could derive the conventional Bitcoin private key.
It does not make the Bitcoin network itself quantum resistant.
Instead, it protects a particular output prepared using the QSB construction.
The experiment also demonstrated why the method is not yet suitable for ordinary Bitcoin users.
StarkWare said producing the transaction required several hours of computation and cost approximately $150 to $200 in computing resources.
Levy’s earlier proposal had estimated costs of roughly $75 to $150.
Those expenses are separate from Bitcoin’s normal transaction fee.
The method also requires preparation before coins become vulnerable.
Coins whose public keys have already been exposed cannot automatically gain protection from QSB.
An attacker with a future quantum computer could begin working against those previously exposed keys before the owner prepares a protected transaction.
The relay limitation creates another obstacle.
Because ordinary Bitcoin Core nodes treat the transaction format as nonstandard, users cannot simply broadcast QSB transactions through the network in the usual way.
They need direct access to a miner willing to accept them.
MARA’s Slipstream service provided that route for the mainnet demonstration.
The service allows transactions that comply with Bitcoin consensus rules but fail ordinary relay policies to be submitted directly for potential inclusion in blocks.
That makes QSB technically usable today, but operationally difficult.
A broad emergency solution for Bitcoin would need to work across many miners, wallets and users rather than depend on specially arranged transaction submission.
StarkWare CEO Eli Ben-Sasson has positioned QSB as a possible safety mechanism while Bitcoin developers consider network-level quantum defenses.
That distinction matters because changing Bitcoin’s signature architecture would require extensive coordination across developers, miners, node operators, exchanges and wallet providers.
Bitcoin protocol changes are deliberately difficult.
Any upgrade affecting how coins are secured would also need to address older addresses and users who may not move their holdings quickly.
QSB offers a narrower approach that can operate under current rules.
Its mainnet demonstration shows that Bitcoin can accommodate an experimental quantum-resistant spending method before the network adopts a broader cryptographic upgrade.
Bitcoin developers are separately discussing proposals for protocol-level protection.
One is BIP-360, which proposes a new Pay-to-Merkle-Root output structure and removes a Taproot spending path considered vulnerable to future quantum attacks.
Unlike QSB, such a proposal would require a Bitcoin soft fork and network-wide adoption.
A protocol upgrade could eventually offer a standardized migration route for users rather than requiring specially prepared transactions and direct miner submission.
No immediate quantum threat to Bitcoin has been demonstrated.
Current quantum computers remain far below the scale required to derive Bitcoin private keys in practical conditions.
The concern is instead about preparing the network before such machines become capable enough to threaten existing cryptography.
Bitcoin presents an unusual challenge because coins can remain untouched for years or decades.
If quantum-capable machines emerge faster than expected, users may need sufficient time to migrate assets into safer address formats.
That makes early experimentation valuable even when the threat remains theoretical.
The StarkWare transaction does not solve Bitcoin’s quantum problem, and it does not make existing wallets quantum safe.
It demonstrates something narrower: an individual Bitcoin output can be protected and spent using a quantum-resistant construction while the underlying consensus rules remain unchanged.
For Bitcoin developers, that offers another option while longer-term protocol solutions are debated.
The next challenge is making such protection cheaper, easier to relay and practical enough to use before quantum computing moves from a theoretical cryptographic risk to a real one.
