
StarkWare said researcher Avihu Levy has conducted an experimental quantum-resistant Bitcoin transaction on mainnet. The transaction reportedly used a 10,000-satoshi output in block 964,199 without requiring modifications to Bitcoin’s consensus rules.
StarkWare described the transaction as the first of its kind. MARA Pool mined the block after receiving the transaction directly through its Slipstream service, since the transaction’s nonstandard format prevented ordinary Bitcoin nodes from relaying it through the public mempool.
Nathan Jeffay, a StarkWare spokesperson, said the transaction cost approximately $150 to $200 in computing resources. StarkWare added that the process took several hours, demonstrating that a single Bitcoin output can receive quantum-resistant protection under the network’s current rules, albeit with substantial computational and operational demands.
How StarkWare’s Quantum-Resistant Bitcoin Transaction Works
Levy first proposed the Quantum-Safe Bitcoin (QSB) scheme in April. It combines hash-based one-time signatures with computational searches that tie spending authorization to an individual transaction. The design is intended to prevent forgery even if future quantum computers become powerful enough to compromise Bitcoin’s elliptic-curve cryptography.
Google researchers estimated in March that a sufficiently advanced quantum computer could theoretically recover a Bitcoin private key within nine to 12 minutes after its public key becomes visible. Google said such technology could potentially allow an attacker to replace a transaction during the confirmation window.
Levy’s original proposal estimated that creating a QSB transaction would require between $75 and $150 in GPU computing costs. The completed StarkWare demonstration increased that estimate to approximately $150 to $200.
QSB is focused on individual Bitcoin transactions rather than a network-wide cryptographic upgrade. It allows coins to be transferred into specially protected outputs without changing Bitcoin’s underlying protocol. However, it cannot protect coins whose public keys were exposed before they were migrated, potentially giving attackers time to analyze those keys.
The transaction’s nonstandard status under Bitcoin Core’s default relay rules also presents a practical challenge. Standard nodes will not propagate the transaction before confirmation, so it must be sent directly to a cooperating miner through a service such as MARA’s Slipstream. This means the method depends on preconstructed transactions and access to participating miners.
StarkWare CEO Eli Ben-Sasson said QSB could provide an interim safeguard while developers pursue broader protocol-level protections. The demonstration shows that quantum-resistant spending can be implemented under Bitcoin’s current rules without changing the network’s underlying cryptography.
Meanwhile, Bitcoin developers are considering proposals including BIP-360. The proposed soft fork would introduce a Pay-to-Merkle-Root output type while removing Taproot’s quantum-vulnerable key-path spending. Such a change would require network-wide coordination and formal activation.
QSB follows a different path by functioning without a protocol upgrade. The mainnet experiment demonstrates that Bitcoin’s existing consensus rules can support quantum-resistant spending in a limited form, while broader protections remain under consideration.






