StarkWare Says First Experimental Quantum-Safe Bitcoin Transaction Has Been Mined
Key Takeaways
- •StarkWare reported the first quantum-safe Bitcoin transaction was mined on the Bitcoin mainnet using its Quantum-Safe Bitcoin (QSB) method.
- •QSB protects individual transactions with hash-based cryptography without changing Bitcoin's consensus rules or requiring a network fork.
- •Coinbase's quantum advisory council estimated in June that roughly 7 million Bitcoin could be vulnerable to future quantum attacks due to exposed public keys and address reuse.
- •StarkWare acknowledged QSB cannot protect addresses with already-exposed public keys and currently requires transactions to be sent directly to miners.
- •StarkWare CEO Eli Ben-Sasson said Bitcoin still needs a soft fork to address the quantum threat long term, cautioning that the network is not yet prepared.

StarkWare, the blockchain infrastructure company behind the Ethereum layer-2 network Starknet, says the first quantum-safe Bitcoin transaction has been mined on the Bitcoin mainnet, testing a way to protect funds from future quantum attacks without changing the network's consensus rules.
In a blog post on Wednesday, Starkware said the transaction used Quantum-Safe Bitcoin, or QSB, a method developed by Starkware researcher Avihu Levy. Levy published the research in April, and Starkware engineer Tomer Giladi later helped turn the proposal into a working mainnet transaction.
"A quantum-safe transaction was mined on the Bitcoin mainnet today that holds up against an adversary running a working quantum computer," Starkware wrote. "Bitcoin holders now have a way to move coins into storage a quantum computer cannot open."
Bitcoin secures transactions using elliptic-curve cryptography, which a sufficiently powerful quantum computer running Shor's algorithm could theoretically break in order to derive private keys and steal funds. No quantum computer capable of breaking today's cryptographic systems is known to exist, but the risk is taken seriously well beyond crypto: in 2024 the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards, and government agencies including CISA have urged organizations to begin migrating away from quantum-vulnerable cryptography.
Protecting Bitcoin could eventually require either a hard fork, which introduces rules incompatible with older software and can split the network, or a soft fork, which can introduce new rules while remaining compatible with older nodes. Starkware said a soft fork remains the preferred long-term solution, while QSB offers a way to protect individual holdings without waiting for a network upgrade.
"I still want Bitcoin to choose to do a soft fork and I expect we will get one," Starkware CEO Eli Ben-Sasson said. "What today's successful transaction offers Bitcoin is a reassurance that holdings can be protected before that happens."
The issue has drawn growing attention as researchers assess which Bitcoin holdings could be most exposed to future quantum attacks. In June, Coinbase's quantum advisory council estimated that roughly 7 million Bitcoin could be vulnerable because of exposed public keys and address reuse. That figure includes coins thought to be held in early-era addresses, including those linked to Bitcoin's pseudonymous creator Satoshi Nakamoto, whose public keys have long been visible on-chain.
According to Starkware, Quantum-Safe Bitcoin adds a second, quantum-resistant lock based on hash functions rather than elliptic curves. Hash-based cryptography is considered more resistant to known quantum algorithms, which is why hash functions and post-quantum signature schemes form the basis of most proposed quantum-resistant designs. QSB uses "signature grinding," which performs computational work off-chain to find a transaction hash that Bitcoin will accept as a validly formatted signature.
Starkware acknowledged that QSB does not make Bitcoin quantum-safe, but rather protects specific transactions using hash-based security. It cannot protect addresses with already-exposed public keys, and it currently requires transactions to be sent directly to miners.
"This amazing feat should not be viewed as a message saying 'Bitcoin is prepared for the quantum threat.' Far from it," Ben-Sasson wrote on X. "I hope whatever attention this brilliant work gets will also help folks hear loud and clear our message: Huston, we've got a problem, and the way to fix it should be to get serious about serious soft forks for [Bitcoin]," he said. "That's how catastrophe can be avoided, and we still have time."