The Bitcoin Beacon The Bitcoin Beacon
Network & Mining · Netanya

StarkWare Sent Bitcoin’s First Quantum-Safe Transaction

A researcher moved 10,000 satoshis with a signature no known quantum computer could unravel — and did it without touching a line of Bitcoin’s consensus rules.

By The Bitcoin Beacon · NETANYA · August 28, 2026 · 6 min read
A cryptographer at a workbench shielding a glowing bitcoin coin behind a lattice of light as a crystalline quantum computer looms, linocut
Network & Mining · Illustration: The Bitcoin Beacon

NETANYA — On Aug. 26, in block 964,199, a Bitcoin transaction moved 10,000 satoshis — about nine dollars. The sum was trivial; the method was not. StarkWare researcher Avihu Levy sent it using a construction he calls Quantum Safe Bitcoin, and it is being described as the first spend on the main network engineered to survive an attack from a quantum computer.

The window a quantum computer would attack

A standard Bitcoin address hides your public key behind a hash, so the key stays secret while your coins sit still. The exposure comes when you spend. The moment a transaction is broadcast, its public key is laid bare in the mempool while it waits to confirm. A sufficiently powerful quantum computer running Shor’s algorithm could, in that window, work backward from the exposed key to the private key and race to redirect the funds before the honest transaction lands.

That brief, unavoidable exposure is the vulnerability. It is also why the coins most at risk are the oldest and most reused — including the roughly one million bitcoin attributed to Satoshi in early pay-to-public-key outputs, whose keys are already visible on the chain.

How Levy closed it

The trick is called signature grinding. Rather than accept the first valid signature a wallet produces, Levy’s process runs through millions of candidate signatures until it finds one that never leaks the public-key data Shor’s algorithm would need. Combined with RIPEMD-160 hashing, StarkWare says the method delivers about 118 bits of resistance under Shor’s algorithm.

The important part is what it does not require. There is no soft fork, no hard fork, and no change anyone else has to agree to. It works inside Bitcoin’s existing rules, which means a user with exposed coins could reach for it today without waiting on the whole network.

No soft fork, no hard fork, no permission — just a signature ground down until it gives a quantum computer nothing to grab.

The catch: hours and hundreds of dollars

It is slow and expensive. The grinding took several hours of GPU time and cost $150 to $200 — orders of magnitude above a normal fee, which today clears for pennies. The transaction couldn’t travel the open mempool either; it was submitted straight to a miner through Marathon Digital’s Slipstream private service. So this is an emergency exit, not a wallet feature. Levy first laid out the construction in a paper in April 2026; this week he proved it runs on the live chain.

Why it matters for a network built not to change

Bitcoin’s durable answer to quantum computing — new address types, post-quantum signature schemes — would require consensus changes that take years to design, review and activate. That difficulty is a feature for a monetary network worth more than $1.6 trillion, and a constraint when a new threat appears on the horizon. What Levy demonstrated is that a careful holder has a manual escape hatch in the meantime, one that needs no committee’s approval.

The limits, fairly stated

The demonstration does not make Bitcoin quantum-safe. Most coins still sit in address types that expose the public key when spent, and no quantum machine capable of running Shor’s at the needed scale is known to exist — the threat is plausibly years or decades away. Skeptics reasonably argue a protocol-level fix will arrive before it is urgent. The counter is that the most exposed coins are the oldest and largest, and that a defense is worth proving before the clock forces the question. One curiosity: StarkWare is best known for scaling work on Ethereum, which makes a Bitcoin-only cryptography milestone an unusual dateline for the firm.

Why it matters: Bitcoin’s answer to quantum computing won’t come from a vote for years — so the first working defense arrived as something a single user can run alone.

Sources

  1. The Block — First quantum-resistant Bitcoin transaction successfully executed, StarkWare says
  2. StarkWare — The first quantum-safe Bitcoin transaction has been mined
  3. Crowdfund Insider — StarkWare Confirms First Quantum-Safe Bitcoin Spend On Mainnet
  4. The Quantum Insider — StarkWare Researcher Demonstrates Quantum-Resistant Bitcoin Transaction
  5. The Cryptonomist — Quantum-Resistant Bitcoin Transaction Marks First on Mainnet

Figures — block 964,199, a 10,000-satoshi transfer, ~118-bit resistance under Shor’s algorithm, several hours of GPU time and $150–$200 in cost, and submission via Marathon’s Slipstream — are per StarkWare’s account and the reporting above. Quantum timelines are contested estimates, not settled facts. Informational only — not financial advice.

The world’s bitcoin headlines, in your inbox every morning.

Free. Five minutes. No hype.

Subscribe free