BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

StarkWare’s quantum-safe Bitcoin transaction reaches mainnet

StarkWare announced on Wednesday that it has executed the first-ever quantum-safe Bitcoin transaction confirmed on the mainnet, which ensured that the coins moved into a hash-based structure

AnonymousCryptoCompass newsroom
August 27, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

StarkWare announced on Wednesday that it has executed the first-ever quantum-safe Bitcoin transaction confirmed on the mainnet, which ensured that the coins moved into a hash-based structure are safe from attacks exploiting Shor’s algorithm. This is significant not just for Bitcoin but also for other big blockchains, which rely on elliptic-curve signatures and ultimately encounter the same problem.

Why has the whole market been watching this

The potential danger is nothing out of the ordinary. If someone’s Bitcoin public key appears in public records, a powerful enough quantum computer using Shor’s algorithm could potentially discover their private keys and launch a hacking attempt.

According to Glassnode Research, a total of 6.04 million BTC, which accounts for 30.2% of the cryptocurrency’s total supply, is quantum-exposed at rest. Of these 6.04 million BTC, 1.92 million BTC are structurally exposed because of the type of its output, while 4.12 million BTC are operationally exposed because of practices like address reuse and custody behavior.

Glassnode Research Bitcoin Supply by Quantum Exposure l Glassnode Research

 

That differentiation is necessary. Glassnode measures at-rest exposure: coins with public keys that are already known before they are transferred by their owners. However, a new danger arises in terms of spending when a concealed public key is revealed during the transaction process.

Currently, there is no quantum machine able to perform such an attack. However, in 2026, Google experts calculated that breaking Bitcoin’s secp256k1 curve would require either 1,200 logical qubits and 90 million Toffoli gates or 1,450 logical qubits and 70 million gates. According to a simulation of a superconducting architecture, less than half a million physical qubits would be sufficient.

How signature grinding shuts the mempool window

This is where the demonstration by StarkWare comes into play. In regular Bitcoin payments, the private key can be exposed during transmission. Hence, the quantum hacker could compute the private key of the transaction before it is confirmed and beat the original transaction to completion.

Avihu Levy, the general manager of applications at StarkWare, invented Quantum-Safe Bitcoin (QSB) to solve this shortcoming without altering Bitcoin’s consensus protocol. The QSB concept is based on Binohash and works by transforming the quantum-vulnerable part of the protocol into a hash-to-signature puzzle that relies on RIPEMD-160’s pre-image resistance and does not depend on elliptic-curve assumptions broken by Shor’s algorithm.

Before sending the transaction, the sender conducts resource-intensive computations outside the platforms. By using Levy’s suggested setup, QSB is theoretically capable of providing around 118 bits of second pre-image resistance against Shor’s threat model. A quantum hacker would still benefit from the quadratic enhancement offered by Grover’s algorithm, even if he wouldn’t gain the exponentially higher advantage inherent in Shor’s algorithm against elliptic curve cryptography.

Levy’s findings came to light in April 2026, with StarkWare engineer Tomer Giladi playing a critical role in the deployment of the first mainnet transaction using that method.

The catch: a miner-direct path and hours of compute

There are actual limits. In Levy’s studies, the cost of off-chain GPU computation necessary to produce a transaction is about $75 to $200, while the abstract of the study says that the amount involved would be a few hundred dollars. Depending on how many GPUs are available, the computation might require a few hours to finish.

QSB transactions can be classified as nonstandard by the relay policy of Bitcoin, which means they cannot follow a normal mempool path. Accordingly, StarkWare sent its transaction straight to a miner, and MARA inserted it via the Slipstream service.

Importantly, QSB cannot help with the 6.04 million BTC already noted as exposed by Glassnode. If an attacker can see the public key long enough to find the private key in the future, then the attack can take place without waiting for the transaction in question to arrive. QSB serves as a way to safely store protected coins, not to secure all current Bitcoin.

Why StarkWare still wants a soft fork

Levy and StarkWare CEO Eli Ben-Sasson both say the durable answer remains a protocol-level upgrade. BIP 360 proposes Pay-to-Merkle-Root, or P2MR, as a new output type intended to support migration away from quantum-vulnerable signature paths. BIP 361 proposes a phased sunset for legacy ECDSA and Schnorr signatures; it notes that more than 34% of all bitcoin had revealed a public key on-chain as of March 1, 2026.

For now, Ben-Sasson presented the demonstration as breathing room rather than a permanent solution.

Avihu’s breakthrough is important because it gives the psychological reassurance which we need and which the asset itself needs.”

He has previously compared crypto’s approach to the threat with passengers on the Titanic. After Wednesday’s test, he said the demonstration showed:

“there are lifeboats.”

Bitcoin traded near $78,620 as the news circulated.

 

The smartest crypto minds already read our newsletter. Want in? Join them.