Live markets
BTC ETH SOL BNB XRP DOGE
View all markets

Bitcoin Ran Its First Quantum-Safe Transaction Without Changing a Single Rule

Bitcoin Ran Its First Quantum-Safe Transaction Without Changing a Single Rule

Transaction 305a24ff…ab07 confirmed in block 964,199 on August 26. It moved a 44,000-satoshi output and paid a 5,179-satoshi fee.

StarkWare describes it as the first quantum-safe Bitcoin transaction. It required no soft fork, no hard fork, and no change to consensus rules.

It also cost several hundred dollars in off-chain computation and could not travel through the ordinary mempool.

How It Works

Bitcoin proves ownership through elliptic-curve signatures. That is the class of mathematics Shor’s algorithm could solve on a sufficiently large quantum computer.

The method, called Quantum-Safe Bitcoin or QSB, adds a second lock built from cryptographic hash functions rather than elliptic curves, running in parallel with the existing signature check.

Shor’s algorithm cannot break hash functions, and Grover’s algorithm cannot accelerate a brute-force search enough to compromise the spend. Reported resistance is roughly 118 bits against Shor.

The construction uses signature grinding and RIPEMD-160 hashing, and draws on a technique called Binohash developed by BitVM creator Robin Linus.

It was designed by Avihu Levy, a researcher and General Manager of Applications at StarkWare, who published the underlying research in April 2026 and built the implementation on his own time.

The Caveats Are Substantial

This is where the coverage and the reality diverge.

The transaction does not make ordinary BTC holdings quantum-safe. It demonstrates that a holder could move coins into a spending path a quantum computer cannot open. Coins sitting in standard addresses are unaffected.

Because QSB produces a non-standard transaction format, it does not propagate through the ordinary mempool. It needed a direct path to a miner, which MARA Slipstream provided.

It is not available in mainstream wallets or exchanges, and it costs significantly more than a standard transaction.

The on-chain record confirms the transaction was mined. It does not independently establish the construction’s claimed quantum resistance, which rests on the published research rather than on the block.

StarkWare itself frames QSB as a stopgap while it pushes BIP-360 as the long-term fix.

The Other Announcement the Same Week

Blockstream published a technical proposal called SHRINCS, a post-quantum signature scheme designed specifically for Bitcoin.

Jonas Nick, who designed it with Mikhail Kudinov, described it as the first post-quantum signature proposal conceived specifically for Bitcoin, while clarifying it does not aim to be definitive or best in every respect.

The limitations are meaningful. SHRINCS would process around three transactions per second. It requires each wallet to use a single-use key per transaction, meaning operators must track which keys have already been used.

It lacks a formal security proof, its reference software is not production-ready, and adopting it would require a soft fork with sufficient network backing.

Blockstream Research separately published an evaluation of lattice-based post-quantum signatures for Bitcoin, rating Falcon and Dilithium among the options.

Why Two Things at Once

These are answers to different questions, and treating them as competing is a misreading.

QSB is an individual defense available now, for holders willing to pay and accept operational friction. SHRINCS is a network-wide upgrade that would require consensus.

The debate around quantum threats has largely assumed Bitcoin would eventually need a contentious fork to defend itself. QSB pushes back on that assumption for individual transactions without resolving it for the network.

Adam Back has publicly downplayed the immediacy of the quantum threat while his firm works on the proposal, which is a coherent position rather than a contradiction: the risk is not imminent, and the upgrade path takes years.

Prediction markets are reportedly pricing around a 5% chance of a network-wide post-quantum upgrade happening this year.

The Ethereum Parallel

The Ethereum Foundation is reviewing a draft proposing leanXMSS signatures to replace BLS and prepare validators for quantum threats.

Two of the largest networks are now working the same problem in public within the same week, which is a change from the years when quantum risk was mostly a conference topic.

Optimisus covered the earlier stage of that concern when Tether’s chief executive warned inactive bitcoin wallets could eventually be exposed.

What Holders Should Take From It

No quantum computer today can break Bitcoin’s cryptography. Nothing about this week changes the near-term risk profile of holding BTC.

What changed is that a defensive option moved from paper to a mined block, and a formal upgrade proposal now exists to be criticized and improved.

The practical exposure most often cited is coins in addresses whose public keys are already exposed on-chain, which is a subset of holdings rather than all of them.

The realistic timeline for anything network-wide is measured in years, and it will run through the same consensus process that has struggled with far smaller changes. Optimisus covered how that process performs under pressure in the piece on a soft fork that drew 2.53% miner support.

Bitcoin’s upgrade record this year underlines the point, including the eCash fork that turned out to be a rehearsal.

That is the honest constraint. The cryptography is arriving faster than the governance that would deploy it.

Sources

This is not financial advice.

Optimisus covers crypto and technology news for readers who want the detail behind the headline.