StarkWare reported that researcher Avihu Levy successfully tested an experimental quantum-resistant Bitcoin transaction on mainnet. The transaction spent a 10,000-satoshi output in block 964,199 without making any changes to Bitcoin’s consensus rules.
The company described the transaction as the first of its kind. MARA Pool included it in a mined block after receiving it directly through its Slipstream service because Bitcoin’s standard nodes would not relay the nonstandard transaction through the public mempool.
Nathan Jeffay, a StarkWare spokesperson, said the computation cost approximately $150 to $200, while StarkWare noted that completing the process took several hours. The experiment demonstrates that individual Bitcoin outputs can receive quantum-resistant protection under the existing rules, although the approach currently comes with notable costs.
How StarkWare’s Quantum-Resistant Bitcoin Transaction Works
Avihu Levy’s Quantum-Safe Bitcoin (QSB) proposal, introduced in April, combines hash-based one-time signatures with computational searches designed to link authorization to a particular transaction. The mechanism is intended to prevent unauthorized spending even if future quantum computers become capable of breaking Bitcoin’s elliptic-curve cryptography.
Google researchers said in March that a sufficiently advanced quantum computer could potentially recover a Bitcoin private key within nine to 12 minutes after its public key is revealed. Such an ability could give attackers an opportunity to alter transactions before they receive sufficient confirmations.
QSB focuses on protecting individual transactions instead of replacing Bitcoin’s cryptographic system across the entire network. Users can move coins into specially protected outputs without modifying the underlying protocol. However, funds tied to public keys that were already exposed could remain at risk before they are transferred into a protected output.
A key limitation is QSB’s nonstandard transaction format under Bitcoin Core’s default relay rules. Regular nodes will not broadcast such transactions before confirmation, meaning users need to deliver them directly to a compatible miner through a service like MARA’s Slipstream. This requires both transaction preparation and access to a participating miner.
StarkWare CEO Eli Ben-Sasson said QSB could act as a temporary layer of protection while the Bitcoin community works toward protocol-level solutions. The experiment provides a method for quantum-resistant spending without changing Bitcoin’s core cryptography.
Developers are separately examining measures such as BIP-360, a proposed soft fork that would add a Pay-to-Merkle-Root output type and eliminate Taproot’s quantum-sensitive key-path spending. Implementing such a change would require broader coordination and network activation.
Unlike a protocol upgrade, QSB can operate under Bitcoin’s existing consensus framework. The mainnet test suggests that quantum-resistant spending is already possible in a limited form, while broader network-wide defenses against quantum threats remain under development.