StarkWare reported that researcher Avihu Levy has carried out an experimental quantum-resistant Bitcoin transaction on mainnet. The transaction reportedly spent a 10,000-satoshi output in block 964,199 without making any changes to Bitcoin’s consensus rules.
StarkWare described the transaction as the first of its kind. MARA Pool mined the block after receiving the transaction directly through its Slipstream service, as the transaction’s nonstandard structure meant regular nodes would not relay it through the public mempool.
Nathan Jeffay, a StarkWare spokesperson, said the transaction required approximately $150 to $200 in computing costs. StarkWare said the process took several hours, highlighting that the technique can protect an individual Bitcoin output under the current rules, although it comes with considerable computational and operational requirements.
How StarkWare’s Quantum-Resistant Bitcoin Transaction Works
Levy’s Quantum-Safe Bitcoin (QSB) proposal, introduced in April, combines hash-based one-time signatures with computational searches that link authorization to a specific transaction. The design aims to prevent fraudulent spending even if a sufficiently advanced quantum computer eventually compromises Bitcoin’s elliptic-curve cryptography.
In March, Google researchers estimated that a powerful quantum computer could theoretically obtain a Bitcoin private key within nine to 12 minutes after its public key is exposed. Google said this could give an attacker an opportunity to replace a transaction while it remains in the confirmation process.
Levy’s original proposal estimated that generating a QSB transaction would cost between $75 and $150 in GPU computation. StarkWare’s live demonstration, however, put the actual computational expense at roughly $150 to $200.
QSB focuses on protecting individual Bitcoin transactions instead of introducing a new cryptographic system across the network. It enables users to move coins into specially protected outputs without changing Bitcoin’s protocol. However, funds with public keys that were already exposed before migration would remain vulnerable, since an attacker could potentially analyze those keys before the coins are transferred.
Another limitation comes from the transaction’s nonstandard status under Bitcoin Core’s default relay policy. Regular nodes will not propagate the transaction before confirmation, requiring it to be sent directly to a cooperating miner through a service such as MARA’s Slipstream. As a result, the process requires prepared transactions and access to participating miners.
StarkWare CEO Eli Ben-Sasson said QSB could provide an additional safety layer while broader protocol-level protections are being developed. Rather than changing Bitcoin’s core cryptography, the system demonstrates a way to introduce quantum-resistant spending under the network’s existing rules.
Bitcoin developers are separately considering measures such as BIP-360, a proposed soft fork that would create a Pay-to-Merkle-Root output type and eliminate Taproot’s quantum-vulnerable key-path spending. Such an upgrade would require network-wide coordination and activation.
QSB does not depend on waiting for a protocol change. The mainnet test demonstrates that Bitcoin’s current consensus rules can support a limited form of quantum-resistant spending, while more comprehensive network-level protections remain under consideration.
































