Bitcoin’s First Quantum-Resistant Transaction – Here’s What It Actually Means

StarkWare’s Avihu Levy secured 10,000 satoshis in block 964,199, but 6 million BTC worth $483 billion remains exposed

C. da Costa Avatar
C. da Costa Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • StarkWare researcher Avihu Levy executed Bitcoin’s first quantum-resistant transaction without altering consensus rules.
  • Glassnode identifies 6.04 million BTC worth ~$483 billion as vulnerable to quantum attacks via exposed public keys.
  • Deploy QSB before Q-day arrives, or hash-secured migration risks becoming a race against quantum theft.

Glassnode estimates 6.04 million BTC30.2% of issued supply — already have their exposed public keys sitting exposed on-chain. At a hypothetical $80,000 per bitcoin, that’s roughly $483 billion worth of potentially vulnerable coins, waiting for a quantum computer good enough to pick the lock. On August 26, 2026, StarkWare researcher Avihu Levy mined the first quantum-resistant Bitcoin transaction on mainnet using hash-based cryptography, without touching a single consensus rule. Real progress. Also not a cure. Both things are true simultaneously.

The Lock Inside the Lock

QSB bolts a hash-based second lock onto Bitcoin’s existing security model — no new opcodes, no fork required.

Where elliptic-curve signatures currently do Bitcoin’s security work, a sufficiently powerful quantum computer running Shor’s algorithm [a quantum method for breaking public-key cryptography] could theoretically derive private keys from exposed public keys — breaking the whole model. Most experts, including Michael Saylor, reportedly put that threat more than a decade out. Coinbase’s research counters that preparation must begin now, because protocol migrations take years. The disagreement itself is telling.

Built entirely from Bitcoin’s existing Script opcodes, QSB adds a second, hash-based lock alongside the usual elliptic-curve signature. Hash functions resist quantum attack differently — Grover’s algorithm [a quantum search speedup] provides only a quadratic speedup, not the exponential break Shor’s delivers against discrete log problems. The result: approximately 118 bits of quantum-resistant security. No new opcodes. No soft fork. No consensus change.

What the QSB transaction actually involved:

  • Confirmed in Bitcoin block 964,199, mined by MARA Pool
  • Transaction ID 305a24ff…ab07; output size: 10,000 satoshis
  • Submitted via MARA’s Slipstream because it is non-standard — regular nodes won’t relay it
  • Computation cost: roughly $75–$150 in GPU time per transaction
  • Security mechanism: hash pre-image resistance, not elliptic-curve signatures

“Quantum-safe Bitcoin, mined on mainnet, today.”StarkWare’s X announcement, crediting Avihu Levy, engineer Tomer Giladi, and MARA’s Slipstream

A Lifeboat, Not a Life Raft

QSB works best as an early escape hatch — deploy it before a quantum adversary exists, or the math gets uncomfortable.

If a quantum machine came online tomorrow, timing would matter enormously. QSB works cleanly when deployed before a capable adversary exists — quietly migrating vulnerable coins into hash-secured outputs. Use it after Q-day, and broadcasting from a compromised address becomes something closer to a drag race: an honest transaction versus a quantum-generated theft attempt. StarkWare CEO Eli Ben-Sasson reportedly describes QSB as a lifeboat — proof the escape hatch exists, but “not a reason to relax.”

While QSB closes one specific window, the house still has open doors. Standard P2PKH, P2WPKH, and P2TR outputs remain elliptic-curve dependent. An additional 4.12 million BTC are “operationally exposed” through address reuse alone. QSB is a niche tool for high-value holders willing to absorb GPU costs that dwarf typical transaction fees. It cannot sweep Bitcoin clean.

“Minimize the chance that the Bitcoin community feels the need to fork to burn coins.” — Developer Matt Corallo, on securing as many coins as possible before Q-day

For institutional custodians, the regulatory pressure is already concrete. A consortium including Coinbase, BlackRock, Fidelity Digital Assets, Strategy, Galaxy, and Blockstream pledged $15 million over three years for Bitcoin security research, with post-quantum cryptography named as the first focus area. France’s ANSSI will stop certifying non-quantum-resistant security products from 2027, with full compliance required by 2030. That deadline is closer than Q-day.

QSB is simultaneously a proof of concept and a political signal: Bitcoin can accommodate hash-based post-quantum constructions within existing rules. BIP-360‘s Pay-to-Merkle-Root proposal represents the next protocol-level step, but community consensus on which post-quantum signature algorithms to standardize hasn’t arrived yet. The lifeboat exists. The ship still needs work.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →