StarkWare Executes First Quantum-Resistant Bitcoin Transaction, But the Hard Part Hasn't Started
StarkWare says it has completed the first quantum-resistant transaction on the Bitcoin network, proving the concept works without touching Bitcoin's protocol. The catch: it costs up to $200 per transaction and requires bypassing normal network routing entirely.
The milestone was reported on August 27, 2026, the date The Block published its coverage, and is the result of StarkWare's Quantum Safe Bitcoin (QSB) project, first published as an open-source proposal by company CPO Avihu Levy on April 9, 2026. The transaction ran entirely within Bitcoin's existing rules, replacing standard elliptic curve signatures (the cryptography that quantum computers threaten) with hash-based Lamport-style signatures that Shor's algorithm cannot efficiently break. No soft fork, no community vote, no protocol change was required.
Levy has been explicit about what QSB is and is not. According to Unchained Crypto, he described it as a "last-resort emergency tool," not a replacement for standard Bitcoin payments. StarkWare itself acknowledged that Bitcoin still requires a protocol-level upgrade to be fully secure from a capable quantum computer. The transaction achieved approximately 118 bits of resistance against Shor's algorithm, but remains theoretically exposed to Grover's algorithm, a weaker quantum attack that researchers consider manageable because Grover's algorithm delivers only a quadratic speedup rather than the exponential speedup that makes Shor's algorithm so threatening.
What the Transaction Actually Required
The proof-of-concept leaned heavily on off-chain hardware. The test used eight Nvidia RTX PRO 6000 GPUs running for roughly six hours, putting the estimated cost per transaction at $75 to $200 in cloud compute resources. Because the resulting transactions exceed Bitcoin's default relay policies, they cannot travel through the standard peer-to-peer network. They must be submitted directly to miners through services like Marathon Digital's Slipstream, which accepts non-standard transactions.
QSB builds on Binohash, a transaction introspection technique developed by Robin Linus, the creator of BitVM and a researcher affiliated with ZeroSync and Stanford University. Linus demonstrated Binohash on Bitcoin mainnet in February 2026, laying the groundwork for StarkWare's implementation.
One notable security property of QSB is that private keys never leave the user's device. This distinguishes the approach from custodial or third-party solutions and is relevant for anyone evaluating it against alternative approaches.
Why the Urgency Is Real
A March 2026 paper from Google's Quantum AI team sharpened the timeline considerably. Researchers found that Bitcoin's elliptic curve cryptography could theoretically be broken with fewer than 500,000 physical qubits, a reduction of roughly 20 times from prior estimates near 9 million qubits. Modelling cited in that paper and reported by The Quantum Insider suggests that threshold could be crossed within a single 10-minute Bitcoin block window, giving an attacker enough time to derive a private key from an unconfirmed transaction before it settles.
The exposure on-chain is substantial. Approximately 6.9 million BTC sit in addresses where the public key is already visible, including coins associated with Satoshi Nakamoto's earliest wallets. This category includes coins held in early Pay-to-Public-Key (P2PK) outputs from Bitcoin's first years, a subset of roughly 1.7 million BTC that is at particular risk, as well as coins in reused addresses where the public key has been revealed through prior spending. Galaxy Digital put the dollar value of that broader exposure at around $470 billion as of mid-2026, a figure that fluctuates with the BTC price. A June 2026 research paper, cross-referenced by The Quantum Insider, estimated that roughly 35% of circulating Bitcoin supply carries a measurable quantum exposure footprint.
Justin Drake, a researcher at the Ethereum Foundation, said his confidence in a quantum-capable computer arriving by 2032 "has shot up significantly," and assigned at least a 10% probability to private key recovery being possible by that date. Bitcoin developer Bit Paine offered a wider window: "I still think roughly 10 years is the more likely timeframe, but I assign an uncomfortably high likelihood that we see something disruptive within five years."
What This Means for Users in India, Nigeria, and Across Africa
The stakes are not evenly distributed. India leads the 2026 Chainalysis Global Crypto Adoption Index with 156 million crypto users, according to CoinLaw, citing the Chainalysis index. Nigeria ranks second globally with around 45 million crypto holders, 52% of whom are under 30; approximately 59% of crypto-active Nigerian adults hold USDT, reflecting the dominance of stablecoins across remittance corridors. Africa as a whole reached approximately 75 million wallet users in 2026, with stablecoin adoption rising 180% across Sub-Saharan Africa. Crypto-powered remittances in Africa are expanding at roughly 50% per year.
For these users, the $75 to $200 cost per QSB transaction is not a technical footnote. It is a practical disqualification. Micro-remittances across the Nigerian diaspora corridor or between Indian families abroad and home represent small, frequent, cost-sensitive transfers. A compute bill of up to $200 per transaction makes QSB irrelevant to that use case entirely.
The hardware wallet gap compounds the problem. Older Trezor models cannot be patched to support post-quantum signatures under the proposed BIP-360 standard, and Ledger has added ML-KEM support only for secure communication rather than transaction signing. Users of such devices will face a hardware replacement burden before any protocol upgrade can protect them. It is worth noting, however, that Blockstream benchmarking has shown hash-based schemes can already run on current wallet chips without requiring new silicon, suggesting the transition may be more tractable on modern hardware than on legacy devices.
The threat is not limited to future attacks. Adversaries may already be collecting on-chain data for future decryption, a strategy known as "harvest now, decrypt later." For users in early-adoption markets with high volumes of P2PK or early P2PKH transactions, the window for migration is not abstract.
The Protocol Path Forward
The permanent fix sits with BIP-360, which proposes a new address format called Pay-to-Merkle-Root that would use ML-DSA signatures (standardized by NIST as FIPS 204) instead of vulnerable ECDSA. Those post-quantum signatures are dramatically larger, approximately 7,800 bytes compared to 64 bytes for Schnorr signatures, a throughput tradeoff that any realistic assessment of BIP-360 as a near-term practical solution must weigh carefully. BIP-360 was merged into the official bitcoin/bips repository on February 11, 2026, and a testnet implementation from BTQ Technologies launched the following month. Merging into the bips repository signals that the proposal is open for community discussion, not that activation is scheduled. A parallel proposal, BIP-361, covering post-quantum migration and legacy signature sunset, is also actively under discussion as of August 2026. NIST guidance calls for deprecating ECC-256 cryptography by 2030 and full disallowance after 2035.
Bitcoin's governance process is slow by design. Researchers and developers working on payment infrastructure for African fintech and South Asian remittance platforms would do well to track BIP-360's testnet progress and begin planning address migration tooling accordingly. The workaround exists. The solution is still being built.