**StarkWare** announced that it executed the first Bitcoin (BTC) mainnet transaction designed to defend against quantum computer attacks. This approach is assessed to provide a security strength of approximately 118 bits against quantum attacks.

Key points

  • StarkWare said it protected real transactions from quantum attacks without modifying the Bitcoin protocol in any way.

  • However, using this method requires computations that take several hours per transaction.

  • Mainstream nodes refused to relay due to the non-standard format, so the mining firm MARA processed the transaction directly.

Quantum-resistant Bitcoin transactions land on the mainnet

StarkWare explained via its official blog that, with this transaction, funds that could have been targeted by attackers once quantum computers emerged can no longer be reached. The person overseeing this design is **Avihu Levy**, StarkWare’s Chief Product Officer (CPO). He previously disclosed the technique in April under the name “Quantum Safe Bitcoin.” The result is permanently recorded on the Bitcoin blockchain, allowing anyone to verify it.

When the paper was first published, the implementation had not yet fully completed on-chain broadcasting, and testing was only carried out at the stage of fixing the GPU for computation. This process was run for about six hours using eight Nvidia (Nvidia) GPUs.

Transaction mining was handled by MARA. MARA included these transactions via its Slipstream service, which accepts transactions that ordinary Bitcoin nodes refuse to propagate due to their non-standard format.

Related article: Cardano could be interoperable with Ethereum within a few months…remarks by Hoskinson

Levi’s quantum-resistance approach implemented without a soft fork

Existing Bitcoin transactions rely on the ECDSA electronic signature scheme. It is known that if a sufficiently powerful quantum computer uses the Shor algorithm, the private key can be derived and broken. The quantum-safe Bitcoin proposed by Levi moves this weak point to a hash function, forcing attacks to rely only on **brute force** without any known shortcut algorithms. At present, no algorithm has been proposed that would let quantum computers efficiently reverse-engineer hashes.

This technique is designed to operate within Bitcoin’s legacy script constraints: 201 opcodes and a 10,000-byte limit on script size. As a result, it is assessed to achieve security on the order of about 118 bits.

Levi defined this approach not as a “general payment method” meant to replace existing payment systems, but as a “last resort” used only when needed. The reason is that, from the user’s perspective, the costs and complexity are too high. For reference, the current average Bitcoin on-chain transaction fee is reportedly around 30 cents.

This design is based on an initial concept called “Binohash” proposed by **Robin Linus**. Binohash requires additional computational work on Bitcoin transactions, but it still relies on cryptographic methods that are highly likely to be rendered ineffective by quantum computers. Levi’s version is designed to have senders perform massive searching until a valid solution is found, and the paper estimated the required workload at around 70 trillion attempts. This work is performed off-chain on widely used GPUs rather than on-chain.

Bitcoin quantum risk response: debate for and against among the developer community

StarkWare CEO **Eli Ben-Sasson** has long argued that Bitcoin should not delay responding to quantum threats any longer. Rather than waiting for protocol upgrades to be consolidated through future consensus, he says it should experiment with and adopt the approaches available now.

Levi is also a co-author of the quantum-resistant address proposal BIP-360, which was merged into Bitcoin’s official repository in February of this year. Unlike this quantum-safe Bitcoin, BIP-360 requires a soft fork at the network level.

The paper released in April received both praise and criticism from the developer community. Bitcoin analyst **Daniel Batten** pointed out that calling these attempts “quantum-safe” is an exaggeration. Roughly 1.7 million BTC stored in the initial pay-to-public-key (pay-to-public-key) addresses remain exposed regardless of what new transaction techniques emerge.

These initial supply items can’t be protected because the public keys are already revealed on the blockchain. In other words, to structurally reduce quantum risk, a more fundamental solution is needed—one that covers past holdings as well as the address structure.

Next article: iPhone 18 Pro—camera upgrades may remain exclusive to “Pro Max”