Within a week, the build cost of a “post-quantum” Bitcoin transaction plummeted from about $320 to about $67—down roughly 79%—yet approximately 6.9 million Bitcoins can’t even get through the door to this scheme.

📢 想聊行情的进群

These numbers come from the “Quantum-Secure Bitcoin Optimization Challenge” organized by StarkWare together with Yukon Research and Eigen Labs. The prompt was very specific: who can drive down the compute cost needed to construct a post-quantum transaction. Last month, StarkWare mined the first such transaction on the Bitcoin mainnet, costing about 3,100 GPU hours and roughly $320. The open competition ran for just a week; one of the core benchmarks jumped from verifying 146 million candidate values per second to over 820 million per second on a standard RTX 4090. Across both tracks, a total of 62 improvements were adopted.

So where are the savings coming from? They’re off-chain. The most expensive part of this transaction is performing a brute-force search on the user’s own machine: Bitcoin originally requires a signature, and the方案 is modified to insert a hash value instead. But among roughly every 700 trillion hash outputs, only one has the right “shape,” meaning it has to be forced through again and again. The faster the code runs, the fewer GPU hours it takes to achieve the same result—so the cost shows up as a graphics-card bill, not as Bitcoin transaction fees.

Even more telling is the leaderboard. The leading record was set by developers who run AI models. Anthropic’s Opus 5 and Fable 5.1 take the top spots, followed closely by OpenAI’s GPT-6 Astra, Grok 4.6, and Kimi. In other words, in this “making Bitcoin more post-quantum” competition, the main contenders are AI.

My take: cost was never the real threshold. $67 isn’t a price tag—it’s an estimate under specific hardware assumptions, and it will be refreshed anytime the next record is set. StarkWare itself is actively cooling things down. The real bottleneck is coverage: this construction only protects coins whose public keys have not yet been exposed. Those roughly 6.9 million Bitcoins from early years, using old formats with public keys already posted on-chain—at today’s prices worth about $580 billion—cannot be saved. Also, these transactions are non-standard and must be sent directly to miners, effectively bypassing normal channels; StarkWare acknowledges that the long-term answer is still a soft fork, not a “single-point plug-in.”

So this is more like a stress test: it proves that compute can be piled on and costs can be driven down, while also putting the “who can’t be saved” problem right on the table. The quantum threat shifts from “will it come” to “after it comes, which coins are safe.”

Do you think the real bottleneck for post-quantum protection is compute cost, or that batch of old coins whose public keys are already exposed and can’t be moved at all? Let’s discuss in the comments.

Click the avatar to watch the live stream

every day, I’ll keep you updated on Bitcoin security and quantum-threat hotspots—more than just watching what news happens, I’ll help you understand the logic and the opportunities behind it 👀🚀