Starkware says the first quantum-safe Bitcoin transaction has been mined on mainnet. Researchers have warned for years that some older wallets could lose their protection once quantum machines become powerful enough.
What actually happened on Bitcoin on August 26?
In a blog post published Wednesday, Starkware, the company behind the Ethereum layer-2 network Starknet, said it mined a mainnet transaction using a new method called Quantum-Safe Bitcoin, or QSB. Starkware researcher Avihu Levy published the idea back in April, and engineer Tomer Giladi turned the proposal into a working transaction on the live network. It's a notable case of a team known for Ethereum work turning its attention to Bitcoin's own protocol.
"A quantum-safe transaction was mined on the Bitcoin mainnet today that holds up against an adversary running a working quantum computer," Starkware wrote in the post. Bitcoin holders now have a way to move coins into storage a quantum computer cannot open, the company said.
The real news is not the transfer itself but the fact that it required no change to the network's rules at all. It ran under Bitcoin's existing protocol, meaning the effect is available today rather than waiting on a community decision about an upgrade.
How does Quantum-Safe Bitcoin actually work?
Bitcoin normally secures signatures with elliptic-curve cryptography. A sufficiently powerful quantum computer could, in theory, run Shor's algorithm to derive a private key from a public one and take the funds. QSB adds a second lock on top of the standard signature, based on hash functions, which hold up far better against Shor's algorithm than elliptic curves do.
The method relies on a technique Starkware calls "signature grinding." Off-chain computation searches for a transaction hash that Bitcoin's existing rules will accept as a validly formatted signature. Here is what that means in practice.
- Point: QSB adds a separate, hash-based safeguard on top of the transaction's existing signature.
- The method works under Bitcoin's current rules, with no soft fork or hard fork needed.
- It protects only the coins an owner actively moves through the new method.
- It cannot rescue addresses whose public key has already been exposed on the blockchain.
- For now, transactions have to go straight to miners rather than through a normal mempool.
Starkware itself admits QSB does not make all of Bitcoin quantum-safe. It is closer to insurance for one transaction and one wallet than an upgrade for the entire protocol.
Why is the quantum threat to Bitcoin even real?
The question is not hypothetical. In June, Coinbase's quantum advisory council estimated that roughly 7 million BTC could be vulnerable because of exposed public keys and address reuse. That is close to a third of all coins in circulation.
The risk falls mainly on older wallets whose public key has already appeared on-chain, for example through a prior spend from that address. Fresh addresses that have never sent a transaction stay less exposed under the current protocol logic, since they only reveal the public key's hash rather than the key itself.
Most engineers in the field expect that a computer capable of breaking a Bitcoin signature within a reasonable time is not arriving tomorrow, and maybe not for several years. That's exactly why some developers prefer to build protection early rather than wait until the threat becomes practical. Roughly 19.9 million BTC are in circulation right now, so Coinbase's estimate covers a large slice of the market, not an abstract minority.
Soft fork or patch: what Starkware is actually pushing for
Protecting the whole network can go two ways. A hard fork introduces rules incompatible with older software and risks splitting the network into two separate chains. A soft fork tightens the rules so older nodes still recognize new transactions as valid. That is the path Bitcoin's community has historically preferred, the same route used for SegWit and Taproot.
Starkware insists QSB is not a replacement for a soft fork, only a way to buy time before one happens. The company still views a full protocol upgrade as the safest fix for the entire network.
"Houston, we've got a problem, and the way to fix it should be to get serious about serious soft forks for Bitcoin. That's how catastrophe can be avoided, and we still have time."
- Eli Ben-Sasson, CEO of Starkware, from a post on X dated August 27, 2026
In the same post, Ben-Sasson added that the successful transaction should not be read as a sign that "Bitcoin is prepared for the quantum threat." Readiness for the network as a whole, he said, still requires a separate community decision on a protocol upgrade, and that decision is what Starkware is really pushing for.
What this means for Bitcoin holders
Most people who keep coins on an exchange or in a hardware wallet and have never spent from that address do not need to change anything right now. QSB works more as a signal to developers that the technical protection already exists, leaving open only the question of when the network agrees on a broader fix.
Anyone holding large amounts long-term and reusing the same address should watch this topic more closely and consider moving to a hardware wallet with a fresh address for every transaction. Nataliia Dorofieieva noted that research like this tends to speed up work on Bitcoin's protocol upgrades rather than slow it down, since it gives the community a concrete example that protection is technically possible today. Large exchanges and custodians usually handle key rotation for their clients on their own, so the practical takeaway for a regular holder is simple: don't send funds through the same address more than necessary. Anyone can check their own address history on a blockchain explorer: if an address has ever sent a transaction, its public key is already known to the network, and those are the wallets worth moving to a newer format first.




Comments
Your email address will not be published. Required fields are marked *