Researcher Avihu Levy has executed the first quantum-resistant Bitcoin transaction on the network’s mainnet, spending a 10,000-satoshi output in block 964,199 by routing it directly to mining firm MARA through its Slipstream service, bypassing Bitcoin’s standard relay network, according to StarkWare, the Ethereum scaling firm behind the experiment.
Because the transaction used a nonstandard format, ordinary Bitcoin nodes would not have relayed it through the public mempool. Instead, it was routed directly to MARA Pool through the mining firm’s Slipstream service, which accepts transactions outside the standard relay path. MARA then mined the block containing it.
The cost of pulling off a quantum resistant Bitcoin transaction was not trivial. StarkWare spokesperson Nathan Jeffay indicated the computation behind the transaction ran roughly $150 to $200 and took several hours to complete, underscoring that, for now, this form of protection remains expensive and slow rather than something available to average users on demand.
How the quantum resistant Bitcoin scheme works
The method behind this quantum resistant Bitcoin transaction is Levy’s Quantum-Safe Bitcoin (QSB) scheme, which he first outlined in April. QSB pairs hash-based one-time signatures with computational searches that tie authorization to one specific transaction, an approach meant to hold up even if elliptic-curve cryptography, the math Bitcoin currently relies on, is eventually broken by a powerful quantum computer.
The urgency behind quantum resistant Bitcoin research traces partly to a Google estimate from March, which suggested a sufficiently advanced quantum machine could derive a Bitcoin private key in nine to 12 minutes once its public key is exposed.
That timeframe would theoretically fall within Bitcoin’s confirmation window, potentially letting an attacker swap out a pending transaction before it settles.
Levy’s original April proposal put the cost of generating such a transaction at $75 to $150 in GPU computation; StarkWare’s completed mainnet run landed somewhat higher, at $150 to $200.
Crucially, QSB does not retrofit quantum resistant Bitcoin protection onto the network at large. It secures individual outputs by moving coins into a specially protected destination, but it cannot shield funds whose public keys were already exposed before the migration, leaving a window in which those older keys could theoretically be analyzed by an attacker ahead of a protected transfer.
Why this quantum resistant Bitcoin method can’t scale yet
The core limitation is relay policy. Because Bitcoin Core’s default rules classify this type of quantum resistant Bitcoin transaction as nonstandard, it cannot travel through the ordinary peer-to-peer network before confirmation. Anyone wanting to use it must prepare the transaction in advance and submit it directly to a cooperating miner, as StarkWare did through MARA’s Slipstream service, a workaround, not a widely accessible tool.
StarkWare co-founder and CEO Eli Ben-Sasson framed the demonstration as a stopgap rather than a fix. He said QSB offers a safety net while protocol-level protections are still being developed, positioning the mainnet test as proof of concept for what is possible under Bitcoin’s existing rules rather than a permanent solution.
Eli Ben-Sasson, co-founder of StarkWare
The protocol-level alternative to quantum resistant Bitcoin
Separately, Bitcoin developers are weighing broader, network-wide changes. Among them is BIP-360, a proposed soft fork that would introduce a Pay-to-Merkle-Root output type and retire Taproot’s key-path spend, which is considered vulnerable to quantum attacks. Unlike QSB, this route would require coordinated activation across the entire Bitcoin network rather than transaction-by-transaction protection.
For now, the mainnet test stands as evidence that a form of quantum resistant Bitcoin transaction can already be processed under current consensus rules, even as the debate over a network-wide upgrade continues. Bitcoin traded at $77,654.20 at the time of reporting.
Note on sourcing: the original reporting attributes statements to StarkWare’s Nathan Jeffay and CEO Eli Ben-Sasson in indirect (reported) speech rather than direct quotations, so no verbatim quotes have been added here beyond what was documented.