The First Quantum-Resistant Bitcoin Transaction Has Been Mined

The First Quantum-Resistant Bitcoin Transaction Has Been Mined

A StarkWare researcher has successfully sent the first Bitcoin transaction designed to resist attacks from a sufficiently powerful quantum computer. The experimental transaction landed on Bitcoin’s mainnet without requiring a soft fork or any change to the network’s consensus rules. While the achievement is significant, it is not a full fix for Bitcoin’s potential quantum problem. It is better understood as a demonstration that users can create a quantum-resistant escape hatch today, even while developers continue debating a permanent protocol-level solution. Quantum computers pose a potentially serious problem for Bitcoin because much of the network’s security depends on cryptographic assumptions that powerful enough machines could eventually defeat. Bitcoin uses elliptic-curve cryptography for the signatures that prove ownership of coins. A cryptographically-relevant quantum computer running Shor’s algorithm could theoretically derive a private key from an exposed public key, allowing an attacker to spend funds they do not own. The biggest practical concern is the bitcoin already sitting in addresses that could eventually be vulnerable to a quantum attack. Glassnode estimated in May that roughly 6.04 million BTC, or 30.2% of the issued supply, had public keys exposed on-chain. At a bitcoin price of $80,000, that translates to roughly $483 billion worth of potentially vulnerable coins. That huge pool of potentially stealable bitcoin is why the issue has sometimes been described as a quantum treasure hunt. Bitcoin creator Satoshi Nakamoto’s early coins alone, which may otherwise never move if it turns out no one has the associated keys, represent an extraordinary potential prize for whoever develops a sufficiently powerful quantum computer. Some Bitcoin developers have spent much of the past year arguing over what should happen before such a machine arrives. The emerging view is less about rushing an emergency change into Bitcoin today and more about having a migration mechanism ready to deploy before so-called Q-day, the point at which quantum computers become capable of breaking Bitcoin’s existing signatures. Matt Corallo, who was one of the earliest developers to work on Bitcoin, has argued that the immediate objective should be increasing the number of coins that can be secured before a cryptographically relevant quantum computer exists. In a Bitcoin developer discussion this year, he wrote that the community should seek to “minimize the chance that the Bitcoin community feels the need to fork to burn coins” by reducing the amount of bitcoin that remains vulnerable. Corallo has also described a future in which a soft fork could disable vulnerable spending paths once the threat becomes sufficiently serious. The precise mechanism remains controversial, particularly over what should happen to coins whose owners fail to migrate. Should those coins be frozen forever at some point or should an entity with a quantum computer be able to snatch them up? The issue has attracted attention well beyond Bitcoin’s core developer community. Coinbase established an independent advisory board focused on quantum computing and blockchain security in the crypto space at large. In July, Coinbase, Strategy, BlackRock, Galaxy, Fidelity Digital Assets, Blockstream and other companies founded a consortium that pledged $15 million over three years toward Bitcoin security research, with post-quantum cryptography as its first focus. People need to stop giving this guy's FUD the time of day. Literally *the* top two Bitcoin research orgs (Blockstream Research and Chaincode) have each put resources into figuring out what a post-quantum Bitcoin change should look like, and have had some interesting results!… https://t.co/AyldCEH0by — Matt Corallo 🟠 (@TheBlueMatt) February 3, 2026 That said, there is no consensus on the quantum threat being an imminent issue that must be dealt with today. Strategy’s Michael Saylor and many others have argued that a serious quantum threat is likely more than a decade away, while Coinbase’s research has stressed that preparation needs to begin well before the technology becomes capable of breaking existing cryptography. Some investors have nonetheless treated the issue as a reason to remain cautious about institutional bitcoin exposure. Ray Dalio, for example, has repeatedly cited quantum computing among the technological risks facing bitcoin. That is the backdrop for StarkWare’s recent experiment with a quantum-resistant Bitcoin transaction. The transaction uses a system called Quantum-Safe Bitcoin, or QSB, developed by StarkWare researcher Avihu Levy. Levy first published the approach in April in a paper arguing that Bitcoin transactions could be made resistant to quantum attacks without changing the protocol. Instead of using the types of digital signatures that a sufficiently powerful quantum computer could eventually break, QSB relies on a different cryptographic approach built around hashing, a technique that is considered much more resistant to quantum attacks. The method builds on an earlier proposal called Binohash and is designed to work within Bitcoin’s existing transaction rules, meaning it does not require changing the network’s basic software in order to be used today. However, there is a major catch. Creating one of these transactions requires substantial off-chain computation. Levy’s original paper estimated the GPU cost at a few hundred dollars, compared with the tiny fees normally associated with sending bitcoin. The method was explicitly presented as a last-resort option rather than something suitable for ordinary Bitcoin payments. Additionally, while QSB can protect coins once they are moved into a quantum-resistant output, moving them there could become dangerous if a cryptographically relevant quantum computer already exists. When a user broadcasts a transaction from a quantum-vulnerable address, the information needed to derive its private key could become available to a quantum attacker, potentially allowing the attacker to steal the coins before the transaction is confirmed. That makes QSB a potentially useful emergency escape route, but migrating vulnerable coins before a CRQC exists would avoid this race altogether. StarkWare also does not view this as anything close to a final answer to the quantum question. Eli Ben-Sasson, the company’s CEO, compared the technique to a lifeboat, saying that it provides reassurance but “is not a reason to relax” and instead gives the industry a reason to build more such safeguards. The quantum panic that spread through crypto earlier this year somewhat obscured the reality that proposals for quantum readiness, such as Bitcoin Improvement Proposal (BIP) 360, already exist, and the first quantum-resistant transaction on mainnet is evidence that at least one emergency option already works. However, uncertainty persists over specifics such as which quantum-resistant signature algorithm should be used and what should be done with bitcoin that is not moved to a new, secure address format in a timely manner.

Original Source

Read the full article at Gizmodo →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.