Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

StarkWare’s Quantum-Resistant Bitcoin Transaction Mainnet Test Costs up to $200

quantum-resistant Bitcoin transaction quantum-resistant Bitcoin transaction

A quantum-resistant Bitcoin transaction landed on mainnet last week, confirmed in block 964,199, and the exercise cost its creator up to $200 and hours of GPU time. Bitcoin.com identifies the man behind it as Avihu Levy, Chief Product Officer at StarkWare, not merely a researcher as initial reports described him.

Levy’s scheme, called Quantum Safe Bitcoin (QSB), spent a 10,000-satoshi output using hash-based one-time signatures combined with computational searches that bind an authorisation to a specific transaction. The construction is designed to remain unforgeable even if a quantum computer breaks elliptic-curve cryptography. No protocol change was required: Levy’s QSB paper, released on 9 April 2026, shows the entire scheme fits inside Bitcoin’s existing legacy Script limits of 201 opcodes and 10,000 bytes.

The security guarantee is roughly 118-bit second pre-image resistance under a quantum threat model, according to The Quantum Insider’s coverage of the QSB proposal. Levy also credited Robin Linus for foundational work on Binohash and for a correction that shaped the final cost-security tradeoff in the scheme.

The Quantum-Resistant Bitcoin Transaction That Couldn’t Use the Mempool

QSB transactions are classified as nonstandard under Bitcoin Core’s default relay policy, so ordinary nodes will not propagate them. Levy had to route the transaction directly to MARA Pool via its Slipstream service, a direct-submission pipeline Marathon launched on 22 February 2024 to handle large or non-standard transactions. As of early August 2026, MARA Pool holds approximately 5.37% of Bitcoin’s total aggregate hashrate, meaning Slipstream transactions sit in a private queue until MARA mines a block.

The cost is the other constraint. Levy estimated in April that generating a QSB transaction would require between $75 and $150 in GPU computation. StarkWare spokesperson Nathan Jeffay subsequently put the actual expense higher, telling reporters the completed transaction cost ‘low hundreds of dollars’ and estimating the figure at around $150 to $200. The process took hours of computation. Levy himself described QSB as a last-resort measure, not a replacement for protocol-level protections.

The urgency framing traces to a March estimate from Google researchers: a sufficiently capable quantum computer could theoretically derive a Bitcoin private key within nine to twelve minutes of its public key becoming visible on-chain, a window that overlaps Bitcoin’s normal confirmation time. QSB addresses that exposure at the individual-transaction level only; it does not upgrade cryptography across the network.

Where BIP-360 Fits and What Comes Next

Levy is also a co-author of BIP-360, the proposed soft fork that would introduce a Pay-to-Merkle-Root (P2MR) output type. The BIP-360 specification notes that P2MR outputs are resistant to long-exposure attacks on elliptic-curve cryptography but not to short-exposure quantum attacks. The proposal’s other co-authors are Hunter Beast (a senior protocol engineer at MARA) and Ethan Heilman and Isabel Foxen Duke, according to Bitcoin Magazine. Post-quantum signature schemes such as ML-DSA (Dilithium) and SLH-DSA (SPHINCS+) are floated as candidates for follow-on soft forks once P2MR is established.

On the testnet side, BTQ Technologies Corp. (Nasdaq: BTQ) shipped what it described as the first working implementation of BIP-360’s P2MR output type in Bitcoin Quantum testnet v0.3.0, released on 19 March 2026, per The Quantum Insider. Bitcoin Core had made no progress toward implementation as of that date.

StarkWare CEO Eli Ben-Sasson was direct about the endgame: ‘A soft fork should happen, and I believe it will.’ QSB is the stopgap in the interim. At $150 to $200 per transaction and a routing dependency on a single pool controlling roughly 5% of hashrate, the scheme is not ready for general use. The open question is how long the soft-fork process takes, given that Bitcoin governance moves slowly and quantum hardware timelines remain contested.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use