StarkWare reports a quantum-safe Bitcoin mainnet transaction
StarkWare says a Bitcoin transaction using Avihu Levy’s Quantum-Safe Bitcoin method has been mined on mainnet without changing Bitcoin’s consensus rules. The company describes the transaction as the first mainnet use of the QSB construction. The claim matters because it tests whether some coins can be moved into quantum-resistant storage before a future Bitcoin protocol upgrade. It does not mean Bitcoin as a whole is quantum-safe.What StarkWare says was mined
StarkWare says Avihu Levy’s Quantum-Safe Bitcoin, or QSB, method moved from a research paper to Bitcoin mainnet with a transaction that adds quantum-resistant protection without a consensus change. The company says Levy, a researcher and General Manager of Applications at StarkWare, published the research in April 2026, and that StarkWare engineer Tomer Giladi helped bring the construction to a working transaction.The announcement frames the event as a proof that a holder can move coins into a form of storage designed to resist an adversary with a working quantum computer. That is narrower than making the network quantum-safe. The Bitcoin protocol remained unchanged, and StarkWare itself says a soft fork remains the better long-term answer.
How QSB changes the spending risk
The QSB design targets a specific risk window: the period after a Bitcoin public key is exposed and before the transaction is confirmed. Bitcoin signatures rely on elliptic curve cryptography, and StarkWare says Shor’s algorithm running on a sufficiently powerful quantum computer would be able to solve that class of problem quickly.Many Bitcoin addresses hide the public key behind a hash until coins are spent. When a transaction is broadcast, the signature reveals the public key, and the transaction can wait in the mempool before a miner includes it. In StarkWare’s threat model, a quantum adversary could use that open interval to derive the private key and attempt to spend the coins first. QSB is presented as a way to close that particular exposure by adding a second lock based on hash functions rather than elliptic curves.
Why the method avoids a consensus change
StarkWare says QSB works inside Bitcoin as it exists today by relying on tools already accepted by the network. The company says the construction uses signature grinding and draws heavily on Binohash, developed by BitVM creator Robin Linus. In broad terms, the sender spends computation offchain before broadcast, searching for a transaction form that Bitcoin will accept while shifting the security assumption toward the difficulty of reversing a hash.The practical implication is that the experiment did not require a hard fork or soft fork to be mined. That is the main reason the announcement is significant: it suggests a possible protective path for some funds before any protocol-level migration. StarkWare also says the current approach costs several hundred dollars, so it is not presented as a routine retail wallet feature.
The limits are as important as the result
The company is explicit that QSB does not make Bitcoin itself quantum-safe. It also says the method would not help an address whose public key had already been published before the QSB transaction was sent, because a quantum adversary would already have time to work from that exposed key.There is also an operational constraint. StarkWare says QSB transactions use nonstandard formats, so they do not travel through the ordinary mempool and currently need a direct path to a miner. MARA Slipstream provided that mining path for the reported transaction. That means the construction is not yet a simple, broadly available workflow for ordinary users, and any interpretation should separate the mainnet demonstration from mature infrastructure.
StarkWare separates QSB from its own STARK technology
StarkWare says QSB does not use STARKs, even though the company’s wider technology is based on ZK-STARKs, which it describes as post-quantum secure. The announcement says Levy could have built a STARK-based approach, but instead built a construction that runs entirely within Bitcoin using existing Bitcoin tools.The blog also connects the Bitcoin demonstration to Starknet’s own quantum roadmap. StarkWare says Starknet has native account abstraction that can let accounts change signature schemes without a protocol change, and says post-quantum accounts are already live on Starknet mainnet. At the same time, it says Starknet is not quantum-ready today and still has a three-phase roadmap covering remaining elliptic-curve dependencies, existing contracts, and Ethereum-linked bridge and data availability components.
Conclusion
The reported QSB transaction is best read as a constrained but notable mainnet demonstration, not as a completed solution for Bitcoin’s quantum problem. StarkWare’s own framing supports that distinction: the transaction worked without changing consensus rules, but it depends on nonstandard handling, miner-direct routing, and a use case where the relevant public key was not already exposed.For Bitcoin, the immediate implication is analytical rather than investment-related. If StarkWare’s account is accurate, one defensive path can exist before a soft fork. The broader migration question remains unresolved: how to protect ordinary wallets, old coins, exposed keys and cross-chain infrastructure at scale.
Sources
Editorial Team - CoinBotLab