Bitcoin Just Proved a Quantum Escape Hatch Works

A Bitcoin output secured by a hash lock rather than an elliptic curve key

On 26 August, a transaction was mined into Bitcoin block 964,199 — a 10,000-satoshi output, a rounding error in value, and the most interesting thing that happened in crypto this month. Its security does not rest on elliptic-curve cryptography. It rests on the difficulty of inverting a hash. It is the first quantum-safe Bitcoin spend, and it required no soft fork and no change to Bitcoin's consensus rules whatsoever.

The construction is called Quantum-Safe Bitcoin, designed by StarkWare researcher Avihu Levy, who published the underlying research in April and, by several accounts, built it on his own time. Engineer Tomer Giladi turned it into a working mainnet transaction.

What the quantum threat to Bitcoin actually is

It is narrower than the headlines suggest, and the shape of it matters for what follows.

Bitcoin signatures use elliptic-curve cryptography. A sufficiently large quantum computer running Shor's algorithm could derive a private key from a public key. But for a standard unspent address, the public key isn't published — the address is a hash of it. The key only becomes visible at the moment you spend: your transaction reveals it, and it sits in the mempool unconfirmed for some minutes before a block includes it.

That window is the attack surface. A quantum adversary would need to see your public key, derive the private key, and broadcast a competing transaction before yours confirms. Which also explains the one thing most people get wrong: the coins genuinely at risk are the ones whose public keys are already exposed — reused addresses, old pay-to-public-key outputs, anything that has already been spent from. Those keys are public forever. No future upgrade retroactively hides them.

How QSB gets around it without changing Bitcoin

This is the clever part. Rather than adding a new signature type — which would require a soft fork and years of governance — Levy's construction abuses Bitcoin's existing rules.

It uses a technique called signature grinding. The sender searches offchain, over sequence and locktime values, until they find a transaction whose RIPEMD-160 hash happens to look like a validly formatted DER-encoded ECDSA signature. The published design estimates this at roughly one in 246 attempts. Bitcoin's existing verification machinery accepts the result — but the security no longer comes from keeping an elliptic-curve secret. It comes from hash preimage resistance, which Shor's algorithm doesn't break. The implementation estimates around 118-bit second-preimage resistance against a quantum attacker.

Notably, it doesn't use STARKs — StarkWare's own technology, which is post-quantum secure. It runs entirely inside Bitcoin, built from tools Bitcoin already has.

Now the limits, which are severe

StarkWare has been unusually straight about this, and their CEO Eli Ben-Sasson put it plainly: this should not be read as saying Bitcoin is prepared for the quantum threat. Far from it.

So why does it matter?

Because it moves a question from "someday, if governance agrees" to "demonstrably possible now."

The assumption for years has been that protecting Bitcoin from quantum attack requires a protocol change — which means a soft fork, which means the kind of multi-year coordination fight Bitcoin is famously bad at. This transaction shows there is an emergency path that does not need anyone's permission. It is expensive, awkward and limited, but it exists, and it exists before the emergency rather than during it. StarkWare still argues a soft fork is the right long-term answer. They are right. But the fallback is no longer theoretical.

It also fits a pattern we have written about repeatedly this year. Zcash quarantined a proof-circuit flaw with a turnstile built from its own arithmetic. THORChain shipped TSS hardening after a signature exploit. The Coldcard entropy failure showed what happens when randomness is quietly wrong. Cryptographic systems fail slowly and then suddenly, and the interesting work is always the preparation done before anyone is forced to do it.

What you can actually do about it

Nothing in this requires you to act today — a quantum computer capable of this doesn't exist yet, and anyone selling you urgency is selling you something. But the threat model does point at one habit worth having anyway:

Don't reuse addresses. An address you have spent from has published its public key permanently. That is the exposure quantum attacks target, and it is also the thing that lets anyone trivially link your transactions today. The same discipline protects you from a hypothetical future adversary and from a very real present one, which is a rare thing in security. Use a wallet that generates a fresh receive address each time — most modern ones do this by default.

Beyond that: keys in your own custody, backed up offline. A protocol-level quantum upgrade, when it comes, will be something your wallet software adopts — which only helps if the coins are somewhere you control rather than on a platform that may not be around for it.

TokensFund compares THORChain, Chainflip, Changee and CCE.Cash on every swap and routes wallet to wallet — no account, no KYC for standard swaps, flat 1% inside the quote. Every swap lands at an address you generated, which is the version of this that stays true regardless of what breaks next.

A note on risk

Nothing here is financial or security advice. Details reflect StarkWare's announcement and contemporaneous reporting as of 29 August 2026; cost estimates for a QSB transaction vary meaningfully between sources. No quantum computer capable of breaking elliptic-curve cryptography is known to exist, and timelines for one are speculative. QSB is an experimental construction, not a product — do not attempt to use it with real funds without understanding it thoroughly.

Swap to addresses you control

Compare routes →