Bitcoin Just Proved a Quantum Escape Hatch Works

On 26 August, a transaction was mined into Bitcoin block 964,199 — a 10,000-satoshi output, a rounding error in value, and the most interesting thing that happened in crypto this month. Its security does not rest on elliptic-curve cryptography. It rests on the difficulty of inverting a hash. It is the first quantum-safe Bitcoin spend, and it required no soft fork and no change to Bitcoin's consensus rules whatsoever.
The construction is called Quantum-Safe Bitcoin, designed by StarkWare researcher Avihu Levy, who published the underlying research in April and, by several accounts, built it on his own time. Engineer Tomer Giladi turned it into a working mainnet transaction.
What the quantum threat to Bitcoin actually is
It is narrower than the headlines suggest, and the shape of it matters for what follows.
Bitcoin signatures use elliptic-curve cryptography. A sufficiently large quantum computer running Shor's algorithm could derive a private key from a public key. But for a standard unspent address, the public key isn't published — the address is a hash of it. The key only becomes visible at the moment you spend: your transaction reveals it, and it sits in the mempool unconfirmed for some minutes before a block includes it.
That window is the attack surface. A quantum adversary would need to see your public key, derive the private key, and broadcast a competing transaction before yours confirms. Which also explains the one thing most people get wrong: the coins genuinely at risk are the ones whose public keys are already exposed — reused addresses, old pay-to-public-key outputs, anything that has already been spent from. Those keys are public forever. No future upgrade retroactively hides them.
How QSB gets around it without changing Bitcoin
This is the clever part. Rather than adding a new signature type — which would require a soft fork and years of governance — Levy's construction abuses Bitcoin's existing rules.
It uses a technique called signature grinding. The sender searches offchain, over sequence and locktime values, until they find a transaction whose RIPEMD-160 hash happens to look like a validly formatted DER-encoded ECDSA signature. The published design estimates this at roughly one in 246 attempts. Bitcoin's existing verification machinery accepts the result — but the security no longer comes from keeping an elliptic-curve secret. It comes from hash preimage resistance, which Shor's algorithm doesn't break. The implementation estimates around 118-bit second-preimage resistance against a quantum attacker.
Notably, it doesn't use STARKs — StarkWare's own technology, which is post-quantum secure. It runs entirely inside Bitcoin, built from tools Bitcoin already has.
Now the limits, which are severe
StarkWare has been unusually straight about this, and their CEO Eli Ben-Sasson put it plainly: this should not be read as saying Bitcoin is prepared for the quantum threat. Far from it.
- It is expensive and slow. Producing one QSB spend takes hours of computation across high-end GPUs. Published estimates of the cost range from roughly $75 to a few hundred dollars per transaction — orders of magnitude above a normal Bitcoin fee.
- It can't travel normally. The script format is nonstandard, so ordinary nodes won't relay it through the public mempool. This transaction had to be handed directly to a miner through MARA's Slipstream service. A defence that depends on knowing a miner is not a defence available to everyone.
- It protects a narrow slice. It works for legacy outputs. It does not secure Taproot outputs, Lightning channels, or — crucially — any address whose public key has already been exposed. The coins in most danger are precisely the ones it cannot help.
- Bitcoin itself is unchanged. QSB protects specific coins moved into a hash-based output. The network's signature scheme is exactly as quantum-vulnerable as it was last week.
So why does it matter?
Because it moves a question from "someday, if governance agrees" to "demonstrably possible now."
The assumption for years has been that protecting Bitcoin from quantum attack requires a protocol change — which means a soft fork, which means the kind of multi-year coordination fight Bitcoin is famously bad at. This transaction shows there is an emergency path that does not need anyone's permission. It is expensive, awkward and limited, but it exists, and it exists before the emergency rather than during it. StarkWare still argues a soft fork is the right long-term answer. They are right. But the fallback is no longer theoretical.
It also fits a pattern we have written about repeatedly this year. Zcash quarantined a proof-circuit flaw with a turnstile built from its own arithmetic. THORChain shipped TSS hardening after a signature exploit. The Coldcard entropy failure showed what happens when randomness is quietly wrong. Cryptographic systems fail slowly and then suddenly, and the interesting work is always the preparation done before anyone is forced to do it.
What you can actually do about it
Nothing in this requires you to act today — a quantum computer capable of this doesn't exist yet, and anyone selling you urgency is selling you something. But the threat model does point at one habit worth having anyway:
Don't reuse addresses. An address you have spent from has published its public key permanently. That is the exposure quantum attacks target, and it is also the thing that lets anyone trivially link your transactions today. The same discipline protects you from a hypothetical future adversary and from a very real present one, which is a rare thing in security. Use a wallet that generates a fresh receive address each time — most modern ones do this by default.
Beyond that: keys in your own custody, backed up offline. A protocol-level quantum upgrade, when it comes, will be something your wallet software adopts — which only helps if the coins are somewhere you control rather than on a platform that may not be around for it.
TokensFund compares THORChain, Chainflip, Changee and CCE.Cash on every swap and routes wallet to wallet — no account, no KYC for standard swaps, flat 1% inside the quote. Every swap lands at an address you generated, which is the version of this that stays true regardless of what breaks next.
A note on risk
Nothing here is financial or security advice. Details reflect StarkWare's announcement and contemporaneous reporting as of 29 August 2026; cost estimates for a QSB transaction vary meaningfully between sources. No quantum computer capable of breaking elliptic-curve cryptography is known to exist, and timelines for one are speculative. QSB is an experimental construction, not a product — do not attempt to use it with real funds without understanding it thoroughly.
Swap to addresses you control
Compare routes →