The First Quantum-Safe Bitcoin Transaction Needed a Miner's Side Door

StarkWare ran the first quantum-safe Bitcoin transaction on mainnet, but ordinary nodes rejected it and about 7 million exposed coins get no help.

Jan Whitfield Tech

On August 26, a 10,000 satoshi output moved on the Bitcoin mainnet. Worth about eight dollars. The payment landed in block 964,199, and within hours it carried a claim across every crypto feed: the first quantum-safe Bitcoin transaction had cleared without changing a line of Bitcoin's rules. The demonstration was real. So were the parts most of the coverage skipped past.

Avihu Levy, StarkWare's first employee and the head of its applications work, built the method. It leans on a trick called signature grinding. Rather than accept the first valid signature a wallet produces, the software brute-forces millions of candidates until it finds one whose shape never puts the public key where a future quantum computer could read it. That grinding is slow, and it is not free.

An eight dollar payment that cost hundreds

The transaction fee alone came to 5,179 satoshis. The offchain computation behind it ran to roughly $75 to $150 by Levy's own account, and pushing the whole thing through cost several hundred dollars. For a payment worth eight. Price is the smaller problem. Bitcoin nodes relay only the transaction formats they already recognize, and this one looked odd enough that an ordinary node would drop it on sight.

So it never traveled the network at all. Levy handed it straight to a miner. MARA Pool took it through Slipstream, its private channel for nonstandard transactions, and mined it directly into the block. A quantum-safe Bitcoin transaction sits on-chain today because one large mining operation agreed to carry it past the network that would have refused it.

The seven million coins it cannot touch

Signature grinding only helps a coin while its public key stays hidden behind a hash. A lot of bitcoin no longer qualifies. Estimates put around 7 million BTC in categories where the key is already visible, and a quantum-safe Bitcoin transaction does nothing for any of them, because the thing a quantum attacker would need is public knowledge already. No machine capable of breaking that key exists yet, which is the only reason those coins are still sitting untouched.

Coin typePublic key statusHelped by grinding
Unspent, never reusedHidden behind a hashYes, if moved in time
Pay-to-public-key, the earliest coinsVisible on-chainNo
Reused addressesAlready publishedNo
Spent Taproot outputsRevealed at spendNo

Coinliva read the same story off the chain's own data months back: about a third of all bitcoin has already shown its public key on-chain. Migrating those coins into a hash-protected output does not close the gap either. The migration is itself a standard transaction, and it exposes the sending key on the way out.

Why the real fix runs through the miners

StarkWare framed the result as proof that guarding holdings never required a protocol change. Then its own chief executive, Eli Ben-Sasson, said the quiet part out loud. "A soft fork should happen, and I believe it will." A soft fork is not StarkWare's to grant. It needs miners to signal support over months, the same slow gate that has stranded other Bitcoin proposals this year. The grinding demo is a workaround for anyone who can afford it and knows a cooperative miner. It is not a network that defends itself.

Bitcoin mining has had a strange year on its own terms. Difficulty fell year on year, something that had happened only once before. Quantum defense now joins the list of upgrades that ask miners to move before the danger can be measured on any chart. Bitcoin still carries no protocol-level guard against a quantum break, and one clever transaction does not change that. The transaction in block 964,199 proved a narrow point. The coins that most need protecting still do not have it, and the network that would deliver that protection has not yet been asked to vote.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Jan Whitfield
Author

Jan Whitfield

Jan Whitfield is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.