On August 26, a Bitcoin transaction became the first to run on mainnet with protection against a working quantum computer, without any change to Bitcoin's protocol. The work came from Avihu Levy, a researcher and General Manager of Applications at StarkWare, who published the underlying method in April 2026 as a personal project built outside his regular responsibilities. StarkWare engineer Tomer Giladi brought the research from a paper to a live transaction. MARA Slipstream, Marathon Digital Holdings' direct submission service, provided the mining path because the nonstandard format the transaction uses is filtered out by Bitcoin's standard mempool nodes.

StarkWare CEO Eli Ben-Sasson said,

"Avihu took this on after hours, as a passion project, and has now shown that Bitcoin has no expiration date. I still want Bitcoin to choose to do a soft fork and I expect we will get one. What today's successful transaction offers Bitcoin is a reassurance that holdings can be protected before that happens."

The approach draws on Binohash, a technique developed by Robin Linus, the creator of BitVM.

Why the mempool window matters for quantum security

Bitcoin's signatures rely on elliptic curve cryptography on the secp256k1 curve. When a holder spends from an address, the transaction reveals the public key. That key stays visible in the mempool until a miner includes the transaction in a block. Classical computers cannot work backward from a public key to the private key in any practical timeframe, so the exposure window is currently harmless.

Shor's algorithm, run on a sufficiently powerful quantum computer, removes that protection entirely. It targets exactly the class of mathematical problem that makes elliptic curve cryptography secure. A quantum adversary monitoring the mempool could read a public key, derive the private key, and broadcast a competing transaction before the original is confirmed.

Reaching that capability requires a fault-tolerant machine with millions of error-corrected logical qubits. Google's Willow chip, announced in December 2024, achieved notable benchmark results with 105 physical qubits, but cryptographically relevant quantum computing sits far beyond what any publicly known hardware can currently do. The concern is the gap between now and whenever such hardware arrives. Bitcoin's consensus rules do not change on short timelines. NIST finalized its first post-quantum cryptographic standards in August 2024, publishing SLH-DSA, a hash-based signature scheme, and ML-DSA, a lattice-based alternative. Neither has entered Bitcoin's protocol.

How signature grinding removes the private key from the equation

Levy's method adds a second security layer alongside Bitcoin's existing elliptic curve signature. That second layer rests on hash functions rather than elliptic curves. Shor's algorithm cannot break hash functions. The most capable known quantum attack against a hash is Grover's algorithm, which provides a quadratic speedup over classical brute force. That speedup is not sufficient to reverse a well-constructed hash.

The technical mechanism is signature grinding. A valid Bitcoin signature must conform to a specific format. The method searches for a spending transaction whose hash output happens to meet that format requirement. Bitcoin accepts the result because it looks like a valid signature. No private key enters the process. Security then depends on the computational difficulty of reversing a hash rather than the secrecy of a key. The computation happens offchain before the transaction is broadcast and currently costs several hundred dollars.

The limits of what today's transaction proves

StarkWare was direct about what changed and what did not. QSB does not make Bitcoin itself quantum-safe. The consensus rules are unchanged, and the network has no new protocol-level protection across its existing address pool.

A substantial portion of Bitcoin in circulation sits in addresses that have already revealed their public keys, either through prior spending or through early address formats that published keys directly without hashing them first. Those holdings cannot be protected retroactively by QSB. A holder who wants to use the method must act before a quantum adversary has the capacity to exploit a revealed key, which means the method is only useful while quantum computers still fall short of breaking current elliptic curve cryptography.

The nonstandard format also creates a practical constraint today. Standard mempool nodes filter such transactions out, so submitting one requires a direct path to a willing miner. MARA Slipstream provided that path for August 26's transaction. Wider accessibility would require either broader miner support for nonstandard formats or a soft fork that formalizes a new address type for the approach.

Starknet's own quantum roadmap and where it stands

ZK-STARKs, the proving system underlying Starknet, have never depended on elliptic curve cryptography. Hash functions are the mathematical foundation. Native account abstraction on Starknet allows an individual account to adopt a quantum-resistant signature scheme without a protocol change across the network. Post-quantum accounts are already live on Starknet mainnet.

StarkWare published a three-phase quantum security roadmap in June. Phase one targets elliptic curve dependencies that remain in state commitments and contract address derivation. Parts of that phase have shipped. Phase two extends the same protections to existing contracts. Phase three waits on Ethereum because the bridge that connects Starknet to Ethereum and the data availability layer where Starknet posts its transaction data both still inherit elliptic curve cryptography from L1. The full roadmap is at quantum.starkware.co.

Levy's QSB method does not use STARKs. He built it from tools Bitcoin already has, because that was the path available without a protocol change. As StarkWare noted in its announcement, a soft fork remains the better long-term answer, but August 26's transaction demonstrated it is no longer the only option available to Bitcoin holders.

Bitcoin Tops $81K as ETF Inflows and Treasury Move Align | HODL FM NEWS
Bitcoin hit $81,237 on Treasury buyback news. Six straight days of ETF inflows totaled $2.26 billion as analysts debated whether a bull market had begun.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.