Blockchain technology company StarkWare said on August 26 local time that a transaction constructed in a quantum-resistant manner had been mined on the Bitcoin mainnet. Bitcoin addresses are usually hashes of public keys, so the public key is not revealed until the coins are spent. But once a spending transaction exposes the public key, there is a risk that during the period it sits in the mempool before being mined, a sufficiently powerful quantum computer could derive the private key from the public key and spend the same coins first. This Quantum-Safe Bitcoin (QSB) approach places a second, quantum-resistant lock based on hash functions alongside the existing lock, and uses "signature grinding," which finds a valid Bitcoin signature without a private key. The sender searches repeatedly off-chain until the hash of the spending transaction is a signature in a valid form, so the security of the transaction comes to rest on the difficulty of inverting a hash rather than on the secrecy of a private key. Bitcoin's consensus rules were not changed, and STARK, StarkWare's zero-knowledge proof technology, was not used either. StarkWare said one transaction costs several hundred dollars, and Unchained reported that creating a single transaction required several hours of computation. Because the transaction format is non-standard, ordinary nodes do not accept it into their mempools or relay it. The researchers delivered the transaction directly to miners through MARA's Slipstream. Unchained reported that the transaction was included in block 964,199 at a size of 10,000 satoshis. Addresses that have already been spent from, and whose public keys are therefore exposed on-chain, are not protected by QSB alone and require separate measures to move the funds. Eli Ben-Sasson, StarkWare's chief executive officer, said he still wants Bitcoin to choose a soft fork. Because standards proposals and adoption by nodes and wallets remain, this demonstration does not make the entire Bitcoin network safe from quantum computers.
StarkWare Demonstrates a Quantum-Resistant Transaction on the Bitcoin Mainnet: Ordinary Nodes Still Cannot Relay It
Metanomia View
Quantum risk is not solely a matter of cryptography. It is also a question of who can move to a safe address first, and which nodes and miners will accept a new transaction format. This demonstration showed that defensive experiments are possible even before a consensus change, but the method costs several hundred dollars and several hours per transaction, so rights for ordinary users only materialize once standard wallets and relay networks follow. Domestic custodians and exchanges should not treat quantum risk as a distant-future concern either, and need to prepare plans for moving assets whose public keys have already been exposed.