StarkWare Says it Confirmed a Quantum Safe Bitcoin Transaction on Mainnet
Blockchains
StarkWare said a Bitcoin transaction using its Quantum Safe Bitcoin, or QSB, design was mined on mainnet without changing Bitcoin’s consensus rules.
The transaction 305a24ff…ab07 was confirmed in block 964,199 on Aug. 26. Blockstream’s record shows that it combined 39,179- and 10,000-satoshi inputs, created one 44,000-satoshi output and paid a 5,179-satoshi fee. The transaction was 1,403 bytes.
The onchain record confirms the cited transaction was included in a block, but it does not independently establish the construction’s claimed resistance to quantum attacks.
StarkWare announced the transaction on Aug. 26 and described it as the first quantum-safe Bitcoin transaction. Researcher Avihu Levy called it a QSB transaction on mainnet.
No Soft Fork Required
QSB uses Bitcoin’s existing legacy scripting rules rather than requiring a soft fork, according to Levy’s open-source implementation. The repository describes a hash-based one-time signature and a “hash-to-signature” puzzle that Levy says depends on RIPEMD-160 preimage resistance rather than the difficulty of breaking an elliptic curve.
The documented process starts with an offchain search over sequence and locktime values until the RIPEMD-160 hash of a transaction-bound public key looks like a valid DER-encoded ECDSA signature, an event the design estimates at roughly one in 2^46 attempts. Two further search rounds select subsets of dummy signatures; the selected indices form a compact identifier for the transaction, while the assembly step extracts the HORS preimages.
ECDSA remains part of the verification path available to Bitcoin Script. The implementation says it is used “only as a vehicle,” while the security-critical work comes from hashing rather than elliptic-curve hardness. Those are the design’s stated security properties, not an independent cryptographic assessment of the transaction.
The parent funding transaction, which contained the 10,000-satoshi output, was confirmed on July 16. It measured 10,125 bytes and paid a 30,000-satoshi fee.
A Mainnet Transaction
StarkWare says QSB does not make Bitcoin quantum-safe. The method protects coins only after they are moved into the special output; it does not retrofit resistance onto ordinary ECDSA- or Schnorr-secured holdings. StarkWare also said the method would not help an address whose public key had already been exposed before the protective transaction was sent.
The transaction was nonstandard and needed a direct path to a miner. Mempool.space labels the spend “Non-Standard” and “Not seen in Mempool,” and identifies MARA Pool as the miner. StarkWare said MARA’s Slipstream service provided the mining path.
Levy’s paper calls the approach a last-resort measure. It says the offchain computation and onchain cost do not scale to Bitcoin’s expected users and throughput, the transaction-generation process is more complex than standard Bitcoin usage, and the scheme does not cover uses such as Lightning Network channels.
The verified result is therefore narrow: transaction 305a24ff…ab07 was mined, while StarkWare and Levy identify it as an implementation of QSB and make the quantum-resistance claim. The blockchain record does not itself audit that claim, and ordinary Bitcoin holdings were not changed by the transaction.
Advertisement
Get an edge in Crypto with our free daily newsletter
Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri
90k+ Defiers informed every day. Unsubscribe anytime.
