+1.09%
-0.07%
-0.69%
-0.68%
-3.09%
-1.55%
The move targets a real weakness in Bitcoin’s underlying cryptography. Elliptic-curve signatures, the standard used by Bitcoin and most major blockchains, are vulnerable to an algorithm called Shor’s algorithm once quantum computers reach sufficient power. Right now, no machine can pull that off. Google researchers projected in 2026 that breaking Bitcoin’s secp256k1 curve would need 1,200 logical qubits, though simulations suggest fewer than half a million physical qubits might actually be required. That’s still a significant technical hurdle, but not an impossible one, and it’s exactly why teams like StarkWare are moving now rather than waiting.
How Exposed Is Bitcoin Right Now
Glassnode Research estimates 6.04 million BTC, roughly 30.2% of total supply, is currently quantum-exposed in some form.
- 1.92 million BTC are structurally exposed due to output type
- 4.12 million BTC are operationally exposed through practices like address reuse or custody behavior
The distinction matters. Structural exposure is baked into how certain coins were originally sent. Operational exposure comes down to habits, meaning some of that risk could be reduced today simply by changing how wallets and custodians handle addresses.
The Method Behind the Transaction
Avihu Levy, StarkWare’s general manager of applications, built the system behind this transaction, called Quantum-Safe Bitcoin (QSB). It solves the vulnerability without touching Bitcoin’s consensus protocol at all.
QSB relies on something called Binohash, which turns the quantum-vulnerable part of a transaction into a hash-to-signature puzzle instead. That approach leans on RIPEMD-160’s pre-image resistance rather than the elliptic-curve math that Shor’s algorithm can break. Senders have to run resource-intensive computations off-chain before sending, and that computation isn’t cheap. GPU costs run between $75 and $200 per transaction and can take several hours depending on GPU availability.
Because QSB transactions are nonstandard, they bypass the normal mempool entirely. StarkWare sent its transaction directly to a miner, with mining company MARA inserting it through its Slipstream service.
What This Does Not Fix
QSB cannot secure the 6.04 million BTC already exposed. Glassnode is clear on that point. It protects new transactions going forward and gives holders a way to safely store protected coins, but it does nothing for coins that are already sitting in vulnerable addresses.
For that, Levy and StarkWare CEO Eli Ben-Sasson are pushing for changes at the protocol level. BIP 360 proposes a new output type called Pay-to-Merkle-Root, which would let holders migrate away from quantum-vulnerable signatures. BIP 361 goes further, suggesting a phased sunset for legacy ECDSA and Schnorr signatures altogether.
Ben-Sasson described Wednesday’s demonstration as “breathing room,” not a permanent answer. He has previously compared crypto’s quantum exposure to the Titanic, and after this test, he offered a more hopeful framing: “there are lifeboats.”
Hashlytics Take
Calling this Bitcoin’s “first quantum-safe transaction” is technically accurate and slightly misleading at the same time. It’s a working proof of concept for new coins, not a fix for the 30% of supply already sitting exposed. Ben-Sasson’s own framing, breathing room rather than a solution, is the more honest read here. The real story isn’t that Bitcoin solved its quantum problem. It’s that solving it will require a protocol-level fight over BIP 360 and BIP 361, and those fights move a lot slower than a single mainnet demo.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



