Risk Radar

Bitcoin Security / high

Bitcoin Just Tested a Quantum-Safe Transaction — But BTC Is Not Quantum-Proof Yet

StarkWare has executed an experimental quantum-safe Bitcoin transaction on mainnet without changing Bitcoin's consensus rules. Here's what it proves—and what it doesn't.

August 28, 2026Last updated 10:30 UTC5 min read

A Bitcoin transaction confirmed this week may eventually matter far more than its monetary value suggests.

On August 26, 2026, StarkWare announced that an experimental quantum-safe Bitcoin transaction had been mined on Bitcoin mainnet.

The transaction used a method called Quantum-Safe Bitcoin, or QSB, developed by StarkWare researcher Avihu Levy.

Most importantly, the test worked without changing Bitcoin's existing consensus rules. (StarkWare)

That sounds like Bitcoin has solved the quantum-computing problem.

It has not.

What happened is narrower — but technically significant.

Why quantum computers could threaten Bitcoin

Bitcoin ownership relies heavily on public-key cryptography.

A private key produces a public key, and digital signatures prove that the person spending Bitcoin controls the corresponding private key.

Current computers cannot practically derive a Bitcoin private key from its exposed public key.

A sufficiently powerful cryptographically relevant quantum computer could theoretically change that.

Algorithms such as Shor's algorithm could attack elliptic-curve cryptography much more efficiently than classical computers.

That creates a future risk:

If a public key is exposed, could a quantum computer reconstruct the private key and steal the Bitcoin?

Today's quantum computers are nowhere near the capability required to attack Bitcoin at scale.

But migration takes time.

That is why researchers are experimenting now.

What StarkWare actually did

The QSB method protects funds using hash-based cryptographic techniques rather than relying exclusively on Bitcoin's conventional elliptic-curve signature system.

The experimental transaction spent a specially protected Bitcoin output on mainnet.

StarkWare says the scheme can withstand an attacker equipped with a future functioning quantum computer.

And it did so within Bitcoin's existing rules. (StarkWare)

That last point is important.

Bitcoin upgrades are difficult because any consensus change requires broad coordination across:

  • developers;
  • node operators;
  • miners;
  • wallets;
  • exchanges;
  • users.

A method that can offer some protection before a network-wide upgrade could provide an emergency migration path.

Why Bitcoin is not quantum-safe now

This is the distinction most headlines risk missing.

The experiment does not retroactively protect all Bitcoin.

Existing BTC remains governed by Bitcoin's normal cryptographic structure.

QSB only protects outputs deliberately moved into the special construction.

So the accurate conclusion is:

Bitcoin has demonstrated an experimental quantum-resistant storage technique.

Not:

Bitcoin is quantum-proof.

Even StarkWare continues to support a future protocol-level upgrade as the cleaner long-term solution. (StarkWare)

Which Bitcoin is most exposed?

Quantum risk is not identical for every Bitcoin output.

Generally, the concern becomes greater once a public key has been revealed onchain.

Modern Bitcoin addresses often hide the public key until the coin is spent.

But older address types, reused addresses and certain already-spent constructions can expose public keys.

That means any future quantum migration will need to consider:

  • lost coins;
  • old wallets;
  • inactive whale addresses;
  • exchange custody;
  • reused addresses.

One of the most politically difficult questions may eventually be:

What happens to coins that never migrate?

If powerful quantum computers arrive and abandoned coins remain vulnerable, attackers could potentially claim them.

That creates major technical and governance questions.

Why this matters now

The quantum threat is not an immediate Bitcoin crisis.

But waiting until quantum computers can break today's cryptography would be far too late.

Bitcoin has hundreds of billions of dollars of value distributed across millions of addresses.

Updating that system could require years.

The correct time to design migration paths is therefore before they are urgently needed.

StarkWare's experiment is valuable because it moves quantum resistance from:

academic discussion

to:

something that has actually executed on Bitcoin mainnet.

The trade-offs

The method is not currently suited for normal Bitcoin payments.

Quantum-resistant signature structures can be much larger and computationally expensive.

Reports on the experiment indicate meaningful offchain computation and larger data requirements compared with an ordinary Bitcoin transaction. (Crypto Economy)

That makes QSB more similar to:

emergency secure storage

than:

replacement for every Bitcoin transaction.

A future protocol-level post-quantum signature scheme could offer better efficiency.

The real timeline remains unknown

Nobody knows exactly when — or whether — quantum computers capable of breaking Bitcoin's current cryptography will become operational.

Predictions vary dramatically.

That uncertainty cuts both ways.

Dismissing the problem because it is not immediate is risky.

Claiming Bitcoin is about to be broken is equally misleading.

The practical approach is preparation.

What to watch next

The important developments are:

  1. additional QSB mainnet tests;
  2. wallet integrations;
  3. Bitcoin Improvement Proposals for post-quantum signatures;
  4. advances in cryptographically relevant quantum computing;
  5. exchange and custodian migration plans;
  6. decisions around old or abandoned BTC.

The biggest takeaway from this week's transaction is therefore not:

Quantum Bitcoin is solved.

It is:

Bitcoin developers now have evidence that at least one quantum-resistant migration technique can operate under today's Bitcoin rules.

For an asset designed to survive for decades, that is worth paying attention to.

FAQ

Is Bitcoin quantum-safe?

Bitcoin's standard cryptography is not considered resistant to a sufficiently powerful future quantum computer. However, no currently available quantum computer can practically break Bitcoin cryptography at scale.

What did StarkWare test?

StarkWare executed an experimental Bitcoin mainnet transaction using a quantum-resistant method called Quantum-Safe Bitcoin.

Did Bitcoin need a hard fork?

No. The experimental transaction worked within Bitcoin's existing consensus rules.

Should Bitcoin holders move their coins now?

There is no evidence of an immediate quantum threat requiring normal Bitcoin users to urgently move funds.