A new Bitcoin mainnet transaction demonstrates a quantum-resistant method for moving funds, but roughly 7 million BTC remain exposed to future quantum attacks due to public key visibility and protocol limitations
Bitcoin has taken a step toward addressing the long-term threat posed by quantum computing, with a recent mainnet transaction demonstrating that some funds can be moved using quantum-resistant techniques-without waiting for a protocol upgrade. The transaction, included in block 964,199 on August 26, used a hash-based security method developed by StarkWare researcher Avihu Levy. This approach shifts the critical spending condition away from traditional elliptic-curve signatures, which are vulnerable to quantum attacks, and instead relies on the difficulty of reversing hash functions. The transaction was submitted directly to miner MARA via its Slipstream service, bypassing the public mempool due to its nonstandard format.
Quantum Risk Remains
While the demonstration shows that quantum-resistant transactions are possible under Bitcoin's current consensus rules, it does not mean the network is broadly protected. According to StarkWare, the method-called Quantum-Safe Bitcoin (QSB)-only works for coins whose public keys have not yet been revealed on-chain. Once a public key is exposed, as is the case with older pay-to-public-key outputs, Taproot outputs, or reused addresses, those coins remain vulnerable to future quantum computers that could derive private keys from public keys. StarkWare's CEO, Eli Ben-Sasson, emphasized that a scalable, protocol-level solution is still needed to protect the entire network.
Technical and Practical Barriers
The QSB method leverages the fact that, for many Bitcoin addresses, the public key remains hidden until the first spend. By repeatedly varying transaction data until a valid hash-based signature is produced, eligible coins can be moved to a quantum-resistant condition before their public key is revealed. However, this process is computationally intensive and costly-StarkWare reported that the mainnet test required several hundred dollars' worth of cloud GPU resources. Additionally, because the transaction is nonstandard, it cannot be broadcast through the public mempool and must be submitted directly to a miner willing to include it. These limitations make QSB a niche escape route rather than a practical solution for most users.
Millions of BTC Still Exposed
Estimates suggest that about 7 million BTC are potentially exposed to quantum risk because their public keys are already visible on the blockchain. For these coins, the QSB workaround offers no protection. The challenge of securing these funds remains unresolved, and a protocol-level migration path would likely require a soft fork or other network-wide upgrade. As quantum risk becomes a more prominent concern for institutions and regulators, industry groups such as the Bitcoin Security Consortium-formed by BlackRock, Coinbase, and others-have pledged funding for research into post-quantum cryptography. The U.S. Treasury has also begun including digital assets in its broader quantum-readiness planning.
Bitcoin's quantum vulnerability is not the only security issue facing the industry. As major exchanges wind down operations and traditional financial institutions accelerate blockchain adoption, the landscape for digital asset security continues to evolve. For example, recent developments in institutional blockchain infrastructure are covered in EgonCoin's analysis of how exchange closures are reshaping the crypto market.
According to blockchain data, the transaction demonstrating the QSB method was included in block 964,199 on August 26, 2026. At the time, Bitcoin's circulating supply was approximately 19.7 million BTC, with an estimated 7 million BTC considered at risk due to public key exposure. The Bitcoin Security Consortium has committed $15 million over three years to support research into quantum-resistant solutions and broader network security.
Quantum computing poses a unique challenge for blockchain networks like Bitcoin because it threatens the cryptographic assumptions underlying digital signatures. While hash functions are also theoretically vulnerable to quantum attacks, the advantage is far smaller than with public-key cryptography. This means that hash-based approaches can buy time, but they are not a permanent fix. The window for migration is limited, and the cost and complexity of current solutions make them inaccessible for most users. As the industry debates protocol upgrades and migration strategies, the risk to exposed coins remains a critical concern for holders, developers, and regulators alike.