Key Highlights
- StarkWare has demonstrated a quantum-resistant Bitcoin transaction method that operates within current protocol rules, requiring no soft fork or network upgrade.
- The approach uses hash-based cryptography to protect against quantum computers deriving private keys from exposed public keys, but costs approximately $320 in computing per transaction under current implementation.
- Significant limitations remain: transactions must be submitted directly to miners, and the method cannot protect coins whose public keys are already exposed — the primary target for any quantum attacker.
StarkWare Unveils Quantum-Resistant Bitcoin Transaction Method Without Protocol Changes
Israeli blockchain scaling firm StarkWare has published research demonstrating a method to execute quantum-resistant transactions on Bitcoin without requiring a soft fork or any modification to the network’s consensus rules. The technique leverages hash-based cryptographic commitments — specifically leveraging the collision resistance of SHA-256 — to shield coins from a future scenario in which a sufficiently powerful quantum computer could derive a private key from an exposed public key using Shor’s algorithm.
Because the construction fits entirely within Bitcoin’s existing script and transaction validity rules, it can be deployed immediately as an emergency mitigation if the quantum threat materializes before the broader ecosystem adopts a more comprehensive, protocol-level upgrade such as BIP-360 or similar proposals for post-quantum signature schemes. However, the current implementation carries a steep computational price tag: approximately $320 of computing resources per transaction, according to the cost breakdown published by StarkWare.
Cost Claims and Independent Verification
A third-party contest site associated with the research cites a lower figure of $66 per transaction, but this number remains an estimate drawn from a test computation and has not been validated by a subsequent transaction actually mined on the Bitcoin mainnet. The improved code referenced by the contest site has not been shown preparing another transaction that was successfully included in a block. Applying the speedups displayed on the contest site to StarkWare’s original $320 cost breakdown yields an estimated $83 per transaction, according to calculations performed by CoinDesk. The contest site states that later record-setting runs surpass those measurements, though it does not disclose which specific results underpin the $66 estimate.
Operational Constraints Limit Practical Deployment
Beyond cost, the method imposes structural constraints that reduce its utility as a general-purpose solution. Transactions constructed using this approach must be sent directly to a miner because they do not propagate through the Bitcoin peer-to-peer network in the standard manner. More critically, the protection only applies to coins whose public keys have not yet been exposed on-chain — such as those locked in pay-to-taproot (P2TR) or pay-to-witness-script-hash (P2WSH) outputs where the public key remains hidden until spending. Coins in pay-to-pubkey-hash (P2PKH) or reused pay-to-taproot addresses with revealed public keys — the very cohort a quantum adversary would target first — cannot be secured retroactively by this method.
Why This Matters
The research addresses a long-standing theoretical vulnerability in Bitcoin’s elliptic curve cryptography (secp256k1), which secures the vast majority of coins in circulation. While large-scale, fault-tolerant quantum computers capable of breaking ECDSA do not yet exist, advances in quantum error correction and qubit coherence have accelerated expert timelines. The National Institute of Standards and Technology (NIST) has already standardized post-quantum algorithms such as CRYSTALS-Dilithium and SPHINCS+, but integrating them into Bitcoin would require a contentious, multi-year soft fork process with broad miner, developer, and user consensus.
StarkWare’s hash-based fallback offers a permissionless, immediate escape hatch — but only for a subset of unspent transaction outputs (UTXOs) and at a cost that currently limits use to high-value holdings. The requirement for direct miner submission also introduces trust and censorship considerations. As the ecosystem debates long-term quantum resistance — including proposals for quantum-resistant address formats and commit-reveal schemes — this work establishes a proven, if imperfect, bridge capability.
Frequently Asked Questions
- Does this method require a Bitcoin soft fork or protocol upgrade?
- No. The construction operates entirely within Bitcoin’s existing consensus and script rules, meaning it can be used today without any network-level changes.
- Can this protect all Bitcoin holdings from a quantum attack?
- No. It only secures coins whose public keys have not yet been revealed on-chain — primarily Taproot and certain Script-based outputs. Coins in legacy P2PKH addresses or reused Taproot addresses with exposed public keys remain vulnerable.
- What is the real-world cost to use this quantum-resistant transaction method?
- StarkWare’s published breakdown estimates ~$320 in compute per transaction. Independent analysis by CoinDesk applying claimed optimizations suggests ~$83, while a contest site cites an unverified $66 figure. No subsequent mainnet transaction has confirmed the lower costs.


