StarkWare Tests Quantum-Safe Bitcoin Locking on Mainnet Without a Hard Fork, but It Is Not Ready for Mass Use

Updated Oct 9, 2026

StarkWare Tests Quantum-Safe Bitcoin Locking on Mainnet Without a Hard Fork, but It Is Not Ready for Mass Use

Quantum risk has moved from a distant theoretical concern to a practical design question for blockchain systems. While today’s quantum computers are not capable of breaking Bitcoin’s cryptography at scale, researchers, protocol teams, and custody providers are increasingly asking the same question: what should the migration path look like before the threat becomes urgent?

StarkWare’s latest research adds an important data point to that debate. Researchers associated with StarkWare have demonstrated a quantum-safe Bitcoin locking approach on Bitcoin mainnet that does not require a hard fork, a soft fork, new opcodes, or changes to Bitcoin consensus rules. The mechanism, referred to as Quantum-Safe Bitcoin, or QSB, was designed by StarkWare researcher Avihu Levy and has already been tested with a real mainnet spend.

The achievement is technically meaningful, but it should not be misunderstood. QSB is not a full post-quantum upgrade for Bitcoin. It is closer to an emergency research prototype: useful for exploring what can be done under today’s rules, but still expensive, operationally complex, and unsuitable for everyday users.

What StarkWare Demonstrated on Bitcoin Mainnet

The key milestone is that a QSB output was spent on Bitcoin mainnet in block 964,199 on August 26, 2026. According to Starknet’s explanation of the research, the approach uses hash-based computation to construct a locking mechanism that avoids depending on elliptic curve private keys at the point where quantum resistance matters most.

That distinction is important. Bitcoin’s current ownership model is primarily based on the Elliptic Curve Digital Signature Algorithm, commonly known as ECDSA, and increasingly Schnorr signatures for Taproot outputs. These schemes are secure against classical computers when used correctly, but sufficiently powerful quantum computers running Shor’s algorithm could, in principle, derive private keys from exposed public keys.

QSB takes a different path. Instead of asking Bitcoin to adopt a new post-quantum signature scheme immediately, it uses Bitcoin’s existing scripting and hash primitives to build a lock that is intended to be harder for quantum computers to break. Hash functions are generally considered more resilient against known quantum attacks than elliptic curve signatures, although Grover’s algorithm can still reduce the effective security margin. For background on Bitcoin’s scripting model, see the Bitcoin developer documentation on Bitcoin Script.

The result is a clever demonstration of what can be achieved within Bitcoin’s current rules. It also highlights why Bitcoin’s conservatism is both a strength and a challenge: the base layer is extremely hard to change, but that means experimental safety mechanisms must work around existing constraints.

Why “No Fork Required” Matters

In blockchain governance, “no fork required” is a powerful phrase. Hard forks and even soft forks require broad ecosystem coordination among developers, miners, node operators, businesses, wallets, and users. Bitcoin upgrades are especially slow by design because the network prioritizes stability, backward compatibility, and minimal trust in centralized decision-making.

QSB avoids that governance bottleneck. It does not ask Bitcoin nodes to accept new consensus logic. It does not introduce a new opcode. It does not require miners to upgrade software in order for the spending condition to be valid under consensus.

That makes the research valuable as a proof of possibility. It shows that certain forms of quantum-aware custody can be explored today, before the community reaches agreement on a long-term protocol upgrade.

However, there is a major difference between “valid under consensus” and “usable in production.”

The Practical Limits: Cost, Relay Policy, and User Experience

The most important takeaway for Bitcoin users is that QSB is not ready for broad adoption.

First, every transaction using this approach requires substantial computation. StarkWare’s research indicates that the GPU cost of the relevant computation has fallen significantly, from roughly $320 at the beginning of the experiment to around $50. That is meaningful progress, but still far too expensive and complex for normal payments, exchange withdrawals, or routine self-custody operations.

Second, QSB transactions do not fit Bitcoin Core’s default transaction relay policy. In Bitcoin, a transaction can be valid by consensus but still not be relayed by ordinary nodes if it falls outside standard policy rules. This means users would need to submit QSB transactions through miners willing to receive them directly. That introduces operational friction and reduces accessibility.

Third, there is no mature wallet infrastructure. A real consumer-grade quantum-safe Bitcoin workflow would need address formats, signing or proving tools, recovery procedures, fee estimation support, transaction monitoring, and clear user warnings. Without these components, the risk of user error may be higher than the theoretical cryptographic risk the scheme is trying to address.

Finally, moving existing BTC into a QSB-style lock still requires a conventional Bitcoin transaction. If the user’s public key is exposed during that migration, the transition itself may involve the very kind of quantum-sensitive signature mechanism the scheme is designed to avoid. This is one reason why QSB should be viewed as an emergency mechanism, not a complete migration plan.

Bitcoin Still Needs a Long-Term Post-Quantum Roadmap

The broader industry conversation is shifting toward post-quantum cryptography. The U.S. National Institute of Standards and Technology has already published standards for several post-quantum algorithms, marking a major step toward real-world deployment in traditional security systems. More information is available from NIST’s overview of post-quantum cryptography standardization.

For Bitcoin, however, adopting post-quantum signatures is not simply a matter of choosing an algorithm. The network would need to evaluate trade-offs including:

  • Signature size and transaction weight
  • Verification cost for full nodes
  • Compatibility with existing addresses and scripts
  • Migration paths for old coins
  • Risks around inactive or lost wallets
  • Miner incentives and mempool behavior
  • Long-term security assumptions

A soft fork that introduces post-quantum signature verification may eventually be the cleanest path, but it would require extensive review and consensus. Bitcoin’s history shows that even relatively narrow upgrades can take years of discussion, testing, and activation planning.

QSB is therefore best understood as a bridge concept. It demonstrates urgency and creativity, but it does not remove the need for a carefully designed Bitcoin post-quantum upgrade.

Why StarkWare Is Especially Interested in This Problem

StarkWare’s involvement is not accidental. The company has long focused on STARK-based proving systems, which rely heavily on hash functions rather than elliptic curve assumptions. This design makes STARKs an important part of the broader conversation around quantum-resistant blockchain infrastructure.

Starknet, the Layer 2 network built around STARK proofs, has stated that its underlying proof system was designed with hash-based security in mind and that it has a quantum migration roadmap. That does not mean Starknet is already fully independent from quantum risk. As an Ethereum Layer 2, its settlement and finality still depend on Ethereum’s base layer. If Ethereum’s core cryptography requires post-quantum migration, Layer 2 networks must account for that dependency.

This is where the strategic discussion becomes more interesting. At Token2049, StarkWare CEO Eli Ben-Sasson raised an open question: should Starknet eventually become a Layer 1 so that it can control its own post-quantum upgrade timeline rather than waiting for Ethereum’s roadmap?

That idea is not a formal decision. Still, it reflects a broader trend in the crypto industry: security assumptions are becoming a strategic issue, not just a technical one. Chains, rollups, bridges, wallets, and custodians all need to understand which cryptographic foundations they depend on and how quickly they can migrate if required.

For readers looking to understand the Layer 2 security model more generally, Ethereum’s documentation on rollups provides a useful starting point.

What This Means for Bitcoin Holders

For most Bitcoin holders, there is no immediate action required. The quantum threat remains a medium- to long-term concern, not a reason to panic. The more practical security risks today are still phishing, seed phrase leakage, malware, exchange compromise, poor backup practices, and signing malicious transactions.

That said, QSB is a reminder of several best practices:

  • Avoid unnecessary address reuse, because exposed public keys may matter more in a future quantum scenario.
  • Prefer modern wallet setups that give users clear transaction visibility and secure key management.
  • Keep long-term holdings in self-custody where recovery information is protected offline.
  • Follow credible protocol research rather than reacting to sensational claims about quantum computers.
  • Understand that “quantum-safe” is not a single feature, but an ecosystem-wide migration challenge.

Bitcoin’s security is not static. It has evolved through better wallet standards, improved scripting capabilities, SegWit, Taproot, and ongoing research. Post-quantum migration will likely follow the same pattern: slow, debated, tested, and eventually standardized only if the network reaches broad agreement.

The Bigger Picture for Crypto in 2025 and Beyond

Across the blockchain industry, 2025 has been defined by a more mature approach to infrastructure risk. Restaking, modular blockchains, zero-knowledge systems, account abstraction, and institutional custody have all pushed security engineering into the spotlight. Quantum resistance now sits alongside these themes as a long-horizon requirement.

The StarkWare experiment is important because it turns an abstract question into a concrete mainnet test. It shows that Bitcoin’s current design still has unexplored flexibility. At the same time, it confirms that real post-quantum readiness will require more than clever scripting. It will require standards, wallets, user education, miner coordination, and protocol-level agreement.

For self-custody users, the lesson is straightforward: cryptography matters, but operational security matters just as much. A future post-quantum Bitcoin upgrade will not help users who lose their seed phrase today or approve a malicious transaction tomorrow.

OneKey is built around that practical reality. As a hardware wallet focused on secure self-custody, offline private key protection, open-source transparency, and clear transaction verification, OneKey helps users reduce the everyday risks that remain most relevant right now. As the industry moves toward post-quantum planning, strong self-custody habits will remain the foundation for protecting digital assets through every cryptographic transition.

Secure Your Crypto Journey with OneKey

View details for Shop OneKeyShop OneKey

Shop OneKey

The world's most advanced hardware wallet.

View details for Download AppDownload App

Download App

Trade global assets. Start with your email in minutes.

View details for OneKey SifuOneKey Sifu

OneKey Sifu

Crypto Clarity—One Call Away.