Bitcoin has quantum computer protection. It costs $200 – Bitcoin.pl

On Wednesday evening, a transaction that StarkWare calls the first quantum computer-resistant transaction entered block 964,199. The equivalent of thirty zlotys was spent on it, and the preparation cost several hundred dollars and hours of graphics card work.

Key takeaways:

  • StarkWare claims this is the first-ever Bitcoin transaction resistant to a quantum computer. It entered the network without changing the consensus rules.
  • Normal nodes do not forward such a transaction, so it must be returned to the miner directly. This transfer was accepted and mined by MARA Pool.
  • The method does not include Taproot addresses, Lightning channels, or wallets whose public key has already been visible on the chain.


On Wednesday evening, Avihu Levy spent 10,000 satoshi, or approximately thirty zlotys. The transfer entered block 964 199 and from the outside it looks ordinary. What is unusual is the signature that authorized it. It was created so as not to reveal anything that a quantum computer could use.

What happened in block 964 199

Levy heads the applications department at StarkWare and since April has been developing a method he calls Quantum Safe Bitcoin. The standard signature in Bitcoin is based on elliptic curves, which is mathematics that a quantum machine can decompose. Levy’s signature is constructed from a hash function, i.e. from a conversion that cannot be reversed. This included signature grinding, i.e. searching by brute force for a variant that does not reveal the public key.

StarkWare claims that this is the first such transaction in the history of the network. The block was mined by MARA Pool after the transfer was accepted by the Slipstream service.

StarkWare spokesman Nathan Jeffay told Cointelegraph that the total cost was “low hundreds of dollars,” or between $150 and $200. Levy estimated in April $75 to $150 for the calculations alone.

Thirty zlotys sent for two hundred dollars. This is how much it costs today to prove that Bitcoin’s rules already allow for a quantum-resistant signature.

Where does quantum risk come from?

Your coins are not lying exposed in your wallet. So when does your public key become visible? Only when you send a transfer. It is from this that a quantum machine could recreate the private key.

And here is the loophole. Google researchers estimated in March that such a machine would extract the private key nine to 12 minutes after seeing the key. This is approximately as much as the network needs for one block, and the transfer usually takes longer to be confirmed.

Therefore, it is not your wallet that is at risk, but only those several minutes when the transfer is waiting in the queue with the key exposed.

Why the network did not want to accept this transaction

Levy’s repository notes that QSB transactions are custom to Bitcoin Core’s default settings. Regular nodes do not forward them, so such a transfer would not enter the public queue. It had to be handed over to the miner from hand to hand.

There are also hours of counting. You’ll pay a few hundred dollars and wait half a day for one transfer to be sent.

Security that enters the network through a side entrance and requires a farm of graphics cards is not a tool for anyone except the author today.

What this protection does not cover

The method guards individual transfers from older types of addresses. Does this mean your coins are now safe? Not if you keep them on a Taproot address or Lightning channel. It will also not help where the public key has already been visible in the chain.

Analyst Daniel Batten called the way StarkWare’s CEO presented his achievement an exaggeration. Dormant wallets and keys already exposed are not touched upon in this work. The accusation hits the nail on the head. The oldest coins, including those from the Satoshi era, have had their public keys exposed on the chain for a dozen years.

StarkWare CEO Eli Ben-Sasson believes that a soft fork is the permanent solution. Developers are considering proposal BIP-360, which would remove the quantum-sensitive release mode from Taproot.

The oldest bitcoins are beyond the reach of this method and are the first in the queue.

What does this mean for you

Today you don’t have to do anything. No existing quantum machine comes close to Google’s estimated power, and Levy’s method is beyond the reach of the average user anyway.

One thing is free though. Don’t reuse an address you’ve already sent coins from. After the first spend, the public key of that address stays on the chain forever. Anything that comes back on it will now lie with its zipper exposed. A good solution are wallets that generate a new address with each deposit.

The rest depends on the change in protocol. When the network finally gets a quantum-resistant address type, the transfer of coins will be yours anyway. No one will transfer your bitcoins for you.

The ten thousand satoshis in block 964 199 protect a signature that no known machine can forge. All remaining bitcoins in circulation are protected by the same signature as yesterday.