StarkWare says it has completed the first Bitcoin transaction designed to resist a future quantum-computing attack during the period before a payment is confirmed, demonstrating a workaround that keeps certain public-key data out of view while the transaction waits in the mempool. The test moved 3.1 BTC, according to the company, but required direct delivery to a miner rather than Bitcoin’s ordinary peer-to-peer relay network.
The experiment offers a narrow, technically demanding form of protection rather than a ready-to-use upgrade for everyday Bitcoin payments. StarkWare said broad quantum-resistant security would require changes to Bitcoin’s protocol, since its transaction did not conform to formats that standard nodes will relay across the network.
MARA mined the transaction through its Slipstream service, StarkWare said. Slipstream allows miners to receive transactions directly, a route that bypasses some standard relay-policy limits and gives experimental transaction designs a path into a block.
A defense for the mempool waiting period
The method was developed by Avihu Levy, head of applications at StarkWare, and uses a process the company calls “signature grinding.” Rather than accepting the first mathematically valid signature for a transaction, the sender generates and checks many candidate signatures until one meets conditions intended to avoid revealing public-key material before confirmation.
That distinction concerns a specific risk scenario. Bitcoin transactions can remain in the mempool for minutes or longer before a miner adds them to a block. During that interval, signature-related information may be visible to anyone monitoring the network. A sufficiently capable quantum computer could, in theory, use that information to derive a private key, forge a competing transaction and attempt to redirect the funds before the original payment confirms.
Today’s computers cannot carry out that attack against Bitcoin’s widely used elliptic-curve cryptography. The concern is instead about how Bitcoin users could protect funds if cryptographically relevant quantum machines emerge before the network adopts new signature standards.
StarkWare’s approach attempts to reduce exposure during the unconfirmed phase, which is one of the most difficult windows to protect without modifying Bitcoin itself. Once a standard Bitcoin transaction has confirmed, its signature data is permanently recorded on-chain; the test does not rewrite Bitcoin’s historical cryptography or protect coins held in already exposed addresses.
High computational cost limits practical use
Signature grinding carries a substantial cost. StarkWare said its implementation may search through millions of candidate signatures and can require hours of computation to create one transaction. The company estimated that a transfer could consume roughly $75 to $150 in computing resources under the current setup.
That cost makes the technique poorly suited to routine payments, especially when ordinary Bitcoin transactions can be created almost instantly. Its immediate value lies more in testing whether a cryptographic defense can be executed against the live Bitcoin chain without waiting for a network-wide consensus change.
The transaction’s delivery method creates another limitation. Bitcoin’s standard node software relays transactions that comply with widely used policy rules. StarkWare said its quantum-resistant transaction was not propagated through that public relay path because it did not meet those normal formats. It instead reached a miner directly, with MARA including it through Slipstream.
Direct miner submission can work for specialized transactions, but it does not provide the open, widely available broadcast process Bitcoin users expect from a standard wallet. A broader solution would need protocol-level support so that wallet providers, nodes and miners could handle quantum-resistant transactions without customized arrangements.
Protocol changes remain the longer-term route
Levy and StarkWare chief executive officer Eli Ben-Sasson have argued that Bitcoin ultimately needs a protocol upgrade to support quantum-resistant signatures at scale. Such an upgrade could introduce cryptographic tools built to withstand quantum attacks, while giving users a defined migration route from older address types.
That process would involve difficult choices. Quantum-resistant signature schemes generally create larger transactions than Bitcoin’s existing signatures, potentially adding pressure to block space. Developers would also need to decide how to handle older coins whose public keys have already been revealed through past spending activity.
The issue extends beyond freshly broadcast payments. Analyst Batten has estimated that about 1.7 million BTC may remain in older address types or other arrangements with publicly exposed keys. If quantum hardware became capable of deriving private keys from those public keys, coins that have not moved for years could become targets.
Google researchers added urgency to the longer-term debate in a March paper that estimated breaking some modern cryptographic systems could require fewer than 500,000 physical qubits under certain assumptions. The research did not show that such a machine exists, nor did it establish an imminent threat to Bitcoin, but it reduced some earlier resource estimates for quantum attacks.
For Bitcoin holders, the StarkWare test does not create a reason to rush into expensive transaction methods. No publicly demonstrated quantum computer can break Bitcoin’s signature system, and the company’s technique remains cumbersome and dependent on direct miner access. It does show that protecting the mempool phase is technically possible today, while placing more pressure on the Bitcoin development community to define a practical migration path before quantum resistance becomes an emergency rather than a design question.
Concerned about BTC’s future security? Dive deeper into quantum-resilient blockchain scaling and strengthen your crypto knowledge.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
