The estimated cost of building a quantum-resistant Bitcoin transaction has fallen from about $320 to roughly $67 in GPU compute in a single week, after developers and AI models competed to optimize the code behind it.
StarkWare, which ran the effort with Yukon Research and Eigen Labs, said the figure comes from the dashboard of the Quantum-Safe Bitcoin Optimization Challenge, an open contest designed to test how far outside solvers could push the number down.
First mainnet transaction arrived last month
The first quantum-safe Bitcoin transaction was mined on mainnet last month. StarkWare developed the construction as a way to protect coins without requiring a network-wide fork.
That first transaction took roughly 3,100 GPU-hours and cost around $320 to build. After one week of open competition, most of that cost had been cut away.
Why the cost moved lower
The savings came from speed. The most expensive part of the process is a brute-force search that runs on a user’s own hardware before anything reaches the blockchain, which is why the expense shows up as a GPU compute bill rather than a Bitcoin fee.
The construction places a hash where Bitcoin expects a signature. Only about one in 70 trillion hash outputs has the required shape, so finding a valid result means hashing inputs again and again until one fits. Faster code reduces the GPU-hours needed to reach the same outcome.
AI-assisted developers led the benchmark table
Participants posted large gains during the contest. One core benchmark climbed from 146 million verified candidates per second to more than 820 million per second on a standard RTX 4090. Across two tracks, 62 improvements were promoted.
StarkWare said the leading records were held by developers running AI models. Anthropic’s Opus 5 and Fable 5.1 were at the top, while OpenAI’s GPT-6 Astra, Grok 4.6, and Kimi were close behind.
$67 is an estimate, not a market quote
StarkWare cautioned against reading too much into the headline number. The $67 figure is an estimate based on stated hardware assumptions, not a market price, and it changes whenever a solver sets a new record.
The approach still has limits
The company said the work does not make Bitcoin quantum-safe on its own. These transactions are nonstandard and must be sent directly to a miner. The construction also only protects coins whose public key has not already been exposed.
StarkWare maintains that a soft fork remains the better long-term fix.
Q-Day concerns remain in focus
The work comes as attention grows around Bitcoin’s exposure to “Q-Day,” the hypothetical moment when quantum computers could break the elliptic-curve cryptography that secures wallets. According to the report, firms including Coinbase are already drafting post-quantum custody playbooks.

