Starknet on Oct. 9 outlined a quantum-safe Bitcoin proposal called QSB, saying StarkWare researchers have validated a locking mechanism on Bitcoin mainnet that does not require a soft fork, new opcodes, or changes to consensus rules.
Tested on Bitcoin mainnet
According to the post, the first QSB output was spent on Aug. 26, 2026, in Bitcoin block 964,199. StarkWare said the related GPU computation cost has dropped from roughly $320 at the outset to about $50.
The scheme was designed by StarkWare researcher Avihu Levy. Its core idea is to use hash-based computation to construct the locking mechanism, avoiding reliance on elliptic-curve private keys that could be broken by quantum computers.
Not ready for broad use
StarkWare said QSB does not mean Bitcoin has achieved full quantum resistance. The company listed several practical limits that still stand in the way of wider deployment.
- Each transaction requires heavy computation.
- Moving existing assets into the scheme still requires a traditional transaction, which carries quantum-related risk.
- QSB transactions do not fit Bitcoin Core’s default relay rules and must be submitted through miners willing to receive them directly.
- There are no supporting wallets, address formats, or recovery procedures at this stage.
StarkWare described QSB as an emergency research option, not a substitute for Bitcoin’s long-term post-quantum upgrade path. It said a lasting solution would still require a soft fork to introduce post-quantum signature mechanisms.
Starknet points to its own migration path
By contrast, Starknet said its underlying STARK proofs were built from the start around hash-based security assumptions, and that it has already set out a quantum migration roadmap.
Even so, Starknet added that as an Ethereum Layer 2 network, full quantum resistance still depends on upgrade progress at the Ethereum base layer.
Layer 1 question raised at Token2049
At Token2049, StarkWare CEO Eli Ben-Sasson also raised an open question: whether Starknet should become a Layer 1 so it could push ahead with post-quantum upgrades on its own schedule rather than wait entirely for Ethereum’s timeline.
That idea has not become a formal decision, according to the post.

