CatBitcoin

Quantum-safe Bitcoin without a fork: what QSB locks, and which boxes it cannot save

Updated September 2026

A small wooden box bound with an iron chain and a brass padlock on a dark workbench, with a row of computer graphics cards standing behind it under a warm desk lamp.
QSB backs a spend with a hash-based signature a quantum computer cannot forge, paid for with a brute-force search on graphics cards. It helps coins whose key is still hidden.

Most quantum plans for Bitcoin need a soft fork, and a soft fork can take years to agree on. QSB is the exception: a transaction built so that even a machine able to break elliptic curve keys could not redirect it, with no change to the rules. On September 23, 2026, StarkWare reported that a week of open competition had cut the estimated cost of making one by 79%. Here is what QSB does, what it really costs, and why, once a quantum computer exists, it only helps coins whose box is still closed.

What is a quantum-safe Bitcoin transaction?

QSB comes from a paper by StarkWare's Avihu Levy, "Quantum-Safe Bitcoin Transactions Without Softforks", dated April 9, 2026. StarkWare says Levy built it after hours, as a side project. Despite the company's name, it uses no STARK proofs. It adapts Binohash, a February 2026 design by BitVM creator Robin Linus, posted to Delving Bitcoin, for reading transaction data inside Bitcoin Script.

The problem it answers is the one this site calls the short exposure attack. When you spend, your wallet publishes your public key and a signature, and the transaction waits in the mempool until a miner picks it up. A quantum computer that could recover the private key in that window could sign a competing transaction that sends the same coins elsewhere. That race is laid out on long exposure vs short exposure.

QSB makes that forgery worthless. The coins are bound to the transaction by a one-time signature built only from hashes, the kind of signature Shor's algorithm does not help with. An ordinary elliptic curve signature still appears in the process, but the project's README describes it as a vehicle for the puzzle, not something the spend's security depends on.

How does a hash stand in for a signature?

Bitcoin Script cannot read a transaction directly. Binohash and QSB get a fingerprint of it by a side door. The locking script contains a fixed signature. When the coins are spent, the spender works out, off the chain, the public key that would make that signature valid for this exact transaction and supplies it, and the script checks that it fits. That key is unique to the transaction. The script then hashes it and requires the result to happen to parse as a correctly formatted signature.

Almost no hash outputs do. StarkWare puts the odds at about one in 70 trillion for the paper's main design, which uses RIPEMD-160. The lock script of the one mined example uses SHA-256 instead, which the paper puts at roughly twice those odds. The only way to find a transaction that passes is to try variations, changing free fields such as the sequence and lock time numbers, trillions of times over. That search, the first of two done on graphics cards, is called pinning: once a transaction passes, changing anything in it breaks the puzzle.

A second stage, run twice, builds the fingerprint that gets signed. The script holds two pools of 150 dummy signatures, one per round, and an old quirk of legacy multisig checking means each choice of a subset from a pool changes the signature hash of the same transaction. In each round the spender searches for a subset that passes the puzzle again, and the positions of the chosen signatures become a digest of the transaction. The spender then signs that digest with HORS, a Lamport-style one-time signature, by revealing hash preimages that only they know.

Binohash alone was not enough. It used the size of a signature as its proof of work, and the paper explains that a quantum computer could build signatures around an unusually small value, making them short without any grinding. QSB replaced that step with the hash puzzle above, which Shor's algorithm cannot shortcut.

What did the first QSB transaction look like?

The lock went on chain first. A transaction mined in block 958,306 on July 16, 2026 sent 10,000 sats to an output whose locking script is 9,923 bytes long, paying a 30,000 sat fee for the whole 10,125-byte transaction. That output is the QSB box.

The spend came six weeks later. Transaction 305a24ff was mined in block 964,199 on August 26, 2026. It is 1,403 bytes and paid 5,179 sats in fees. It combined the 10,000 sats in the QSB box with an ordinary 39,179 sat input from a bc1q address that had already spent, and sent 44,000 sats to an ordinary bc1q address. StarkWare's announcement put the cost at several hundred dollars, and its challenge post three weeks later said building it took roughly 3,100 GPU-hours on a fleet of about 100 graphics cards, about $320. StarkWare engineer Tomer Giladi carried the work to mainnet.

Three details explain why it looks so unusual:

What changed in September 2026?

On September 16, StarkWare, Yukon Research and Eigen Labs announced the Quantum-Safe Bitcoin Optimization Challenge, with $20,000 in prizes from StarkWare and a further prize from Yukon. It had two tracks, one for the pinning search and one for the subset search, scored by how many candidates a submitted graphics-card program checks per second.

A week later StarkWare reported interim numbers. On the benchmark RTX 4090, pinning had gone from 146.09 million candidates per second at the baseline to just over 820 million, and subset selection from about 62 million to 623,518,629. There had been 62 promoted submissions, and StarkWare said the leading entries came from developers working with AI coding models. The challenge dashboard, which applies its own measurements and hardware assumptions to the first transaction's cost, put the estimate at about $67, the figure StarkWare reported.

The numbers kept moving. On September 28, 2026, the challenge dashboard showed an estimated $61 for a simulated fleet of 100 RTX 3090 cards. The single-card records on the benchmark RTX 4090 stood at 1,008,206,828 candidates per second for pinning, about 6.9 times the baseline, and 708,411,009 for subset selection, about 11.4 times. The dashboard's page data lists both tracks as closing on October 7; the organizers' posts give no end date.

Read those figures with the caveats their publishers attach. StarkWare stresses that the figure rests on assumed hardware and should not be read as a price. The benchmark builds no real transactions, so the speedups still have to be measured in the working tool. CoinDesk noted on September 24 that the faster code had not been shown preparing another mined transaction, and that applying the speedups shown on the contest site to its cost breakdown gave about $83 by CoinDesk's own arithmetic. As of September 28, only one QSB spend is publicly known.

Which boxes can QSB protect?

Once a quantum computer exists, only closed ones. StarkWare states the limit plainly in all three of its posts: QSB does not help coins whose public key has already been exposed.

Think of what the attacker needs. Against a closed box, a 1, 3 or bc1q address that has never spent, the attacker sees only a hash and has nothing to feed Shor's algorithm until you spend. If those coins sit in a QSB lock, the later spend out of the lock is bound by a hash-based signature, and the mempool race has nothing to win.

Against an open box, the attacker does not wait for you. The key is already on the chain because the address spent before, was reused, holds an old P2PK output or is a Taproot bc1p address. An attacker with a working machine could derive the private key and move the coins first. No transaction you build afterwards, QSB included, can take that back.

Before that machine exists, the picture is different. Getting coins into a QSB lock is itself an ordinary signed spend from your current address, and it reveals your public key like any other spend. Because the new output is nonstandard, that transaction also has to go straight to a miner. Today the revealed key is harmless, because no machine can use it, so coins in an open box can still be moved, into a QSB lock or simply to a fresh address that has never spent. That is why QSB is a tool to set up before the threat arrives. StarkWare pitches it as an emergency option for holders whose balance is still unexposed. A move made after a capable machine exists would depend on that direct path to a miner, and the paper notes that even a privately mined spend could be at risk if other miners were tempted to rewrite the block.

Taproot cannot host the lock at all, because the trick relies on ECDSA and legacy quirks that Taproot left behind. The paper adds that Taproot would not help anyway: every Taproot output can also be spent through its key path, so an attacker able to compute that key could spend it whatever scripts sit in its tree. That is the same reason Taproot opens the box on arrival.

QSB is a stronger lock for coins whose box is still closed when the threat arrives. It cannot close a box that is already open.

A QSB box is also a different kind of box. Its entire 9,923-byte script is visible from the moment it is funded. What it shows are mostly hash commitments, whose preimages stay secret until the spend, plus fixed signatures that are public by design. A quantum computer could break those signatures, but the paper finds that gains an attacker nothing, because the lock's security rests on the hashes.

How strong is it against a quantum computer?

Strong against Shor's algorithm, thinner against Grover's. Shor breaks elliptic curve keys, and QSB's security does not rest on one. Grover's algorithm speeds up brute-force search against hashes, roughly halving the bits of preimage resistance.

The paper's recommended configuration gives about 118 bits of second-preimage resistance and about 78 bits of collision resistance, and says the first falls to roughly half under Grover. The project's README and StarkWare put that at about 59 bits. Those figures assume RIPEMD-160 as the puzzle hash. The mined transaction's script uses SHA-256, a variant the paper's own table puts at about 115 bits of preimage resistance. The paper argues the practical picture is better than the halving suggests, because Grover's search spreads poorly across many machines and would need large reversible circuits for the hashing and key recovery involved.

The paper also notes that a 160-bit hash keeps about 80 bits of preimage resistance against a quantum attacker. For comparison, 160 bits is the size of the hash behind 1 and 3 addresses and single-key bc1q addresses, the hash that keeps a closed box closed today.

Why is it a last resort and not the fix?

The paper itself calls QSB a last-resort measure and gives the reasons: neither the grinding bill nor the on-chain cost of such large transactions scales to every user and every transaction, the transactions are nonstandard, building them is more complex than a normal spend, and it does not yet cover Lightning channels. Each spend needs its own grinding run.

One practical point works in its favor. The graphics-card search uses only public data, the locking script and an unsigned transaction template, so it can be handed to rented hardware without trusting it. The one-time signature secrets stay on the spender's own device.

StarkWare is clear about where it stands. "This effort does not make Bitcoin quantum-safe," its September 23 post says, and the company still prefers a soft fork as the long-term answer. That road runs through proposals such as BIP-360, whose new output type protects against long exposure attacks, and through the argument over what the first post-quantum output type should look like, covered in P2TRv2 vs P2MR. QSB covers the mempool race that BIP-360 alone does not, but at a cost measured in GPU-hours per spend.

What should you do now?

Quick answers

What is a quantum-safe Bitcoin (QSB) transaction?
QSB is a way of locking and spending bitcoin, designed by StarkWare's Avihu Levy and published in April 2026, that stays safe even if an attacker can forge elliptic curve signatures. The locking script checks a hash-based one-time signature over a fingerprint of the transaction, and it works under Bitcoin's current consensus rules. The first QSB spend was mined on August 26, 2026.
How much does a QSB transaction cost?
On-chain fees are higher than for a normal spend, because the scripts are large: the transaction that created the first lock paid 30,000 sats and the spend paid 5,179 sats. The bigger cost is computing power, because the spender has to brute-force hash puzzles on graphics cards. The first transaction took roughly 3,100 GPU-hours and about $320. After a week of an open optimization contest, StarkWare reported an estimate of about $67 on September 23, 2026, and the contest dashboard showed $61 on September 28. Those are estimates, not prices, and no cheaper QSB transaction has been shown on the chain yet.
Can QSB protect coins in a Taproot or reused address?
Not once a quantum computer exists. At that point QSB can only help coins that already sit in a QSB lock or whose public key is still hidden. If the key is already on the chain, because the address spent before, was reused, is a Taproot bc1p address or an old P2PK output, the attacker could derive the private key and move the coins before any QSB transaction happens. Today, while no such machine exists, coins in an open box can still be moved with an ordinary spend, to a fresh address or into a QSB lock.
Does QSB mean Bitcoin no longer needs a quantum soft fork?
No. QSB is expensive per transaction, nonstandard, hard to use and does not cover Lightning, and its own paper calls it a last-resort measure. StarkWare still prefers a soft fork for broad, lasting protection, and presents QSB as the option available under current rules while proposals such as BIP-360 are debated.
Should I move my bitcoin into a QSB lock now?
No. No quantum computer can break Bitcoin's keys today, QSB transactions have to be built with experimental tools and sent straight to a miner, and a mistake could lose the coins. The useful step now is the ordinary one: keep coins in addresses that have never spent, so that every future option, QSB included, stays open to you.