Invest1 distinct publisher3 min readPublished
The construction runs inside today's Script limits, so no soft fork was needed. The cost of quantum defence moves instead onto the individual holder, at $75 to $150 per transaction.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Fitting inside 201 non-push opcodes and 10,000 bytes of legacy Script [6] is the load-bearing engineering choice here, because it routes around the slowest component of Bitcoin, which is agreement. The price of the detour is that expenses a soft fork would have spread across the network instead land on the individual spender, as $75 to $150 of off-chain computation per transaction on Crypto Briefing's estimate [7].
Set that against balance size. At the top of the quoted range, a single transaction costs 1.5 percent of a $10,000 position and 0.0015 percent of a $10 million one [1]. The same dollar figure is either a wealth tax or a rounding error depending on whose coins are moving, which is why the source calls it impractical for small amounts [8] and tolerable for seven- and eight-figure wallets [14]. The range itself spans a factor of two [2], which is what a cost estimate looks like before anyone has run the thing at volume.
The confirmation path deserves more attention than the cryptography. QSB transactions are nonstandard and will not be relayed by ordinary nodes in the usual way [9], so this one reached a miner through MARA Slipstream, a service built to carry nonstandard transactions past mempool relay constraints [10]. The signature scheme no longer leans on secp256k1 [3][4], but the spend does lean on a commercial route to hashpower. A holder buying quantum insurance is therefore buying two things at once, and only one of them is mathematics.
On the mathematics, the claim is a number rather than a guarantee of longevity: roughly 118-bit second pre-image resistance [5], built on Lamport-style hash-based signatures over RIPEMD-160 [4]. That replaces a weakness with a known shape, Shor's algorithm against elliptic curves [3], with a margin that has to hold for as long as the coins sit still.
StarkWare is running both tracks, and says so. Its June 2026 post-quantum roadmap for Starknet included collaborative work on BIP 360, a proposal for quantum-resistant address formats [13], which is the consensus route QSB was designed to avoid needing. Chief executive Eli Ben-Sasson described QSB itself as a "passion project" showing holders can protect assets now, at a cost, without waiting for protocol changes [11]. That is not the language of a product line, and the two-track behaviour reads as a company treating the no-fork path as cover for people who cannot wait rather than a substitute for the fork. The useful detail is that Avihu Levy, StarkWare's general manager of applications, published the concept with an open-source implementation in April 2026, with a colleague contributing and Robin Linus's Binohash work informing the design [2][12]. Cutting the overhead and making these transactions relay-compatible is now an engineering agenda anyone can pick up [15], which is the difference between a roadmap and a single transaction ID.
Ranked by verification strength, evidence, and original report placement.
On August 26, 2026, StarkWare mined the first quantum-safe Bitcoin transaction on mainnet using the Quantum Safe Bitcoin (QSB) construction; the transaction ID 305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07 is on the Bitcoin blockchain.
The QSB construction was developed by Avihu Levy, StarkWare's General Manager of Applications.
Bitcoin's security currently relies on elliptic-curve cryptography using the secp256k1 curve; a sufficiently powerful quantum computer running Shor's algorithm could theoretically derive a private key from an exposed public key.
QSB replaces elliptic-curve signatures with hash-based cryptography, specifically Lamport-style hash-based signatures that rely on RIPEMD-160 for pre-image resistance.
The construction achieves approximately 118-bit second pre-image resistance.
The implementation fits within Bitcoin's existing legacy Script limits of 201 non-push opcodes and 10,000 bytes, requiring no consensus rule changes and no soft fork.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One checkable artifact, one publisher
The central claim is unusually falsifiable for a single-source story: a named mainnet transaction ID, specific Script limits, and a named security parameter. But every detail comes from one trade publication relaying a vendor announcement, with no independent cryptographic review, no primary StarkWare or BIP 360 document in the cluster, and no third party confirming the cost estimate.
One transaction, one bespoke path
Observed usage is exactly one mainnet spend, executed by the vendor itself, requiring a non-relayable transaction to be handed to miners through a single service. No external user, wallet, exchange, or custodian is reported as using QSB, and the $75-$150 per-spend cost explicitly excludes ordinary transfers.
Milestone real, availability overstated
The milestone framing is fair - the transaction exists and needed no soft fork - and the article is candid about cost and nonstandard relay. The overstatement sits in the inference that a holder can simply move funds into this today and in the projected flow of investment attention, neither of which has tooling, a second user, or any funding datapoint behind it. StarkWare's own CEO calls it a passion project, which the framing of a self-serve quantum hedge runs ahead of.
Vendor-originated milestone claim
The story is a first-mover announcement by a company with a commercial post-quantum roadmap (Starknet, BIP 360 work) and executive quotes carried directly; the publisher adds an investment-attention thesis rather than adversarial scrutiny. Disclosure of cost and relay limits partially offsets, but the promotional incentive to own the phrase 'first quantum-safe Bitcoin transaction' is plain.
Coherent but unreplicated
Internally consistent, technically specific, and dated, with an on-chain artifact anyone could check. Confidence is nonetheless capped by a one-publisher, one-source cluster with no independent verification of the security parameter, cost range, or the 'first' designation, and by month-only dating on the April and June events.
invest
IBM buys HRL, lines up $2B of proposed federal money, and puts 2029 on the retention schedule1 distinct publisher
invest
Crypto's signature swap now has a date, a price tag, and no owner1 distinct publisher
invest
Bitcoin's first post-quantum signature BIP arrives with its tradeoffs already conceded1 distinct publisher
product
Red Hat counted 572 quantum-vulnerable spots in OpenStack. The obstacle is OpenStack's own pins.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
cryptobriefing.com
1 article · August 26, 2026