Product1 distinct publisher3 min readPublished
Gizmodo reports that a StarkWare researcher's transaction needed no soft fork. That fact moves post-quantum migration out of the developer debate and into the custody workflow, where somebody has to schedule it and pay for it.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A custody operations lead who gets a written client question about quantum exposure has had one honest answer available: point at a developer mailing list and describe an argument in progress. The StarkWare demonstration changes the shape of that answer, because according to Gizmodo the technique asked nothing of the network's consensus rules [1], and Gizmodo frames it as an escape hatch a holder can build now rather than a repair to the network [2].
Opt-in is the mechanism here, and opt-in is also the limit on what it covers. A quantum-resistant spending arrangement covers the coins whose holder signs to move them, while the risk Glassnode measured is a pile of already-exposed public keys sitting still [4]. Bitcoin's ownership proofs run on elliptic-curve signatures, and an exposed public key is the input Shor's algorithm would work on [3]. Roughly 69.8% of issued supply was not in that condition when Glassnode looked [3], so the queue is scoped to a minority of supply, which is the one encouraging number in the set.
The institutional money is sized for research rather than for migration. The July consortium's $15 million over three years works out to about $5 million a year [8][1], set against the roughly $483 billion of exposed coins Gizmodo values at an $80,000 bitcoin price [4], or about 0.001% of that exposed value annually [2]. Coinbase has separately stood up an independent advisory board on quantum computing and blockchain security [9], and Corallo said in February that Blockstream Research and Chaincode have each put resources into what a post-quantum change should look like [12]. None of that funds anyone's signing ceremonies.
Nobody has set a date for when migration has to happen, and the people best placed to set one disagree with each other. The emerging developer view, per Gizmodo, is to have a migration mechanism ready before Q-day rather than rush an emergency change through now [13]. Strategy's Michael Saylor and others have put a serious threat more than a decade out, while Coinbase's research argues preparation has to begin well before the machines can break signatures [10]. Ray Dalio keeps listing quantum computing among bitcoin's technology risks [11].
The sort that helps on Monday has two axes: whether the public key is already exposed on chain, and whether anyone can still sign for the coins. Exposed and signable is the queue, and it is the only box a custodian can shrink without permission from anybody. Exposed and unsignable is the hostage population, with Satoshi Nakamoto's early coins the famous case [7], and it is what the fork argument is actually about, since Corallo's stated aim is to reduce the vulnerable pile enough to "minimize the chance that the Bitcoin community feels the need to fork to burn coins" [5] and he has also sketched a soft fork that would disable vulnerable spending paths, with no settled answer for coins left behind [6]. Unexposed and signable is hygiene, and it can wait behind the first box. The figure worth tracking internally is the share of coins under your control sitting in that first box, because a client will ask for it this year and a fork proposal will assume it later.
Ranked by verification strength, evidence, and original report placement.
A StarkWare researcher sent the first Bitcoin transaction designed to resist attacks from a sufficiently powerful quantum computer, and the experimental transaction landed on Bitcoin's mainnet without requiring a soft fork or any change to the network's consensus rules.
Gizmodo describes the transaction as not a full fix for Bitcoin's potential quantum problem, and better understood as a demonstration that users can create a quantum-resistant escape hatch today while developers continue debating a permanent protocol-level solution.
Bitcoin uses elliptic-curve cryptography for the signatures that prove ownership of coins, and a cryptographically-relevant quantum computer running Shor's algorithm could theoretically derive a private key from an exposed public key.
Glassnode estimated in May that roughly 6.04 million BTC, or 30.2% of the issued supply, had public keys exposed on-chain, which at a bitcoin price of $80,000 is roughly $483 billion of potentially vulnerable coins.
Matt Corallo, one of the earliest Bitcoin developers, has argued that the immediate objective is increasing the number of coins secured before a cryptographically relevant quantum computer exists, writing that the community should "minimize the chance that the Bitcoin community feels the need to fork to burn coins".
Corallo has described a future in which a soft fork could disable vulnerable spending paths once the threat becomes sufficiently serious, and the mechanism remains controversial, particularly over whether coins whose owners fail to migrate should be frozen forever or left for an entity with a quantum computer to take.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Crypto's signature swap now has a date, a price tag, and no owner1 distinct publisher
invest
Metaplanet buys a Nasdaq listing with 2,100 of its own bitcoin, and writes a template4 distinct publishers
invest
Strategy sold $333.7M of stock to pay its preferred holders, not to buy bitcoin1 distinct publisher
invest
Strategy sells 6,948 bitcoin at about $62,000 each to keep its preferred dividends paid1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom, four borrowed artifacts
Everything traceable in this story passes through Gizmodo: the mined transaction, Levy's April paper, Glassnode's May exposure figure, Corallo's dated post. The mechanism claim is specific enough to be checkable and the numbers are attributed, which is why this is not lower — but the central event has no transaction ID, no block height, and no second party confirming it, and the 'emerging view' among developers is the writer's summary rather than anything countable.
One spend, nobody downstream
Count what has actually happened: a single experimental transaction, plus $15 million of research money spread over three years, plus an advisory board. Not one wallet, exchange or custodian in this reporting has said it will support the scheme, and its author calls it a last resort priced at hundreds of dollars of GPU time per use. That is a proof of possibility, not uptake — and against 6.04 million exposed BTC it moves nothing yet.
'First' does more work than the tool does
Gizmodo is honest in the body — it says outright this is no fix, prints the GPU cost, and flags that moving coins can expose the very key you are fleeing. The stretch is in the framing around it: a one-off last-resort spend carries a headline of firstness and sits beside a $483 billion exposure number, which invites readers to hear a solution where the reporting describes an option. Modest overstatement, mostly structural rather than asserted.
Every voice here holds a position
Read the roster: the scheme's builder works for the company promoting it; Saylor's decade-plus reassurance protects the largest corporate bitcoin balance sheet described in this story; Coinbase's prepare-now research runs alongside the advisory board it convened and the consortium it helped fund; Corallo, defending Blockstream Research and Chaincode, dismisses outside warnings as FUD while Blockstream sits among the consortium's founders. None of that makes anyone wrong, but nobody quoted is disinterested about the timeline, and Gizmodo does not note the overlaps.
Believable, unconfirmed
The technical story hangs together — hash-based signing inside existing rules is a known idea, and the reported limitations are the ones you would expect — so we hold it as plausible. But a single outlet, an unidentified transaction, month-only dates on the funding and exposure figures, and a consensus claim resting on the writer's own read leave too little to stand on firmly. Corroboration or an on-chain identifier would move this quickly.