StarkWare Researcher Proposes Quantum-Safe Bitcoin Without a Soft Fork
Bitcoin transactions rely on elliptic-curve digital signatures. A sufficiently powerful quantum computer running Shor’s algorithm could derive private keys from exposed public keys and steal assets. Replacing the signature mechanism would require network-wide consensus and asset migration, drawing attention to StarkWare’s upgrade-free approach as a fallback until longer-term changes such as BIP-360 are completed.
On April 9, 2026, StarkWare Chief Product Officer and BIP-360 co-author Avihu Levy published the QSB paper and open-source code. The system uses Bitcoin’s existing Script constraints and hash-based proofs to create quantum-resistant transactions without a soft fork or miner activation. Each transaction requires substantial offline GPU computation at an estimated cost of $75–$200, and the tool is currently intended for emergency recovery.
All Coverage
4 original reportsThe Backstory
The history behind this eventBitcoin Faces Quantum-Security Choice: Bigger Blocks or STARK Proofs
Bitcoin’s current Elliptic Curve Digital Signature Algorithm, or ECDSA, could eventually be vulnerable to quantum computers, requiring the adoption of post-quantum signatures approved by the U.S. National Institute of Standards and Technology. But the new signatures are 10 to 100 times larger than those now in use. Adding them directly would cause blockchain data to surge, undermine decentralization and sharply reduce transaction speeds, leaving the Bitcoin network with a difficult trade-off between quantum security and operational efficiency.
In July 2026, a StarkWare co-founder said a better approach would be to use ZK-STARKs to aggregate multiple post-quantum signatures into a single proof instead of expanding block capacity from the current 4MB to 32–64 MiB. That same month, StarkWare also unveiled a three-stage upgrade plan for Starknet and began studying a fork-free solution with estimated computational costs of $75–$150 per transaction to protect against quantum-security threats.
StarkWare Unveils Starknet Quantum-Resistance Roadmap, Urges Industry to Act
Quantum computers could eventually use Shor’s algorithm to break the elliptic-curve cryptography used by most blockchains, threatening wallet private keys and transaction verification. The proof layer of Ethereum Layer 2 network Starknet uses hash-based STARKs, giving it a foundation for quantum resistance. Legacy contracts and components connecting Starknet to Ethereum still require upgrades, however, making the work critical to the long-term security of assets.
On June 30, 2026, StarkWare unveiled a three-phase roadmap. Phase one will replace Pedersen with BLAKE2, with the operating system configuration hash expected to reach mainnet in early July and the remaining work taking about two months. Phase two will take roughly another month to provide migration tools for legacy contracts. Phase three will address bridging and data availability, with its timetable depending on Ethereum.
Coinbase Warns 7 Million Bitcoin Are Exposed to Quantum Attack Risk
Bitcoin transactions use elliptic-curve digital signatures to protect assets. Once an address reveals its public key, a sufficiently powerful quantum computer could eventually derive the private key and steal the funds. The threat is not exploitable today, but the permanent public record of blockchain data means exchanges and long-term holders must plan ahead to migrate to quantum-secure addresses.
Coinbase’s independent advisory board on quantum computing and blockchain released a report on June 11, 2026, estimating that the public keys for about 7 million BTC have been exposed. About 1.7 million BTC are held in early P2PK addresses, while roughly 5 million BTC are exposed through address reuse and largely consist of active funds such as exchange cold wallets. Attackers can collect the data now and attempt to crack it later.
Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security
Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.
Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.
AmericanFortress Unveils Quantum Defense Plan for Satoshi-Era Bitcoin Holdings
Major blockchains including Bitcoin use elliptic-curve cryptography to secure transactions. If a large-scale quantum computer could run Shor's algorithm, it might derive private keys for older wallets whose public keys have been exposed on-chain. Unlike newer wallets, Pre-BIP32 addresses from the Satoshi era cannot be upgraded automatically. That has put about 1.1 million BTC in the spotlight, with their security also affecting market confidence.
AmericanFortress unveiled a post-quantum signature proposal on May 21, 2026. It plans to use a backward-compatible soft fork to freeze older assets before verifying ownership with zero-knowledge proofs. The company said the approach could protect Satoshi Nakamoto's roughly 1.1 million BTC and nearly 5 million dormant BTC. It also completed an $8 million seed round on May 5, co-led by institutions including SAVA Digital Asset Fund.
Bitcoin’s BIP-360 Proposal Formally Sets Out Quantum-Resistance Roadmap
Bitcoin, with a market capitalization of about $1.3 trillion, relies on elliptic-curve cryptography to secure transactions. If large-scale quantum computers become viable, exposed public keys could potentially be used to derive private keys. Bitcoin developers have therefore proposed BIP-360, adding a quantum-resistant migration to the network’s long-term technical roadmap to reduce the potential risk to existing assets.
Proposed in 2025, BIP-360 introduces Pay-to-Merkle-Root (P2MR), which removes Taproot’s public-key spending path and instead locks scripts with a Merkle root, allowing keys to remain hidden until funds are spent. The proposal remains a draft, with no mainnet activation date, and does not yet introduce a complete post-quantum signature scheme. It nevertheless establishes a foundation for future upgrades.
New Bitcoin PACTs Proposal Seeks to Counter Quantum Computing Threat
If quantum computers were to break Bitcoin's ECDSA signatures, funds held at older addresses whose public keys have been exposed could be stolen. These include addresses attributed to Satoshi Nakamoto, who is estimated to hold about 1.1 million BTC. The dispute centers on whether the community should preemptively freeze vulnerable legacy coins: doing so could prevent theft but might also permanently deprive their original owners of access.
Paradigm partner Dan Robinson unveiled PACTs on May 1, 2026. The proposal would let holders use BIP-322 signatures and OpenTimestamps to create private, timestamped proof of control without moving their BTC. If Bitcoin later freezes vulnerable addresses through a soft fork, holders could recover their assets using quantum-resistant STARK proofs. The proof must be created before a quantum attack or freeze, however, and the proposal has not yet been implemented.
Michael Saylor Says Quantum Threat to Bitcoin Is at Least 10 Years Away
Quantum computers capable of breaking public-key cryptography could threaten Bitcoin signatures and asset ownership, making the technology a long-term market risk. Strategy, formerly MicroStrategy, co-founder and Executive Chairman Michael Saylor said banks, the internet and crypto assets all face the same pressure to upgrade, while Bitcoin could adopt quantum-resistant cryptography through updates to its nodes, wallets and protocol.
Saylor told Natalie Brunell’s “Coin Stories” on Feb. 23, 2026, that any quantum breakthrough posing a material threat was at least 10 years away. At a Mizuho event on April 8, he again said the risk was overstated and could be addressed through upgrades. He also said Bitcoin had likely bottomed at about $60,000 in early February; its price was around $71,200 when the report was published on April 9.
Quantum Attack on Bitcoin Mining Would Require Star-Scale Energy, Study Says
Bitcoin uses a proof-of-work mechanism, and an attacker controlling more than 50% of the network’s computing power could theoretically reorganize its transaction history. An academic research team found that while quantum computing could accelerate calculations, a 51% attack on Bitcoin mining would still face physical constraints including hardware scale, cooling and energy supply, limiting the near-term threat.
As of July 20, 2026, the latest research estimates that a quantum computer powerful enough to overwhelm the entire Bitcoin network could require energy on the scale of a star, putting such a system beyond what existing institutions could deploy with funding alone. A more practical risk is the compromise of older wallets whose public keys remain exposed. Bitcoin developers have begun exploring quantum-resistant signatures and network upgrades.
ARK Invest White Paper Examines Bitcoin’s Quantum-Attack Resilience
Bitcoin relies on elliptic-curve digital signatures to secure asset ownership, but powerful quantum computers could eventually derive private keys from public keys that have already been exposed. ARK Invest and Bitcoin financial services provider Unchained therefore studied advances in quantum technology and potential paths for Bitcoin to adopt quantum-resistant cryptography, an issue with implications for long-term asset security and consensus on network upgrades.
On March 11, 2026, ARK Invest and Unchained published the “Bitcoin and Quantum Computing” white paper, estimating that 34.6%, or about 6.9 million BTC, is theoretically at risk. That includes about 1.7 million BTC believed to be lost and roughly 5.2 million BTC that could be moved to more secure addresses. The report said the threat would emerge in stages and was not urgent in the near term, leaving the community time to deploy quantum-resistant solutions.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.