A breakthrough in protecting cryptocurrency from a potential attack by a quantum computer has been announced by a cryptography and blockchain-infrastructure company.
Israel-based StarkWare revealed Aug. 26 that a quantum-safe transaction using its Quantum-Safe Bitcoin (QSB) method had been mined on the Bitcoin (BTC) mainnet, the cryptocurrency’s live production network.
“StarkWare’s announcement is significant because it demonstrates something that, until now, many people assumed would require a change to the Bitcoin protocol,” explained David de Paula Santos Silva, founder and CEO of CyberX, a global cybersecurity company.
“A Bitcoin holder can now move coins into a quantum-resistant construction using Bitcoin as it exists today, without changing its consensus rules,” he told TechNewsWorld.
He cautioned, however, that StarkWare’s QSB method, developed by the company’s general manager of applications, Avihu Levy, does not make Bitcoin itself quantum-safe. “What was demonstrated on mainnet is a specific way of protecting particular holdings against a quantum adversary,” he said.
“As far as we are aware, this is the first time anyone has actually done this on mainnet instead of just writing a paper about it,” added Joni Zhuleuku, chief research officer at Altcoin Pro, a cryptocurrency education and coaching company in Tampa, Fla.
“For holders, that matters because quantum used to be a someday problem, and now there’s a real, working way to protect coins if someone wants to use it today,” he told TechNewsWorld.
“Most people won’t need to touch this yet,” he said, “but it proves the defense doesn’t have to wait on Bitcoin itself changing first because reaching consensus on Bitcoin takes a long time among miners.”
Adding a Quantum-Resistant Lock
StarkWare explained that Bitcoin’s signatures rest on elliptic curve cryptography. Shor’s algorithm, running on a large enough quantum computer, will be able to solve that class of mathematical problem quickly, so the puzzle protecting a coin will no longer be sufficient to protect it.
QSB closes the window for that type of attack by adding a second quantum-resistant lock alongside the existing one, built on hash functions instead of elliptic curves, StarkWare explained. Shor’s algorithm does not pose the same threat to hash functions as it does to elliptic-curve cryptography.
It noted that QSB uses signature grinding, a technique that lets a valid Bitcoin signature be created without a private key, and it works on Bitcoin exactly as it exists today. The sender spends computational effort searching for a spending transaction whose hash happens to be a validly formatted signature.
Bitcoin accepts it, and the transaction’s security then depends on the difficulty of reversing a hash rather than the secrecy of a private key, it added. The computational work is performed off-chain before the transaction is broadcast.
Private keys are paired with public keys. Publishing a public key is safe today because existing computers cannot feasibly work backward from it to recover the private key. A sufficiently powerful quantum computer running Shor’s algorithm could change that. As StarkWare put it, every published public key would then become “a private key waiting to be recovered.”
Safety Valve, Not a Cure
While QSB shows that BTC holders may have ways to gain some quantum-resistant protection before Bitcoin undergoes a full protocol upgrade, it is not a complete solution, maintained Florian Neukart, chief technology officer at Terra Quantum, a global quantum technology company.
“It protects specific outputs that are moved into this construction,” he told TechNewsWorld. “It does not make existing BTC holdings automatically quantum-safe.”
This is protection against a future threat, not a response to a present one, explained Katrina Rosseini, a visiting fellow at the National Security Institute’s Cyber and Technology Center at George Mason University’s Antonin Scalia Law School in Fairfax, Va.
“Think of it as a safety valve, not a cure,” she told TechNewsWorld. “The method isn’t practical for everyday use yet.”
QSB transactions also use a nonstandard format that does not travel through Bitcoin’s ordinary mempool, so they must currently be submitted directly to a miner.
“It costs roughly $150-$200 in computational time and takes several hours,” she continued. “But it shows holders have another way to protect certain assets while the ecosystem works toward a broader post-quantum fix.”
“For almost all holders, nothing has changed,” added Tim D. Williams, CTO of ProteQC, a cryptographic-resilience advisory firm in London.
“QSB isn’t in any wallet or exchange; it costs hundreds of dollars and hours of computation per transaction, and needs direct handover to a mining pool, presenting new risks in place of current risks,” he told TechNewsWorld.
“What it removes is an argument that ‘nothing can be done about quantum threats until the whole Bitcoin network agrees,’ which, as a result of QSB, is no longer true,” he added.
Bitcoin’s Quantum Problem Is Bigger
Although all cryptocurrencies face a quantum threat, the QSB method may not have legs beyond Bitcoin, contended Shujaatali Badami, a quantum-IoT research engineer in Chicago.
“The QSB trick leans on quirks of legacy Bitcoin script and doesn’t port anywhere else,” he told TechNewsWorld.
StarkWare’s announcement does not represent a viable path to quantum security for Bitcoin, argued Adam Everspaugh, a cryptography expert at Keeper Security, a password management and online storage company in Chicago.
“The technical work is creative, but it falls well short of what real quantum resistance requires,” he told TechNewsWorld.
“Solving quantum risk for cryptocurrencies like Bitcoin requires protocol-level changes,” he asserted. “This workaround does not address the foundational problem that roughly 30% of all issued supply have public keys already exposed on-chain.”
“This method does not help those holders move their coins to quantum-safe storage, nor does it address the risk of abandoned coins being recovered and dumped by a quantum adversary,” he explained. “Individual holder solutions cannot solve network-level problems.”
“The real problems are social and engineering challenges,” he said, including defining Q-day, implementing protocol changes across a decentralized network, and handling abandoned coins during the transition.
“The cryptocurrency community is not solving these through workarounds, and focusing effort on partial measures rather than comprehensive protocol migration risks leaving the network vulnerable precisely when protection becomes critical,” he added.
StarkWare’s demonstration that Bitcoin can be moved into an output protected by hash-based cryptography rather than relying on the elliptic-curve signatures vulnerable to Shor’s algorithm is meaningful, said Utkarsh Ahuja, founder and managing partner at Moon Pursuit, a crypto-native investment firm in Dublin, Calif.
“But the harder problem,” he told TechNewsWorld, “is protecting the enormous amount of value already sitting within today’s infrastructure and creating a migration mechanism that can realistically be adopted by wallets, custodians, exchanges, institutions and individual holders.”
Read the full article here






