{"id":7138,"date":"2026-08-27T15:25:09","date_gmt":"2026-08-27T15:25:09","guid":{"rendered":"https:\/\/cryptolinks.com\/news\/?p=7138"},"modified":"2026-08-27T15:25:09","modified_gmt":"2026-08-27T15:25:09","slug":"quantum-safe-bitcoin-qsb-mainnet","status":"publish","type":"post","link":"https:\/\/cryptolinks.com\/news\/quantum-safe-bitcoin-qsb-mainnet","title":{"rendered":"StarkWare\u2019s Quantum-Resistant Bitcoin Spend Hits Mainnet\u2014No Soft Fork Required"},"content":{"rendered":"<article><strong>StarkWare researcher Avihu Levy\u2019s Quantum-Safe Bitcoin construction successfully spent a specially protected Bitcoin output on mainnet on August 26, 2026, without changing Bitcoin consensus or adding a new opcode. The 10,000-satoshi QSB output was mined through MARA after direct submission via Slipstream\u2014but the result is better understood as an experimental quantum \u201clifeboat\u201d than proof that Bitcoin itself is now quantum-safe.<\/strong>On August 26, 2026, Bitcoin block <strong>964,199<\/strong> included transaction <code>305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07<\/code>, the mainnet spend using Avihu Levy\u2019s Quantum-Safe Bitcoin, or QSB, construction. The specially protected output contained <strong>10,000 satoshis<\/strong>, required no soft fork and no new opcode, and reached MARA Pool through its Slipstream miner-direct service. That is a genuine Bitcoin engineering milestone\u2014but it did not change the cryptography protecting ordinary Bitcoin outputs. Bitcoin\u2019s wider quantum-migration problem, including work around BIP-360 and Blockstream\u2019s SHRINCS, is still very much open.If you want a broader grounding in how Bitcoin transactions, keys and UTXOs work before going deeper, see the <a href=\"\/bitcoin-wiki\">CryptoLinks Bitcoin Wiki and learning resources<\/a> and our review of the <a href=\"\/915\/bitcoindeveloperguide\">Bitcoin Developer Guide<\/a>.<\/p>\n<h2>Key takeaways<\/h2>\n<ul>\n<li><strong>QSB worked under existing Bitcoin consensus rules.<\/strong> No soft fork, new opcode or Bitcoin Core consensus change was required for this demonstration.<\/li>\n<li><strong>The transaction was non-standard under ordinary relay policy.<\/strong> It needed miner-direct submission through MARA Slipstream rather than normal public mempool propagation.<\/li>\n<li><strong>QSB protects a specially constructed UTXO, not Bitcoin globally.<\/strong><\/li>\n<li><strong>Already-exposed elliptic-curve public keys remain a separate migration problem.<\/strong><\/li>\n<li><strong>BIP-360 remains a Draft soft-fork proposal<\/strong> centered on Pay-to-Merkle-Root, or P2MR.<\/li>\n<li><strong>SHRINCS is not active on Bitcoin mainnet.<\/strong> Blockstream has demonstrated post-quantum work on Liquid, while the current Bitcoin-oriented SHRINCS specification remains research-stage.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7149\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet.png\" alt=\"What StarkWare actually put on Bitcoin mainnet\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/What-StarkWare-actually-put-on-Bitcoin-mainnet-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>What StarkWare actually put on Bitcoin mainnet<\/h2>\n<p>The mainnet confirmation matters because QSB is no longer only a paper construction.<\/p>\n<p>The Bitcoin blockchain shows the QSB spend inside <strong>block 964,199<\/strong>, mined by <strong>MARA Pool<\/strong> at <strong>20:48:34 UTC on August 26, 2026<\/strong>. StarkWare describes the transaction as what it believes to be the first quantum-safe Bitcoin-mainnet transaction.<\/p>\n<table>\n<thead>\n<tr>\n<th>QSB mainnet fact<\/th>\n<th>Result<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Transaction ID<\/td>\n<td><code>305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07<\/code><\/td>\n<\/tr>\n<tr>\n<td>Bitcoin block<\/td>\n<td>964,199<\/td>\n<\/tr>\n<tr>\n<td>Block timestamp<\/td>\n<td>August 26, 2026, 20:48:34 UTC<\/td>\n<\/tr>\n<tr>\n<td>Miner<\/td>\n<td>MARA Pool<\/td>\n<\/tr>\n<tr>\n<td>QSB-protected output<\/td>\n<td>10,000 sats<\/td>\n<\/tr>\n<tr>\n<td>Reported transaction inputs<\/td>\n<td>44,000 sats across two inputs<\/td>\n<\/tr>\n<tr>\n<td>Reported transaction fee<\/td>\n<td>5,179 sats<\/td>\n<\/tr>\n<tr>\n<td>Reported QSB locking script<\/td>\n<td>Approximately 9,923 bytes<\/td>\n<\/tr>\n<tr>\n<td>Ordinary mempool relay<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>Miner submission<\/td>\n<td>MARA Slipstream<\/td>\n<\/tr>\n<tr>\n<td>Soft fork required<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>New opcode required<\/td>\n<td>No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The important distinction is that the <strong>10,000 sats were first placed into a specially constructed QSB-protected output and then spent using the QSB authorization mechanism<\/strong>. Saying simply that \u201c10,000 sats were sent quantum-safely\u201d hides the most interesting part of the demonstration.<\/p>\n<p>Conceptually, the sequence was:<\/p>\n<p><strong>Ordinary Bitcoin funding transaction<\/strong><br \/>\n\u2193<br \/>\n<strong>10,000-sat QSB-protected UTXO<\/strong><br \/>\n\u2193<br \/>\n<strong>QSB spending transaction<\/strong><br \/>\n\u2193<br \/>\n<strong>MARA Slipstream<\/strong><br \/>\n\u2193<br \/>\n<strong>MARA Pool<\/strong><br \/>\n\u2193<br \/>\n<strong>Bitcoin block 964,199<\/strong><\/p>\n<h2>How can a quantum-resistant Bitcoin transaction work without a soft fork?<\/h2>\n<p>QSB does not install a new post-quantum signature algorithm into Bitcoin.<\/p>\n<p>Instead, Levy\u2019s construction uses functionality that Bitcoin already knows how to validate. The public implementation combines hash commitments, HORS\/Lamport-style one-time-signature ideas, <code>OP_RIPEMD160<\/code>, existing signature checks and legacy transaction-sighash behavior.<\/p>\n<p>The conceptual trick is unusual: the legitimate spender performs a very large computational search off-chain until transaction-derived values satisfy conditions that Bitcoin\u2019s existing signature machinery already understands.<\/p>\n<p>That turns an apparent limitation into a feature. Bitcoin still executes its old validation rules, but the authorization security of the QSB construction is designed to depend critically on <strong>hash preimages and transaction binding<\/strong> rather than the assumption that an elliptic-curve private key cannot be recovered from its public key.<\/p>\n<p>This is why QSB can use Bitcoin\u2019s existing ECDSA verification machinery without claiming that ECDSA itself becomes quantum-resistant.<\/p>\n<p>For readers who want the deeper protocol mechanics behind scripts, sighashes and transaction validation, the <a href=\"\/915\/bitcoindeveloperguide\">Bitcoin Developer Guide<\/a> is a useful companion resource.<\/p>\n<h2>Why ECDSA can appear inside QSB without securing it<\/h2>\n<p>At first glance, QSB looks contradictory.<\/p>\n<p>Bitcoin\u2019s legacy signature system uses ECDSA over secp256k1, while newer Taproot key-path spending uses Schnorr signatures over the same elliptic curve. A sufficiently capable fault-tolerant quantum computer running Shor\u2019s algorithm could, in principle, break the discrete-logarithm assumption that protects both.<\/p>\n<p>Yet QSB still invokes Bitcoin\u2019s existing signature verification behavior.<\/p>\n<p>The distinction is between <strong>ECDSA as a hardness assumption<\/strong> and <strong>ECDSA verification as a computational gadget<\/strong>.<\/p>\n<p>Normal Bitcoin ownership assumes an attacker cannot derive the private key corresponding to a public key. QSB instead arranges values so that Bitcoin\u2019s existing verifier becomes part of a larger hash-based puzzle. Levy\u2019s security argument is therefore based on the difficulty of finding suitable hash preimages and modifying a transaction without repeating enormous searches.<\/p>\n<p>QSB does not remove ECDSA from Bitcoin. It repurposes machinery Bitcoin already possesses.<\/p>\n<h2>Transaction pinning is a critical part of the construction<\/h2>\n<p>A quantum-resistant authorization system would not help much if an attacker could simply copy the authorization and change the destination.<\/p>\n<p>QSB therefore binds its expensive search to the intended spending transaction.<\/p>\n<p>Fields affecting the transaction sighash\u2014including relevant outputs, sequence and locktime data\u2014feed into the values used by the QSB construction. If an attacker changes the destination or another committed transaction field, the sighash changes.<\/p>\n<p>That changes the values feeding the QSB puzzle, which means the expensive search has to be repeated.<\/p>\n<p>The intended effect is that a future attacker cannot merely recover an exposed elliptic-curve private key, replace the owner\u2019s destination and produce an ordinary competing signature.<\/p>\n<p>I would still avoid interpreting this as proof that every conceivable implementation, malleability or miner-related attack has been eliminated. QSB remains experimental cryptography and should be independently reviewed as such.<\/p>\n<h2>Consensus-valid does not mean mempool-standard<\/h2>\n<p>This may be the most useful Bitcoin lesson in the entire experiment.<\/p>\n<p>A transaction can be <strong>valid under Bitcoin consensus rules while still being rejected from ordinary nodes\u2019 mempools under default policy<\/strong>.<\/p>\n<p>Consensus determines what transactions may legally appear in a valid Bitcoin block. Standardness policy is an additional set of rules Bitcoin Core nodes typically apply when deciding what they will store and relay through the peer-to-peer network.<\/p>\n<p>These are not the same thing.<\/p>\n<p>QSB fits the unusual middle category:<\/p>\n<ul>\n<li>Bitcoin consensus can validate it.<\/li>\n<li>Default mempool policy does not normally relay it.<\/li>\n<li>A miner can still deliberately accept it.<\/li>\n<li>Once included in a valid block, fully validating nodes accept the confirmed transaction.<\/li>\n<\/ul>\n<p>So the correct wording is not \u201cBitcoin nodes rejected QSB.\u201d<\/p>\n<p>The more accurate statement is: <strong>ordinary nodes would not relay the transaction under default policy, but Bitcoin nodes accept it as consensus-valid once it appears in a valid block.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7143\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered.png\" alt=\"Why MARA Slipstream mattered\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-MARA-Slipstream-mattered-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>Why MARA Slipstream mattered<\/h2>\n<p>Because the QSB spend could not travel through the ordinary public mempool, the researchers needed another route to block inclusion.<\/p>\n<p>That route was <strong>MARA Slipstream<\/strong>, a service designed to let users submit certain non-standard Bitcoin transactions directly to MARA.<\/p>\n<p>The MARA dependency is therefore <strong>operational rather than cryptographic<\/strong>.<\/p>\n<p>QSB\u2019s mathematics does not depend on MARA. In principle, another miner willing and able to accept the same consensus-valid transaction could mine it. But today, a usable QSB path depends on obtaining access to a miner that will accept the transaction outside normal relay policy.<\/p>\n<p>That distinction\u2014cryptographic decentralization versus practical relay accessibility\u2014is important. You can learn more about how mining pools participate in Bitcoin block production in the <a href=\"\/mining-pools\">CryptoLinks Bitcoin mining pools guide<\/a>.<\/p>\n<h2>The GPU grinding that makes QSB possible\u2014and expensive<\/h2>\n<p>QSB moves much of its cost away from Bitcoin nodes and into transaction construction.<\/p>\n<p>The public implementation describes several large searches: transaction pinning, a first digest search and a second digest search. The relevant DER-format target has a probability of roughly <strong>2<sup>-46.4<\/sup><\/strong> per random candidate at the consensus level.<\/p>\n<p>That requires enormous amounts of trial-and-error computation.<\/p>\n<p>This should not be confused with Bitcoin mining. QSB\u2019s GPU grinding is <strong>off-chain transaction-construction work<\/strong>, not proof-of-work securing the Bitcoin blockchain.<\/p>\n<table>\n<thead>\n<tr>\n<th>QSB computation stage<\/th>\n<th>Public repository estimate<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Transaction pinning<\/td>\n<td>$25\u2013$50<\/td>\n<\/tr>\n<tr>\n<td>Digest round 1<\/td>\n<td>$25\u2013$50<\/td>\n<\/tr>\n<tr>\n<td>Digest round 2<\/td>\n<td>$25\u2013$50<\/td>\n<\/tr>\n<tr>\n<td>Original modeled total<\/td>\n<td>$75\u2013$150<\/td>\n<\/tr>\n<tr>\n<td>Completed mainnet experiment<\/td>\n<td>Approximately $150\u2013$200 reported; computation took hours<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The narrower $150\u2013$200 figure should be treated as a reported estimate for the completed experiment rather than an audited cloud-computing invoice. Exact mainnet GPU-hours, provider billing and the final hardware mix have not been publicly itemized in enough detail to present them as independently verified accounting data.<\/p>\n<p>The QSB repository also estimates approximately <strong>118 bits of second-preimage resistance<\/strong> under its Shor-threat model, with roughly <strong>59 bits<\/strong> against an idealized Grover speedup. Those are Levy\u2019s analytical estimates, not an independent cryptographic certification.<\/p>\n<h2>What QSB actually protects from a future quantum computer<\/h2>\n<p>The key issue is not simply whether an address has been spent from. It is whether the relevant elliptic-curve public key is already visible to an attacker.<\/p>\n<p>There are two useful categories.<\/p>\n<h3>Long-exposure attacks<\/h3>\n<p>In a long-exposure scenario, a public key is already visible on-chain for months or years before its owner attempts to spend.<\/p>\n<p>Examples can include:<\/p>\n<ul>\n<li>old P2PK outputs;<\/li>\n<li>Taproot\/P2TR outputs, where an elliptic-curve key is committed directly in the output;<\/li>\n<li>reused P2PKH or P2WPKH addresses after the relevant public key has already appeared in a previous spend.<\/li>\n<\/ul>\n<h3>Short-exposure attacks<\/h3>\n<p>Fresh P2PKH and P2WPKH outputs can initially expose a hash of the public key rather than the public key itself.<\/p>\n<p>The public key becomes visible when the owner spends.<\/p>\n<p>A hypothetical sufficiently fast quantum attacker would then have the confirmation window to recover the corresponding private key, construct a conflicting spend and try to get it confirmed first.<\/p>\n<p>QSB is especially interesting because its transaction-binding construction aims to defend against this kind of replacement attack without requiring Bitcoin to know a new post-quantum signature opcode.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7148\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued.png\" alt=\"The biggest catch already-exposed Bitcoin keys cannot simply be rescued\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/The-biggest-catch-already-exposed-Bitcoin-keys-cannot-simply-be-rescued-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>The biggest catch: already-exposed Bitcoin keys cannot simply be rescued<\/h2>\n<p>This is the limitation I would emphasize most strongly.<\/p>\n<p>If a cryptographically relevant quantum computer exists and an output\u2019s elliptic-curve public key is already visible, the attacker does not have to wait for the legitimate owner to initiate migration.<\/p>\n<p>The attacker can attack that public key directly.<\/p>\n<p>If they obtain the classical private key first, moving the legitimate owner\u2019s next output into QSB does not restore the secrecy that has already been lost.<\/p>\n<table>\n<thead>\n<tr>\n<th>Existing Bitcoin output\/state<\/th>\n<th>Public key exposed?<\/th>\n<th>QSB migration potential before a CRQC?<\/th>\n<th>Main issue<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Fresh P2PKH<\/td>\n<td>Usually no<\/td>\n<td>Potentially yes<\/td>\n<td>Key is revealed during migration spend<\/td>\n<\/tr>\n<tr>\n<td>Fresh P2WPKH<\/td>\n<td>Usually no<\/td>\n<td>Potentially yes<\/td>\n<td>Same short-exposure window<\/td>\n<\/tr>\n<tr>\n<td>Reused P2PKH<\/td>\n<td>Often yes<\/td>\n<td>Limited once exposed<\/td>\n<td>Previous spend revealed key<\/td>\n<\/tr>\n<tr>\n<td>Reused P2WPKH<\/td>\n<td>Often yes<\/td>\n<td>Limited once exposed<\/td>\n<td>Previous spend revealed key<\/td>\n<\/tr>\n<tr>\n<td>P2PK<\/td>\n<td>Yes<\/td>\n<td>Can migrate ahead of threat<\/td>\n<td>Long exposure<\/td>\n<\/tr>\n<tr>\n<td>P2TR \/ Taproot<\/td>\n<td>Yes<\/td>\n<td>Can migrate ahead of threat<\/td>\n<td>Long exposure<\/td>\n<\/tr>\n<tr>\n<td>QSB-protected output<\/td>\n<td>Hash-based construction<\/td>\n<td>Intended protection<\/td>\n<td>Experimental and non-standard<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This is also why QSB should not be presented as a way for Satoshi-era P2PK coins to remain safe after a quantum attacker becomes operational. Many early P2PK outputs already publish their public keys.<\/p>\n<h2>Why Taproot has a different quantum-exposure profile<\/h2>\n<p>Taproot is not insecure today.<\/p>\n<p>The concern exists only in the hypothetical presence of a sufficiently capable quantum attacker.<\/p>\n<p>A P2TR output commits directly to an elliptic-curve public key. That key is visible before the output is spent, creating a long-exposure profile.<\/p>\n<p>Fresh P2PKH and P2WPKH outputs are different because a public-key hash can remain on-chain until the first spend reveals the actual public key.<\/p>\n<p>This difference is one reason <strong>BIP-360<\/strong> was proposed.<\/p>\n<h2>BIP-360: the protocol-level Pay-to-Merkle-Root route<\/h2>\n<p>BIP-360 is currently a <strong>Draft Bitcoin consensus soft-fork proposal<\/strong> for a new output type called <strong>Pay-to-Merkle-Root, or P2MR<\/strong>.<\/p>\n<p>P2MR preserves much of Taproot\u2019s script-tree functionality while removing the ordinary elliptic-curve key-path spend. Instead of committing to an internal public key plus a script tree, a P2MR output commits to the Merkle root of the script tree itself.<\/p>\n<p>Its immediate purpose is to reduce <strong>long-exposure quantum risk<\/strong>.<\/p>\n<p>But BIP-360 is not a complete post-quantum signature system by itself. Short-exposure protection and practical post-quantum signatures still require additional work.<\/p>\n<p>That means these two statements should always appear together:<\/p>\n<p><strong>QSB required no soft fork for its August 26 mainnet transaction.<\/strong><\/p>\n<p><strong>A protocol-level upgrade is still the more practical long-term path if Bitcoin wants standardized, wallet-compatible post-quantum protection.<\/strong><\/p>\n<p>A soft fork should also not be confused with a hard fork. Bitcoin soft forks introduce stricter validation rules within Bitcoin\u2019s established upgrade model.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7144\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach.png\" alt=\"Blockstream\u2019s SHRINCS takes a different approach\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Blockstreams-SHRINCS-takes-a-different-approach-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>Blockstream\u2019s SHRINCS takes a different approach<\/h2>\n<p>Blockstream Research is working on a more conventional hash-based signature direction.<\/p>\n<p><strong>SHRINCS<\/strong> is designed as a compact post-quantum signature construction optimized around Bitcoin-like block-space constraints. It uses SHA-256-based hash signatures rather than relying on elliptic-curve hardness for its post-quantum security target.<\/p>\n<p>Blockstream demonstrated post-quantum signing on the <strong>Liquid Network<\/strong> in March 2026.<\/p>\n<p>Liquid is a production Bitcoin sidechain, not Bitcoin mainnet. That makes the SHRINCS milestone real and technically relevant, but it should not be described as a Bitcoin-mainnet post-quantum transaction.<\/p>\n<p>There is also an important status update for readers following older SHRINCS coverage. The current public SHRINCS draft specification lists:<\/p>\n<ul>\n<li><strong>48-byte public keys;<\/strong><\/li>\n<li><strong>548\u20134,619-byte stateful signatures;<\/strong><\/li>\n<li><strong>5,777-byte stateless signatures.<\/strong><\/li>\n<\/ul>\n<p>The specification currently labels itself <strong>Draft<\/strong> and still shows its BIP number as unassigned. SHRINCS is therefore not an activated Bitcoin feature.<\/p>\n<h2>SHRIMPS is related\u2014but it is not SHRINCS<\/h2>\n<p>Blockstream\u2019s related <strong>SHRIMPS<\/strong> work deals with an especially awkward property of compact stateful hash-based signatures: signing devices must safely track state.<\/p>\n<p>If a stateful wallet restores an old backup and unknowingly rewinds its signing state, it can reuse secret material in ways that undermine security.<\/p>\n<p>This becomes especially important for hardware wallets, multisig custody and multi-device setups.<\/p>\n<p>That is a useful reminder that post-quantum migration is not simply a matter of swapping Schnorr for another signature algorithm. Wallet backups, device synchronization, derivation, multisig, recovery and institutional procedures all matter.<\/p>\n<h2>QSB vs. BIP-360 vs. SHRINCS<\/h2>\n<table>\n<thead>\n<tr>\n<th>Criterion<\/th>\n<th>QSB<\/th>\n<th>BIP-360 \/ P2MR<\/th>\n<th>SHRINCS<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Bitcoin mainnet today<\/td>\n<td>Yes, experimental demonstration<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>Soft fork required<\/td>\n<td>No for demonstrated construction<\/td>\n<td>Yes<\/td>\n<td>Bitcoin integration would require consensus functionality<\/td>\n<\/tr>\n<tr>\n<td>Main idea<\/td>\n<td>Hash-based spend using existing Bitcoin rules<\/td>\n<td>Quantum-safer output architecture<\/td>\n<td>Purpose-built hash-based signatures<\/td>\n<\/tr>\n<tr>\n<td>Standard relay today<\/td>\n<td>No<\/td>\n<td>Not applicable until activation<\/td>\n<td>Not applicable until activation<\/td>\n<\/tr>\n<tr>\n<td>Long-exposure protection<\/td>\n<td>Yes for QSB outputs<\/td>\n<td>Primary goal<\/td>\n<td>Intended with PQ spending conditions<\/td>\n<\/tr>\n<tr>\n<td>Short-exposure protection<\/td>\n<td>Intended<\/td>\n<td>Not solved alone<\/td>\n<td>Intended<\/td>\n<\/tr>\n<tr>\n<td>Already-exposed keys<\/td>\n<td>No automatic rescue<\/td>\n<td>Migration problem remains<\/td>\n<td>Migration problem remains<\/td>\n<\/tr>\n<tr>\n<td>Wallet-ready<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>Primary practical cost<\/td>\n<td>Grinding, script size and miner routing<\/td>\n<td>Consensus coordination<\/td>\n<td>Signature size and state management<\/td>\n<\/tr>\n<tr>\n<td>Status<\/td>\n<td>Mainnet proof of concept<\/td>\n<td>Draft BIP<\/td>\n<td>Draft research\/specification<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>I would not treat these projects as direct competitors where one winner makes the others irrelevant.<\/p>\n<p>They answer different questions.<\/p>\n<p><strong>QSB asks:<\/strong> Can Bitcoin validate a hash-secured spending construction today without changing consensus?<\/p>\n<p><strong>BIP-360 asks:<\/strong> Can Bitcoin gain an output architecture that removes a permanently exposed elliptic-curve key path?<\/p>\n<p><strong>SHRINCS asks:<\/strong> What could an efficient Bitcoin-oriented post-quantum signature system look like if Bitcoin consensus eventually learns to verify it?<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7150\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature.png\" alt=\"Why Bitcoin cannot simply adopt any post-quantum signature\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Why-Bitcoin-cannot-simply-adopt-any-post-quantum-signature-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>Why Bitcoin cannot simply adopt any post-quantum signature<\/h2>\n<p>NIST has already standardized post-quantum signature systems, including ML-DSA and the hash-based SLH-DSA.<\/p>\n<p>That does not mean Bitcoin can simply choose one and call the problem solved.<\/p>\n<p>Bitcoin has unusually expensive bytes. Every signature competes for block space, propagates across the peer-to-peer network and has to be processed by validating infrastructure.<\/p>\n<table>\n<thead>\n<tr>\n<th>Scheme \/ construction<\/th>\n<th>Approximate size<\/th>\n<th>Status for Bitcoin<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>BIP-340 Schnorr<\/td>\n<td>64-byte signature<\/td>\n<td>Live<\/td>\n<\/tr>\n<tr>\n<td>ML-DSA-44<\/td>\n<td>About 2,420-byte signature<\/td>\n<td>NIST standard; not Bitcoin consensus<\/td>\n<\/tr>\n<tr>\n<td>SLH-DSA-SHA2-128s<\/td>\n<td>7,856-byte signature<\/td>\n<td>NIST standard; not Bitcoin consensus<\/td>\n<\/tr>\n<tr>\n<td>SHRINCS current draft<\/td>\n<td>548\u20134,619 bytes stateful; 5,777 bytes stateless<\/td>\n<td>Research\/draft<\/td>\n<\/tr>\n<tr>\n<td>QSB mainnet experiment<\/td>\n<td>Approximately 9,923-byte locking Script reported<\/td>\n<td>Experimental Bitcoin-mainnet demonstration<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The last row deserves a warning: QSB\u2019s roughly 9,923-byte figure describes its reported locking Script, so it should not be compared one-for-one with a standalone 64-byte Schnorr signature.<\/p>\n<p>The hard problem is not finding post-quantum cryptography. It is fitting post-quantum cryptography into Bitcoin\u2019s block space, wallet model, hardware devices, custody infrastructure and governance process.<\/p>\n<h2>QSB is a lifeboat, not Bitcoin\u2019s final quantum upgrade<\/h2>\n<p>The \u201clifeboat\u201d analogy is useful if we do not push it too far.<\/p>\n<p>A lifeboat gives you an emergency route.<\/p>\n<p>It does not redesign the ship.<\/p>\n<p>It does not automatically accommodate every passenger.<\/p>\n<p>And it does not remove the reason to strengthen the underlying system.<\/p>\n<p>QSB\u2019s advantages are substantial:<\/p>\n<ul>\n<li>it moved from a paper into a real Bitcoin-mainnet block;<\/li>\n<li>it required no consensus change;<\/li>\n<li>it required no new opcode;<\/li>\n<li>it demonstrates surprising flexibility in existing Bitcoin Script;<\/li>\n<li>it offers researchers a measurable emergency fallback;<\/li>\n<li>it provides real-world data about compute, block space, miner policy and deployment friction.<\/li>\n<\/ul>\n<p>Its limitations are equally real:<\/p>\n<ul>\n<li>large and unusual Script construction;<\/li>\n<li>hours of off-chain computation;<\/li>\n<li>meaningful GPU cost;<\/li>\n<li>non-standard relay;<\/li>\n<li>miner-direct submission;<\/li>\n<li>no ordinary wallet workflow;<\/li>\n<li>no mainstream hardware-wallet integration;<\/li>\n<li>no mature recovery or descriptor standard;<\/li>\n<li>no automatic rescue for already-exposed keys;<\/li>\n<li>no network-wide post-quantum protection.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7145\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness.png\" alt=\"Mainnet demonstration is not the same as production readiness\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/Mainnet-demonstration-is-not-the-same-as-production-readiness-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<h2>Mainnet demonstration is not the same as production readiness<\/h2>\n<p>A useful way to judge QSB is as a development ladder.<\/p>\n<ol>\n<li><strong>Paper:<\/strong> mathematical construction exists \u2014 reached.<\/li>\n<li><strong>Reference implementation:<\/strong> software exists \u2014 reached.<\/li>\n<li><strong>Local\/test environment:<\/strong> construction can be exercised \u2014 reached.<\/li>\n<li><strong>Mainnet demonstration:<\/strong> real Bitcoin transaction mined \u2014 <strong>reached August 26, 2026<\/strong>.<\/li>\n<li><strong>Standard relay:<\/strong> normal public mempool propagation \u2014 not reached.<\/li>\n<li><strong>Mainstream wallet integration:<\/strong> normal user-facing wallet support \u2014 not reached.<\/li>\n<li><strong>Hardware-wallet\/custody support:<\/strong> robust production signing and backups \u2014 not reached.<\/li>\n<li><strong>Broad interoperable adoption:<\/strong> ecosystem-wide deployment \u2014 not reached.<\/li>\n<li><strong>Protocol-level standardized PQ migration:<\/strong> network-wide long-term solution \u2014 not reached.<\/li>\n<\/ol>\n<p>Mainnet success is important without being production readiness.<\/p>\n<h2>Does QSB solve the Satoshi-era and lost-coin problem?<\/h2>\n<p>No.<\/p>\n<p>Some of Bitcoin\u2019s oldest outputs use P2PK and expose public keys directly. If a cryptographically relevant quantum computer becomes capable of deriving the associated private key before those coins have migrated, an attacker could potentially compete for them using the same classical spending authority.<\/p>\n<p>QSB does not answer what Bitcoin should eventually do with vulnerable coins whose owners never migrate.<\/p>\n<p>Possible policy approaches discussed across the broader quantum debate include leaving vulnerable outputs spendable forever, freezing certain old outputs after a migration period, requiring new proofs or creating special migration rules.<\/p>\n<p>Every option has serious tradeoffs.<\/p>\n<p>Leaving everything untouched preserves Bitcoin\u2019s current ownership rules but could allow future quantum theft. Freezing vulnerable outputs could prevent theft but might permanently immobilize coins belonging to legitimate owners.<\/p>\n<p>Bitcoin has not settled that governance question, and QSB does not settle it either.<\/p>\n<h2>What Bitcoin holders should do now<\/h2>\n<p><strong>No immediate wallet action is required solely because this transaction was mined.<\/strong><\/p>\n<p>There is no publicly demonstrated cryptographically relevant quantum computer currently breaking Bitcoin\u2019s secp256k1 signatures. Nobody can responsibly give Bitcoin holders a guaranteed \u201cQ-Day\u201d date based simply on a physical-qubit count or a vendor roadmap.<\/p>\n<p>The useful conclusion is preparedness rather than panic.<\/p>\n<ul>\n<li>Avoid unnecessary address reuse where practical.<\/li>\n<li>Keep wallet software supported and updated.<\/li>\n<li>Use established wallet and backup practices.<\/li>\n<li>Follow Bitcoin Core and wallet-vendor guidance if a widely supported migration standard develops.<\/li>\n<li>Never enter seed phrases into online \u201cquantum checkers.\u201d<\/li>\n<li>Treat anyone selling an urgent QSB migration service skeptically.<\/li>\n<\/ul>\n<p>For normal security today, see our <a href=\"\/news\/secure-crypto-storage\">secure crypto storage guide<\/a> and the <a href=\"\/blockchain-security\">CryptoLinks Blockchain and Bitcoin Security section<\/a>.<\/p>\n<aside>\n<h3>Quantum scam warning<\/h3>\n<p><strong>QSB does not require a new cryptocurrency, token, bridge or Starknet asset.<\/strong><\/p>\n<p>Be suspicious of:<\/p>\n<ul>\n<li>\u201cQSB wallet upgrade\u201d websites;<\/li>\n<li>fake BIP-360 migration portals;<\/li>\n<li>seed-phrase \u201cquantum exposure checkers\u201d;<\/li>\n<li>fake MARA migration services;<\/li>\n<li>fake StarkWare Bitcoin bridges;<\/li>\n<li>\u201cQSB tokens\u201d claiming to be necessary for protection;<\/li>\n<li>urgent emails claiming your Bitcoin will be stolen unless you migrate immediately;<\/li>\n<li>websites asking you to deposit BTC into a \u201cquantum-safe address.\u201d<\/li>\n<\/ul>\n<p>QSB does not require STRK, does not move Bitcoin to Starknet and does not put a STARK proof into Bitcoin.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7146\" src=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem.png\" alt=\"My conclusion QSB changes Bitcoin\u2019s fallback, not the migration problem\" width=\"2304\" height=\"1296\" srcset=\"https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem.png 2304w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem-300x169.png 300w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem-1024x576.png 1024w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem-768x432.png 768w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem-1536x864.png 1536w, https:\/\/cryptolinks.com\/news\/wp-content\/uploads\/2026\/08\/My-conclusion-QSB-changes-Bitcoins-fallback-not-the-migration-problem-2048x1152.png 2048w\" sizes=\"auto, (max-width: 2304px) 100vw, 2304px\" \/><\/p>\n<\/aside>\n<h2>My conclusion: QSB changes Bitcoin\u2019s fallback, not the migration problem<\/h2>\n<p>The strongest conclusion from August 26 is not that Bitcoin solved quantum computing.<\/p>\n<p>It is that Bitcoin\u2019s existing rules turned out to contain enough flexibility for an experimental hash-based authorization construction to protect and spend a specially designed output on the real mainnet.<\/p>\n<p>That matters.<\/p>\n<p>The choice is no longer quite as simple as \u201cactivate a post-quantum soft fork immediately or have zero possible protection.\u201d QSB demonstrates that an emergency transaction-level escape hatch can exist within rules Bitcoin already validates.<\/p>\n<p>But it also demonstrates why an escape hatch is not a mass migration plan.<\/p>\n<p>Hours of GPU computation, substantial off-chain cost, a roughly 10-kilobyte locking construction, non-standard relay, miner-direct routing, experimental software and the inability to restore secrecy to already-exposed elliptic-curve keys are not properties millions of ordinary Bitcoin users should be expected to manage.<\/p>\n<p>BIP-360 and purpose-built post-quantum signature work such as SHRINCS remain important precisely because Bitcoin eventually needs something that can become <strong>standard, interoperable, wallet-compatible, auditable and scalable<\/strong>.<\/p>\n<p>I would therefore describe QSB as a resilience demonstration rather than a recommendation for ordinary cold storage today.<\/p>\n<p>It proves Bitcoin may already have a quantum lifeboat.<\/p>\n<p>It does not mean the ship has finished its quantum upgrade.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>What is QSB?<\/h3>\n<p><strong>QSB, or Quantum-Safe Bitcoin, is Avihu Levy\u2019s experimental method for creating and spending specially protected Bitcoin outputs using current consensus rules and hash-based security assumptions.<\/strong><\/p>\n<h3>Did a quantum-resistant Bitcoin transaction really reach mainnet?<\/h3>\n<p><strong>Yes.<\/strong> A QSB-protected Bitcoin output was successfully spent in block 964,199 on August 26, 2026. \u201cQuantum-resistant\u201d describes this specific construction, not the Bitcoin network as a whole.<\/p>\n<h3>What is the QSB transaction ID?<\/h3>\n<p><strong>The mainnet QSB spending transaction is <code>305a24ffea912b9cf428f29ebf952321c96dab5bab284fc0d0801562f5abab07<\/code>.<\/strong><\/p>\n<h3>How much Bitcoin was involved?<\/h3>\n<p><strong>The specially QSB-protected output contained 10,000 satoshis.<\/strong> Reporting on the transaction indicates the spending transaction used two inputs totaling 44,000 sats, so 10,000 sats should not be confused with the total input value.<\/p>\n<h3>Which Bitcoin block contains it?<\/h3>\n<p><strong>Block 964,199.<\/strong> MARA Pool mined the block on August 26, 2026 at 20:48:34 UTC.<\/p>\n<h3>Did QSB require a Bitcoin soft fork?<\/h3>\n<p><strong>No.<\/strong> This particular construction required no consensus change or new opcode. That does not mean Bitcoin will never need a soft fork for practical network-wide post-quantum migration.<\/p>\n<h3>Why did ordinary Bitcoin nodes not relay QSB?<\/h3>\n<p><strong>Because consensus validity and mempool standardness are different.<\/strong> QSB can be valid inside a Bitcoin block while falling outside the default policy ordinary nodes use for public mempool relay.<\/p>\n<h3>What is MARA Slipstream?<\/h3>\n<p><strong>MARA Slipstream provides a route for certain non-standard Bitcoin transactions to be submitted directly for mining.<\/strong> QSB used that route because ordinary public relay was insufficient.<\/p>\n<h3>Does QSB use STARK proofs or Starknet?<\/h3>\n<p><strong>No.<\/strong> QSB operates using Bitcoin functionality and does not require STARK proofs, Starknet, STRK or a cross-chain bridge.<\/p>\n<h3>Can Ledger, Trezor, Coldcard or normal Bitcoin wallets use QSB?<\/h3>\n<p><strong>There is no mainstream production QSB workflow for ordinary wallets today.<\/strong> The construction remains research-oriented and experimental.<\/p>\n<h3>Can QSB protect Satoshi-era Bitcoin?<\/h3>\n<p><strong>It cannot restore secrecy to public keys that are already exposed once a capable quantum attacker exists.<\/strong> That is especially relevant to many old P2PK outputs.<\/p>\n<h3>Is Taproot quantum-resistant?<\/h3>\n<p><strong>Taproot is secure against known practical attacks today, but its visible elliptic-curve output key creates long-exposure risk in the hypothetical presence of a sufficiently capable quantum computer.<\/strong><\/p>\n<h3>What is BIP-360?<\/h3>\n<p><strong>BIP-360 is the Draft Pay-to-Merkle-Root proposal.<\/strong> It proposes a new P2MR output type through a Bitcoin soft fork and removes the ordinary elliptic-curve key-path structure associated with P2TR.<\/p>\n<h3>Is SHRINCS live on Bitcoin?<\/h3>\n<p><strong>No.<\/strong> SHRINCS has reached research, public-specification and Liquid-demonstration stages, but it is not an activated Bitcoin-mainnet consensus feature.<\/p>\n<h3>Is Bitcoin quantum-safe now?<\/h3>\n<p><strong>No.<\/strong> Ordinary Bitcoin ECDSA and Schnorr spending paths remain elliptic-curve based. QSB demonstrated one specialized hash-based protection mechanism.<\/p>\n<h3>Should Bitcoin holders move their coins today?<\/h3>\n<p><strong>No immediate migration is required solely because QSB was demonstrated.<\/strong> Holders should prioritize ordinary wallet security, avoid unnecessary address reuse and monitor future Bitcoin Core and wallet-vendor migration guidance.<\/p>\n<hr \/>\n<h2>CryptoLinks resources for further reading<\/h2>\n<ul>\n<li><a href=\"\/\">CryptoLinks homepage \u2014 curated Bitcoin and cryptocurrency resources<\/a><\/li>\n<li><a href=\"\/news\/\">Latest CryptoLinks cryptocurrency news<\/a><\/li>\n<li><a href=\"\/bitcoin-wiki\">Bitcoin Wiki and crypto learning resources<\/a><\/li>\n<li><a href=\"\/915\/bitcoindeveloperguide\">Bitcoin Developer Guide review<\/a><\/li>\n<li><a href=\"\/blockchain-security\">Blockchain and Bitcoin Security<\/a><\/li>\n<li><a href=\"\/news\/secure-crypto-storage\">Secure Crypto Storage guide<\/a><\/li>\n<li><a href=\"\/mining-pools\">Best Bitcoin Mining Pools<\/a><\/li>\n<li><a href=\"\/crypto-guides-and-courses-know-how-info\">Crypto guides and courses<\/a><\/li>\n<li><a href=\"\/cryptocurrency-beginners\">Bitcoin and cryptocurrency guides for beginners<\/a><\/li>\n<\/ul>\n<h2>Sources and methodology<\/h2>\n<p>This analysis prioritizes primary technical and on-chain evidence. Mainnet status, scope and the miner-direct path were checked against StarkWare\u2019s August 26 QSB announcement and the public QSB implementation. Block height, timestamp, miner and transaction inclusion were checked against Bitcoin block data. BIP-360 status was checked against the Bitcoin BIPs repository. SHRINCS status and current signature parameters were checked against its current public draft specification and Blockstream Research material. NIST post-quantum standards are used only for context and are not presented as selected Bitcoin upgrades.<\/p>\n<p><em>Research and status cutoff: August 27, 2026. QSB, BIP-360 and SHRINCS are active areas of research and their specifications or implementation status may change after publication.<\/em><\/p>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>StarkWare researcher Avihu Levy\u2019s Quantum-Safe Bitcoin construction successfully spent a specially protected Bitcoin output on mainnet on August 26, 2026, without changing Bitcoin consensus or adding a new opcode. The 10,000-satoshi QSB output was mined through MARA after direct submission via Slipstream\u2014but the result is better understood as an experimental quantum \u201clifeboat\u201d than proof that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7147,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/comments?post=7138"}],"version-history":[{"count":5,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7138\/revisions"}],"predecessor-version":[{"id":7152,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/posts\/7138\/revisions\/7152"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/media\/7147"}],"wp:attachment":[{"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/media?parent=7138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/categories?post=7138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptolinks.com\/news\/wp-json\/wp\/v2\/tags?post=7138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}