Markets

Bitcoin’s Quantum Fix Cannot Protect the Coins Most at Risk

An open contest cut the compute cost 79% in a week, to under $67. Cost was never what stood in the way, and roughly 6.9m BTC still cannot use it.

⏱ 3 min read Markets
Quick Summary
  • Google Quantum AI puts about 6.9m BTC in addresses whose public keys are already on-chain.
  • Coinbase's quantum advisory board counts 1.7m BTC in lost early keys, worth roughly $131bn.
  • StarkWare designed the method, co-runs the contest and produced the $67 estimate itself.

The cost of moving Bitcoin into quantum-resistant storage fell about 79% in a week, from roughly $320 of GPU compute to under $67.

That came out of an open optimisation contest and the engineering is genuine.

Cost was never the part stopping anyone.

What the Contest Achieved

The Quantum-Safe Bitcoin Optimization Challenge, run by StarkWare with Yukon Research and Eigen Labs, promoted 62 improvements across two tracks. Verification throughput went from 146 million candidates a second to more than 820 million on a single RTX 4090, cutting an estimated 3,100 GPU-hours down to a fraction of that.

StarkWare designed the underlying method, employs the researcher who published it, co-runs the contest and produced the cost estimate, so the figure is an interested party’s number. The company says so itself in unusually plain terms. The $67 is an estimate under stated hardware assumptions rather than a market price, it moves with every new record, and the work “doesn’t make Bitcoin quantum-safe on its own.”

The Coins It Cannot Reach by Design

The method, published in April by StarkWare’s Avihu Levy, grinds through candidate transactions until one produces a hash that is itself a validly formatted signature. Security shifts from elliptic curves, which a quantum computer breaks, to hash pre-image resistance, which it does not.

It only works while a coin’s public key is still hidden behind an address hash. Once the key is on-chain, an attacker has what they need before any protective transaction is broadcast.

A Google Quantum AI paper from March puts roughly 6.9 million Bitcoin in addresses whose public keys are already visible. Early pay-to-public-key outputs expose keys from creation. Reused addresses expose them at the first spend. Taproot, the most recent common format, publishes the key by design.

Those are the coins a quantum adversary reaches first, and they are the coins this technique cannot touch at any price.

No Owner Left to Pay

Coinbase’s Independent Advisory Board on Quantum estimates about 1.7 million Bitcoin sit in some 20,000 early public-key outputs that are Satoshi-era or otherwise lost, worth in the region of $131 billion, with no recovery possible.

Protection requires the owner to authorise a transaction. Where the owner is gone, the price is irrelevant. A 79% discount changes nothing for the single largest concentration of exposed coins on the network.

Getting In Means Stepping Outside

For eligible coins the path is still awkward. Moving them into protection means first broadcasting an ordinary transaction, which publishes the public key while it confirms, so the migration briefly opens the window it exists to close.

The protective transaction is also nonstandard and will not travel the ordinary mempool. August’s mainnet demonstration reached a block through MARA’s Slipstream service, and it moved 44,000 satoshis, around $35, at a compute cost in the hundreds.

StarkWare’s own position is that a soft fork remains the better long-term answer. The proposal in play is BIP-360. The contest solved what compute could solve, and left the part that needs consensus exactly where it was.

⚖️ Our Verdict ⚖️ Watch and Wait

The optimisation is real work and a 79% cost cut in a week is a genuine result. It just relieves the constraint that was not binding. The technique cannot protect coins whose public keys are already published, which is where the exposure concentrates, and it cannot protect lost coins at all because nobody is left to sign. The protocol fix still needs a soft fork.