Partner · Blockchain Life 2026 — Dubai, December 1–2 · 15,000+ attendees from 130+ countriesGet tickets →
LIVE
BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—
—▲0.0%
Bitcoin

Quantum-Safe Bitcoin Transaction Cost Falls 79% to About $67

27 Sept 2026by CryptoJazz Admin1 min read8 views
Quantum-Safe Bitcoin Transaction Cost Falls 79% to About $67

The estimated cost of assembling a quantum-safe Bitcoin transaction fell by 79% in one week, to roughly $67 of GPU compute from about $320. The drop came out of the Quantum-Safe Bitcoin Optimization Challenge, an open contest StarkWare started on 16 September with Yukon Research and Eigen Labs, which promoted 62 improvements across two computational tracks. Every cost figure in this story originates with StarkWare, which set the contest and the hardware assumptions behind the estimate. The gains were measured on benchmarks. No transaction has been built at the new price.

What the contest was optimizing

The technique underneath it is signature grinding, and this desk covered it when StarkWare said a quantum-safe Bitcoin transaction had been mined on mainnet in August. Coins sit in an output locked by a hash instead of an elliptic-curve key, and a machine searches off-chain until it stumbles on a transaction whose hash Bitcoin will accept as a well-formed signature. Nothing is signed with a private key, so Shor's algorithm has nothing to break. The search is the expensive part, and the contest attacked it. The Quantum Insider describes the target as a hash output shaped like a DER signature, with about one in 70 trillion hashes taking that shape. That ratio sits in one account.

Two numbers off a graphics card

Both tracks are throughput problems and both moved a long way. On transaction pinning, verified candidates per second on an RTX 4090 went from 146.09 million to more than 820 million, a pair The Quantum Insider and Blockonomi both publish and Decrypt gives in rounder form. Subset selection improved about tenfold, from roughly 62 million operations per second to over 623 million, which The Quantum Insider puts at 623,518,629 exactly. Twenty-three solvers worked the pinning track and 17 the subset track as of 23 September, on that outlet's count alone.

AI models did much of the work, the part Decrypt led on when it filed on Saturday. Opus 5 and Fable 5.1 held the top of both leaderboards, a detail Decrypt and Blockonomi agree on. Decrypt alone also names GPT-6 Astra, Grok 4.6 and Kimi among the entrants. StarkWare's own leaderboard was not fetched, so the standings here are outlets reading it.

The August baseline does not settle

Where $320 comes from is worth pinning down, because this desk published different figures a month ago. In late August, Avihu Levy's repository put the off-chain computation at $75 to $150 a transaction, and StarkWare described the transaction actually mined as costing several hundred dollars. The $320 now used as the starting point sits inside StarkWare's range and well outside Levy's. None of the four accounts read for this story mentions the repository estimate, and we could not establish which figure supersedes which. The new cost is quoted with small variations too, $66 to $67 by Cointelegraph and under $67 elsewhere.

"A construction that costs a few hundred dollars per transaction is a demo. One that costs $67 is closer to something a holder with a large unexposed balance might reach for in an emergency," StarkWare said.

A soft fork is still the ask

Cheaper does not mean usable. The transactions are non-standard, so ordinary nodes will not relay them and each one has to go to a miner directly. The method reaches only coins whose public keys have never appeared on the chain, which rules out every reused address. StarkWare says plainly that the gains "have only been shown in benchmark tests, not in real transactions," and Decrypt carries the same caution in different words, that the $67 is an estimate under stated hardware assumptions and not a market price. All four accounts have the firm still arguing that a soft fork is the better long-term answer.

The research around the threat keeps moving in both directions. A crowdsourced challenge earlier this year cut the estimated quantum resources for attacking secp256k1 by 86%, and its authors were careful to say they had not built an attack. Two contests, two sets of numbers, and both sides of the problem got cheaper. What neither has produced is a date.

Read also: Ripple Sets Out a Four-Stage Path to a Quantum-Safe XRP Ledger

← All news