Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,447▲ 0.63%ETH$2,698▲ 0.39%SOL$121.01▲ 0.26%TOTAL CRYPTO$2.9T▼ 2.34%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.62▼ 3.26%GOLD4,321.20▼ 7.95%WTI92.41▲ 12.20%BRENT97.44▲ 10.00%EUR/USD1.1401▼ 2.29%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

AI Coders Cut Quantum-Safe Bitcoin Cost From $320 to $66

A week-long StarkWare contest, with AI models leading the leaderboard, cut the estimated GPU cost of a quantum-resistant bitcoin transaction by about 79%.

The estimated cost of building a quantum-safe bitcoin transaction fell from about $320 to roughly $66 in a single week, according to StarkWare, whose open optimization contest drew developers and AI models racing to speed up the underlying code.

The first quantum-safe bitcoin transaction was mined on mainnet in August. Building it took roughly 3,100 GPU-hours across a fleet of about 100 graphics processors, a computing bill of about $320 before any network fee. StarkWare, which developed the construction with Yukon Research and Eigen Labs, opened the code to a public competition on Sept. 16 with $20,000 in prizes. One week later, the contest dashboard showed the estimated cost down to $66.

The expensive step is an off-chain brute-force search for a hash that happens to be shaped like a valid bitcoin signature. Faster search code means fewer GPU-hours, so the contest focused on two computational stages: pinning and subset selection. A record pinning submission verified about 881 million candidates per second on an RTX 4090 graphics card, against roughly 146 million for the starting code, a gain of more than 500%. Subset selection improved by about 900%.

The leaderboard itself became a story. StarkWare said the leading records were held by developers running AI models, with Anthropic’s Opus 5 and Fable 5.1 at the top and OpenAI’s GPT-6 Astra, Grok 4.6 and Kimi close behind. Each submission is rerun on a CPU and verified before it counts. Solvers landed 62 promoted submissions across the two tracks.

Why quantum safety matters

Bitcoin’s current security model exposes public keys when coins are spent. A sufficiently powerful quantum computer could use an exposed public key to derive the private key and steal the funds. Estimates of when such machines will exist vary widely, but the security community treats the risk as serious enough to plan for years ahead of any demonstrated break.

StarkWare’s method, called quantum-safe bitcoin, adds hash-based protection that is expected to withstand that attack, and it works entirely within bitcoin’s existing rules. No soft fork or network upgrade is required to use it. That design choice matters, because consensus changes on bitcoin are slow and contentious, and a fix that depends on one could arrive after the threat does.

That makes the construction an emergency option rather than a permanent fix. StarkWare is explicit about the limits. The transactions are nonstandard and must be sent directly to a miner rather than through the normal network relay path. The construction only protects coins whose public keys have not already been exposed, which excludes the cohort a quantum attacker would reach first. And the company still favors a soft fork as the long-term answer.

“This effort does not make Bitcoin quantum-safe,” the company wrote. “It makes one emergency option cheap enough to keep on the shelf.”

An estimate, not a price

The $66 figure comes with caveats. It is an estimate derived from benchmark performance, not a demonstrated cost. The improved code has not yet been used to prepare another transaction that bitcoin miners included in a block. Applying the speedups listed on the contest site to the original $320 cost breakdown yields about $83 by CoinDesk’s calculation, with later record-setting runs going beyond the measured results to reach the lower dashboard figure. The estimate also moves every time a solver beats the record.

The benchmark reproduces what the grinding core demands of a GPU but builds no real bitcoin transactions, so a speedup there still has to be tested against the production implementation. StarkWare’s own dashboard notes apply the measured speedups directly to what the August transaction actually cost, under stated hardware assumptions.

Cost still matters. A construction that costs a few hundred dollars per transaction is a demonstration. One that costs $66 is closer to something a large holder with an unexposed balance might actually reach for in an emergency. At the August price, moving a meaningful treasury through the method would have been impractical for all but the largest holders. The gap between a demo and a tool narrows with each optimization round.

The format mirrors ECDSA.fail, an earlier open leaderboard whose contributors cut the estimated quantum cost of one step in attacking bitcoin’s signatures by 86%. Both projects treat the quantum question as a race between attack and defense, with public scoreboards replacing closed research. In both cases, AI-assisted coding compressed timelines that would previously have taken research teams months.

StarkWare first published the quantum-safe construction in April, when the estimated cost stood at about $200 per transaction. The August mainnet transaction pushed the demonstrated figure to $320, and the contest has now pulled the estimate below $70. The company said it expects the number to keep moving as the challenge continues.

For bitcoin holders, the practical takeaway is narrower than the headline. Coins held at addresses whose public keys are already visible on-chain get no protection from this method. Coins that have never been spent from remain eligible. Anyone planning to rely on the emergency option would also need the technical capability to construct and submit the nonstandard transaction directly to a miner, a step that requires coordination well beyond a normal wallet transfer.

The broader lesson may matter more than the specific number. An open contest with a modest prize pool, staffed partly by AI coding agents, produced a 79% cost reduction in seven days. The same approach is now being discussed for other open cryptography problems, and StarkWare has not ruled out further challenges on related constructions.

SourcesCoinDesk; StarkWare blog; Decrypt; Unchained; TokenPost
Share: X