Bitcoin's Quantum Debate Just Moved From Paper to Mainnet

A hash-based bitcoin spend reached mainnet under current rules, giving quantum alarmists a reason to turn the volume down while developers work on a better signature scheme.

9 min read
Bitcoin's Quantum Debate Just Moved From Paper to Mainnet
Share
TFTC - Truth for the Commoner

Bitcoin Brief

Sup, freaks.

An experimental QSB spend was mined on mainnet this week without changing bitcoin's consensus rules. If you have been losing sleep over quantum computers stealing every exposed coin, take a breath. We now have a mainnet example showing that bitcoin can be moved into a hash-based construction designed to resist a quantum attack under rules nodes already enforce.

I am still firmly in the skeptic camp. I do not think a cryptographically relevant quantum computer is right around the corner. I am not convinced one is possible at all. But never short human ingenuity. AI should have taught us how stupid confident technology forecasts can look a few years later, and nobody knows what new possibilities will emerge as these models become more capable.

Let's dig in.


LEAD STORY

Bitcoin's Quantum Debate Just Moved From Paper to Mainnet

Transaction 305a24ff...ab07 sits in block 964,199. It is a 1,321-vbyte spend built with Quantum Safe Bitcoin, or QSB, a research construction from Avihu Levy and Tom Giladi that uses bitcoin's existing Script rules and is designed to protect a deliberately created output under hash-based assumptions instead of depending on the hardness of secp256k1.

This should help quiet the quantum alarmists. Moving bitcoin into a construction designed to resist a quantum attack is no longer an idea that exists only in a paper or mailing-list thread. It happened on mainnet.

Bitcoin signatures today rely on elliptic-curve cryptography. A cryptographically relevant quantum computer running Shor's algorithm could, in theory, derive a private key from a revealed public key. Nobody has built that machine. Nobody can give you an honest date for when one will arrive. The threat is still worth preparing for because cryptographic migrations take years, and bitcoin cannot afford to improvise one under fire.

I sat down with Jonas Nick and Mikhail Kudinov for TFTC #700 at the end of last year to walk through this. Jonas made a point that stuck with me. He studied AI and once thought the field was going nowhere. Then ChatGPT happened. Quantum computing is a very different technology, but his warning was simple: be careful when people confidently declare that a breakthrough has no clear path and may never arrive.

My takeaway from that conversation was equally simple. Bitcoin's signature scheme will eventually need another upgrade. When that work happens, we should shoot for the best of both worlds: a better signature scheme that also gives bitcoin quantum resistance. That is a much bigger job than writing down a clever cryptographic construction. Consensus, wallets, hardware devices, derivation standards, custody systems, exchanges, and every other piece of infrastructure built around today's keys and signatures will have to move with it.

QSB found a weird route through rules we already have.

The construction uses a HORS-like one-time signature and a hash-to-signature puzzle inside legacy Bitcoin Script. ECDSA still appears in the machinery because OP_CHECKSIG is one of the tools available to Script, but the authors' security claim rests on hash preimage resistance rather than the elliptic-curve assumption a quantum computer would attack.

No soft fork. No new opcode. No committee meeting. A miner accepted the transaction and bitcoin validated it under the rules every node already enforces.

Bitcoin developers should pay attention to that.

It also exposes the limits. The transaction was non-standard under default relay policy, so it did not move through the normal peer-to-peer mempool. It reached a miner through MARA's Slipstream service. The construction protects bitcoin intentionally committed to this unusual script. It does not reach backward through time and protect every exposed public key on the UTXO set. It does not give wallets a usable address format, recovery flow, multisig policy, derivation standard, or migration path. It does not answer what happens to coins that never move before a capable quantum machine arrives.

Levy called it a “research quirk”, which is exactly right. The design crossed the line from a paper into consensus-valid bitcoin. I would not confuse that with a ready-made path to post-quantum security.

The good news is that there are a number of teams working on this problem. Jonas and Mikhail described active implementations and benchmarking efforts around hash-based schemes. BIP 360 continues to develop a soft-fork path. QSB has now put another approach through a real mainnet spend. Material progress is being made without anybody panic-shipping a consensus change.

That is where I land. I remain skeptical that a quantum computer capable of attacking bitcoin is close, if it is possible at all. I also refuse to bet against human ingenuity, particularly when no one knows what increasingly capable AI models will enable researchers to discover. Give the developers time to compare the trade-offs, improve the signature scheme, and get the migration right.

The alarmists can turn the volume down. The work is happening. My bet is that bitcoin has plenty of time, and every experiment like this makes that bet safer.


SIGNAL

LIGHTNING SECURITY

Core Lightning Prepares an Emergency Release After Real Vulnerabilities Surface

Core Lightning says a flood of AI-generated CVE reports included several real vulnerabilities. The team is preparing signed emergency binaries, with source and reproducible builds to follow after the immediate operator response.

No patched release had appeared on the project's GitHub release page as of 9:26 a.m. ET. Core Lightning's advice is to upgrade promptly when the signed binaries land. Operators who cannot upgrade immediately should restart with --offline, which closes peer connections while leaving the daemon running to watch the chain. Shutting a node down completely removes that monitoring.

Details remain embargoed, so do not guess at exploit mechanics or affected balances. Watch the official account, verify the release signature, upgrade, remove the offline flag, and confirm the node reconnects.

AI-generated vulnerability reports are noisy. This batch was not empty noise. Operators should treat the maintainer warning as an incident, not content.


AI POWER

Nvidia Reportedly Moves to Buy the Open-Model Distribution Layer

TechCrunch relays competing reports: The Information says Nvidia agreed to buy Hugging Face for $12.9 billion, while Business Insider says the talks had not produced a signed agreement and could still fall apart. Neither company had confirmed a transaction as of Thursday morning. Treat this as a developing M&A report, not a signed or closed deal.

Nvidia already dominates much of the accelerator and software stack used to train and serve AI. Hugging Face is where a large part of the open-model world discovers, distributes, tests, and deploys models. Owning that hub would pull Nvidia closer to developers and workloads just as Chinese accelerators and open models create more alternatives to Nvidia silicon at inference.

Yesterday's Ox Alpha story showed that substitution is already happening inside China. If this deal is confirmed, Nvidia would own the market square where open AI gets distributed instead of relying on another chip cycle.

Hardware margins created the war chest. Distribution is where Nvidia may try to defend the empire.


PUBLIC HEALTH

Shapiro Is Using a Measles Scare to Push More State Power

Pennsylvania's Department of Health labeled two Lancaster County deaths “measles-associated,” even though the department admits that label does not mean measles was the certified cause. County Commissioner Josh Parsons says, after speaking with Coroner Steve Diamantoni, that the coroner had identified zero deaths caused by measles. Shapiro's health bureaucracy chose the scarier label anyway.

When Nicolas Hulscher joined me on TFTC #728, we talked about what happens when health institutions destroy their own credibility. I think the political play is obvious. Shapiro and Pennsylvania Democrats are stoking fear before the midterms while pushing Orwellian health rules that would expand state access to homes, schools, medical records, vaccine data, and private student interviews. The Amish should be particularly alarmed. They have maintained a deliberate distance from the state for generations, and the proposal itself points to Amish vaccination patterns. This looks like an attempt to break that isolation and drag them deeper into a surveillance regime they never asked for. It is deeply wrong. Public health does not give politicians a blank check to invade privacy, civil liberties, or bodily autonomy.


NUCLEAR POWER

Radiant Says It Won an Army Agreement for 15 Portable Microreactors

Radiant says the Army and Defense Innovation Unit executed a binding Janus agreement worth up to $750 million to develop and deploy 15 Kaleidos microreactors by 2030. The company says the Army evaluated design maturity, manufacturing readiness, deployment strategy, and commercial viability before selecting the one-megawatt portable reactor.

Until the agreement and milestone schedule are public, treat the ceiling as contingent program value, not cash already obligated or fifteen operating reactors. Public Army and DIU materials establish the Janus program and Radiant's earlier eligibility, but do not disclose the new agreement's initial obligation. Delivery, licensing, fueling, site preparation, testing, and acceptance still stand between an award and electrons.

Jamie McAvity and I discussed the generation bottleneck on TFTC #758. The United States cannot add AI loads, harden military bases, and rebuild industry while strangling reliable generation. Portable nuclear will now get a real procurement test.

Good. Build the reactors. Publish the milestones. Let performance settle the argument.


ENERGY SECURITY

The Netherlands Is Cementing Away Its Gas Optionality

The Netherlands is permanently plugging and dismantling Groningen's former production wells after legally ending extraction in 2024. The shutdown followed decades of production-induced earthquakes, property damage, and safety concerns. Dutch regulators warn that earthquakes may continue while the depleted reservoir stabilizes.

Europe is making this decision inside a less secure energy system. Ending extraction is one thing. Permanently plugging the wells makes a restart through them impractical and sacrifices optionality that a future government may desperately want under different technology, compensation structures, security threats, or public consent.

Anas Alhajji told me on TFTC #779 that “everything boils down to energy dominance.” Europe keeps demonstrating the inverse. It outsources production, increases dependence on imported LNG, and then destroys domestic optionality in the name of finality.

Energy policy should price the damage. It should not pretend future scarcity is impossible.


Sponsored

Bitkey

Bitkey is self-custody with no seed phrase, no single point of failure, and recovery and inheritance built in.

Disclosure: Sponsored by Bitcoin at Block. Bitkey is not available in New York. Bitcoin is a non-deposit, non-bank product, is not FDIC insured, and involves risk, including monetary loss. See the Bitcoin disclosures.

Get Bitkey
Sponsored

Salt of the Earth

Salt of the Earth makes electrolyte drink mixes containing sodium, potassium, magnesium, and calcium, with flavored and unflavored options.

Shop Salt of the Earth

⚡ FREEDOM TECH CORNER

Audit the Quantum Safe Bitcoin Prototype

The QSB repository includes the paper, Bitcoin Script, CUDA search code, transaction pipeline, and consensus-verification tools behind the mainnet proof. The project is open source and explicitly a work in progress.

Cryptography improves under hostile review. Developers should inspect the security model, policy assumptions, GPU implementation, and transaction construction before repeating the headline. Do not use the prototype to protect meaningful funds. Use it to sharpen bitcoin's post-quantum research.


DATA SNAPSHOT

As of August 27, 2026, approximately 9:26 a.m. ET

bitcoin price~$79,460
Sats per dollar~1,258
Block height964,302
Recommended next-block fee2 sats/vB
Three-day network hashrate~890 EH/s
Projected next difficulty adjustment+0.50%
Next retarget height965,664

Sources: Coinbase for spot price; mempool.space for block, fee, hashrate, and difficulty data.

TFTC Roundtable

An experimental QSB spend just landed on mainnet without a fork. Does it narrow bitcoin's migration path or prove that the weirdest corners of Script still have more room than we thought?

Join the Roundtable

⚡ Looking for a wallet, node, miner, or backup tool?
Browse BitcoinProducts.com

See you tomorrow. Nothing here is investment advice. Do your own research.


YouTube: https://www.youtube.com/@TFTC

podcast: https://www.tftc.io/tag/podcasts/

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.