AI-Assisted Coding Cuts Quantum-Safe Bitcoin Cost from $320 to $66
A one-week open competition combining AI coding tools with Bitcoin's quantum-safe transaction method cut estimated GPU compute costs from $320 to $66. The number is a benchmark, not yet mainnet proof, but the velocity matters.

One week of open, AI-assisted competition just moved quantum-safe Bitcoin from exotic research to something approaching an actionable emergency tool.
Key takeaways
- StarkWare, Yukon Research, and Eigen Labs ran a one-week coding challenge that produced 62 accepted improvements, lifting throughput from roughly 146 million to 881 million candidates per second on the same benchmark GPU.
- The estimated GPU compute cost of a quantum-safe Bitcoin transaction dropped from $320 (the verified cost of the August 26 mainnet transaction) to $66 per Yukon's live dashboard, though this figure has not yet been demonstrated in a second mined transaction.
- QSB works inside Bitcoin's existing rules today with no soft fork required, but transactions must be submitted directly to a willing miner and cannot protect coins whose public keys are already exposed on the network.
StarkWare announced September 23 that a one-week open competition cut the estimated GPU compute cost of preparing a quantum-safe Bitcoin transaction from roughly $320 to $66, first reported by CoinDesk. The improvement came from 62 accepted code submissions, many built with AI coding tools, that made the underlying search process approximately six times faster on identical hardware.
The $320 figure was real and documented. On August 26, 2026, the first quantum-safe Bitcoin transaction was mined at block 964,199, submitted through MARA's Slipstream service, requiring roughly 3,100 GPU-hours across about 100 graphics processors. That cost was the compute work done before the transaction hit Bitcoin's network, separate from the on-chain fee. The $66 figure comes from the Yukon Research live leaderboard and is a benchmark projection, not a verified second transaction.
One honest number to hold alongside it: CoinDesk's own back-of-envelope math applying the competition speedups to the original $320 cost breakdown yields roughly $83, not $66. The gap likely reflects how benchmark conditions translate to real-world GPU utilization. Both numbers represent a dramatic reduction; neither should be reported as a proven mainnet cost until a second transaction is actually mined.
What the Competition Actually Demonstrated
StarkWare launched the QSB Optimization Challenge on September 16 alongside Yukon Research and Eigen Labs, offering a prize pool of over $20,000. The challenge targeted two computational tasks: pinning and subset-selection, the core bottleneck in the original method designed by StarkWare researcher Avihu Levy.
The leading submission hit approximately 881 million candidates per second against roughly 146 million for the starting code, on the same NVIDIA RTX 4090 benchmark GPU. That is a roughly 6x throughput improvement in one week of open, permissionless development.
Levy originally described QSB as a "last resort measure" when he published the design in April 2026. That framing made sense at $320 per transaction. At $66 and falling, the calculus changes. This is closer to a usable emergency bridge for holders with exposed public keys who cannot wait for the network to coordinate a soft fork.
StarkWare CEO Eli Ben-Sasson has framed QSB in terms of lifeboats, saying on August 26: "What Avihu has illustrated is that there are lifeboats. That is not a reason to relax. It is a reason to build more of them, and to build them now." The long-term preferred fix for both Levy and StarkWare is a protocol-level soft fork, not QSB as a permanent solution.
The Cypherpunk Use of AI
The same week debates about AI as a surveillance and control tool dominate headlines, an open competition with AI-assisted builders just delivered a roughly 6x speed improvement on Bitcoin's quantum defense. The result was open code, a prize pool, and no institutional mandate required.
The timeline compounds that point. From Levy's April paper to the first mainnet transaction took roughly four months. From that first transaction to a 6x throughput gain took one week of open competition. That is the pace of decentralized, incentivized development, and it matters to anyone tracking whether Bitcoin can actually adapt before a quantum threat becomes operational.
Chinese researchers have pushed the quantum attack benchmark against secp256k1 forward this year. The threat is not imminent at current hardware trajectories, but the window is finite. What this week demonstrated is that Bitcoin's builder community is not waiting around.
The falsifiable thesis: open, AI-assisted development is closing the cost gap fast enough to make QSB a practical emergency tool before quantum hardware crosses the threshold. The trigger that breaks it is straightforward. If the $66 benchmark cannot be reproduced in an actual mined transaction, or if no miners beyond MARA prove willing to process QSB transactions at scale, the "engineering-solvable" framing reverts to interesting research with no practical path to deployment.
What to Watch
The next data point that matters is a second mined QSB transaction with a verified compute cost. Until that number is on-chain, $66 is a benchmark target, not a proof. Watch the Yukon leaderboard for further throughput improvements and for any announcement of additional miners accepting QSB submissions outside MARA's Slipstream service.
Sources
Frequently Asked Questions
What is Quantum-Safe Bitcoin (QSB) and how does it work?
QSB is a method designed by StarkWare researcher Avihu Levy that lets a Bitcoin holder move funds using a hash-based signature scheme instead of the standard ECDSA signature vulnerable to quantum attack. The process requires an intensive pre-computation step (the GPU "grinding" that costs $66-$320) to find a valid transaction that meets the requirements, after which the transaction is submitted directly to a miner for inclusion in a block. It works inside Bitcoin's existing consensus rules with no protocol upgrade required.
Can Bitcoin holders use this today, and which coins qualify?
Technically yes, with significant constraints. A holder must find a miner willing to accept a non-standard transaction submission (currently MARA via Slipstream), pay the associated GPU compute cost, and pay the on-chain fee.
Critically, QSB can only protect coins whose public keys have not yet been exposed on the network. Any address that has already sent a transaction has an exposed public key and cannot be protected by this method. Coins sitting in addresses that have never spent (where only the address hash is public) are the eligible candidates.
Does this eliminate the need for a Bitcoin soft fork to become quantum-resistant?
No. QSB is an emergency bridge, not a network-wide fix. StarkWare and Levy both continue to advocate for a protocol-level soft fork as the proper long-term solution.
QSB addresses the specific case of individual holders who need to move funds before network-wide quantum resistance is deployed. It does not protect the broader Bitcoin network or coins held in already-exposed addresses.


