
Elon Musk has endorsed a fringe physics theory that suggests quantum computers can only reach a maximum of 200-400 qubits, potentially providing additional support for Bitcoin's quantum resistance. On August 29, Musk replied to an Institute of Art and Ideas post about Oxford physicist Tim Palmer's work, agreeing that the universe operates in fixed chunks rather than a smooth continuum. As reported by CoinDesk, investor Fred Krueger subsequently cited Musk's support, claiming that 'Bitcoin may already be quantum-safe' and referencing the latest estimates requiring at least 835 logical qubits to break Bitcoin's signatures with Shor's algorithm. Palmer's credentials include being a Royal Society fellow elected in 2003 and spending his career building weather forecasting models at Oxford, with his paper published in the Proceedings of the National Academy of Sciences in March. The theory argues that nature contains no smooth continuum, so quantum entanglement eventually hits a wall, with Palmer predicting this limit at 200-400 qubits on current hardware and never exceeding 1,000 qubits.
Bitcoin confirmed its first mainnet transaction using researcher Avihu Levy's Quantum-Safe Bitcoin (QSB) method on August 27, according to StarkWare and MARA Foundation. The transaction was successfully mined in block 964,199 and protected a 10,000 satoshi output worth approximately $8 at current prices, along with a fee of 5,179 satoshis. As reported by StarkWare, the mined transaction demonstrated that QSB can operate under Bitcoin's existing consensus rules without requiring new opcodes, a soft fork, or changes by Bitcoin nodes. The transaction was mined by MARA Pool through its Slipstream service, with the block confirmed on August 27. This marks the first successful demonstration of quantum-resistant Bitcoin transactions on mainnet, showing a workaround under existing rules while broader protocol-level protections remain under consideration.
The QSB transaction cost $150-200 and required several hours to complete, as reported by StarkWare spokesperson Nathan Jeffay. Creating a QSB spend involves searching for transaction parameters whose resulting RIPEMD-160 hash can be interpreted as a valid DER-encoded signature, requiring approximately 2462^46 hashing attempts. According to StarkWare's research paper, the search costs between ₹75-₹200 using cloud GPUs, with the research paper allowing a wider range of ₹75-₹200 for implementation uncertainty. These figures cover off-chain computation costs, not Bitcoin network fees, and each transaction requires its own search, though the work can be divided across several GPUs. QSB transactions exceed Bitcoin's standard relay policy limits and require direct submission to participating miners, bypassing ordinary mempool relay. The demonstration shows that Bitcoin's existing consensus rules can accommodate quantum-resistant spending, while broader protocol-level protections remain under consideration.
Currently, Bitcoin at rest, especially behind most modern wallet addresses such as Pay-to-Public-Key-Hash (P2PKH) and Native SegWit (P2WPKH), is quantum resistant as they only show a hash, which hides the public key on public blockchains. However, this makes reusing these addresses susceptible to theft if quantum computers arrive, as the moment one spends using these addresses, the actual key is revealed to the blockchain. As reported by AMBCrypto, this creates a gap that StarkWare's QSB scheme addresses by providing quantum-resistant protection during the spending process. The only current challenge to the QSB scheme is that it can only work with private mempools, which serve as a waiting room before miners validate or confirm transactions. This particular transaction was made possible by MARA's private mempool Slipstream service, though MARA Foundation's Isabela Foxen noted that private mempools are not an appropriate long-term solution for Bitcoin quantum resistance.
In parallel developments, cryptography researchers have published a draft specification for SHRINCS, a post-quantum signature scheme for Bitcoin transaction authorization. The draft, authored by conduition, Ethan Heilman, Mikhail Kudinov, Oleksandr Kurbatov, Jonas Nick, and contributor remix7531, describes a hash-based design that combines a compact stateful signing path with a stateless fallback. SHRINCS relies on the security of its underlying SHA-256 hash function and targets NIST security category 1, corresponding to 128 bits of classical security and 64 bits of quantum security. The scheme combines a compact stateful component called FXMSS with a larger stateless fallback based on a customized variant of SLH-DSA, producing signatures ranging from 548 to 4,619 bytes depending on selected tree structure. The stateless fallback has a fixed signature size of 5,777 bytes, while the combined public key is 48 bytes. Blockstream Research notes that a sufficiently capable quantum computer could recover a private key from an exposed public key and spend the funds it protects, making this work on post-quantum options essential before the threat materializes.
Despite the historic milestone and Musk's physics theory endorsement, the market is pricing only a 5% chance that a final network-wide post-quantum upgrade could happen this year, according to AMBCrypto. Adam Back's Blockstream has been actively working behind the scenes to fast-track post-quantum advancement, with the firm calling SHRINCS a 'very good trade-off' amongst current options for the final network-wide upgrade. However, the Bitcoin Improvement Proposal (BIP) for SHRINCS will need to be discussed, criticized, and improved before it can be adopted as the ultimate post-quantum upgrade. Eli Ben-Sasson, CEO of StarkWare, hailed the quantum-safe transaction as 'huge' for the path forward for the post-quantum era, emphasizing that while the accomplishment shows solutions can be found and implemented, the network needs to decide that this is the path forward. The current approach of quantum-safe transfers without a soft fork provides temporary protection while the network explores protocol-level changes for a comprehensive upgrade. Bitcoin's price action has remained largely unaffected, with BTC near $78,449 after a 1.17% daily gain, while developers continue working on post-quantum migration proposals with the real test arriving around 2029.