Q-Day Field Notes: Bitcoin’s Quantum Bill Dropped 79% in a Week

An open contest run by StarkWare, Yukon Research and Eigen Labs cut the estimated cost of building a quantum-safe Bitcoin transaction from about 320 dollars to 67 in a week. That benchmark matters more than any Q-Day forecast - three notes on it, and two things people get wrong.
Q-Day Field Notes: Bitcoin's Quantum Bill Dropped 79% in a Week
The threat model is elliptic-curve cryptography, not a chip like this one. Photo: jurvetson / Flickr (CC BY 2.0)

Most Q-Day writing is about a date. The interesting number this week was a cost. StarkWare, Yukon Research and Eigen Labs ran an open competition on a narrow, unglamorous question: how cheaply can you build a Bitcoin transaction that a quantum computer could not forge? One week of open competition pulled the estimated cost from roughly $320 down to about $67 — a 79% cut — measured in GPU compute on the user’s own machine.

That figure is not a price, and it is not a physics breakthrough. It is a benchmark, and benchmarks are where engineering decisions actually get made. Three notes on it, two things people get wrong, and one honest limit.

Note 1: the $67 is a GPU bill, not a Bitcoin fee

Understand where the cost lives and everything else follows. To protect coins without changing Bitcoin’s consensus rules, StarkWare’s construction slots a hash where the network expects a signature. The catch is the shape of the output: only about one in 70 trillion hash results qualifies, so you hash and hash on your own hardware until one fits. None of that search happens on-chain. It happens on a GPU you pay for.

The first such transaction, mined on mainnet last month, took roughly 3,100 GPU-hours and about $320 to construct. Then solvers went to work on the code. One core benchmark went from 146 million verified candidates per second to more than 820 million on a single RTX 4090, with 62 improvements promoted across two tracks. Faster code means fewer GPU-hours for the same result — and that is the whole 79%.

Q-Day Field Notes: Bitcoin's Quantum Bill Dropped 79% in a Week
The expensive part of a quantum-safe transaction is a brute-force search on your own hardware, not a network fee. Photo: qubodup / Flickr (CC0)

Note 2: this is the kind of workload AI models are good at

The leaderboard was dominated by developers running AI models, with Anthropic’s Opus 5 and Fable 5.1 at the top and OpenAI’s GPT-6 Astra, Grok 4.6 and Kimi close behind. Once you look at the shape of the task, that is unsurprising: it is a bounded search with a loud, measurable success signal. Propose, test, keep the winner — the loop optimisation contests have run for decades, now executed faster and more cheaply.

Where I stay conservative is the extrapolation. Optimising a hash loop and designing a system are different problems. A model that finds a faster search has demonstrated something real about the cost of one primitive. It has not demonstrated that the same loop can decide whether Bitcoin should soft-fork, how a custody operation should be rebuilt, or who pays for migrating dormant coins. Those decisions still need people who carry the consequences.

Note 3: the schedule is political, which is exactly why it is worth insuring against

The European Union warned last week that Q-Day — the point at which a quantum computer can break the elliptic-curve cryptography protecting wallets — could arrive before quantum computers become commercially useful, and gave member states until the end of 2026 to plan for it. Read that the way an engineer reads a risk register: the probability is unknown, the loss is irreversible. When you cannot price the probability, you price the downside.

That is the logic behind both a post-quantum custody playbook at Coinbase and an open optimisation contest at StarkWare. Neither is a bet that Q-Day is imminent. Both are the recognition that the cost of acting has finally fallen low enough to be line-itemed in a budget.

Q-Day Field Notes: Bitcoin's Quantum Bill Dropped 79% in a Week
Cooling, vacuum and power budgets are what make quantum timelines genuinely hard to call. Photo: jurvetson / Flickr (CC BY 2.0)

Two things to get right

1. This does not make Bitcoin quantum-safe. StarkWare is explicit about the limits: the transactions are nonstandard, they must be sent directly to a miner, and the construction only shields coins whose public key has not already been exposed. The company still argues that a soft fork is the better long-term fix. A cheaper workaround is not a protocol upgrade, and anyone telling you Bitcoin is post-quantum today is selling you something.

2. $67 is an estimate under stated hardware assumptions, not a market price. It moves every time a solver beats a record, and it covers only the compute being measured. Treat it as a direction of travel — a curve bending down — not a quote.

Q-Day Field Notes: Bitcoin's Quantum Bill Dropped 79% in a Week
Q-Day is a lock-versus-key problem with a schedule attached. Photo: außerirdische sind gesund / Flickr (CC BY 2.0)

What I would actually watch

  • The curve, not the date. Track the record, the hardware assumptions behind it, and who keeps spending on it. A falling cost is the only durable signal in this debate; Q-Day forecasts have been wrong in both directions for a decade.
  • Who moves first in production. A custodian drafting a post-quantum playbook matters more than a conference talk about timelines. Custodians act when the numbers clear.
  • Whether the fix reuses an existing interface. Nonstandard transactions routed straight to a miner work today, but a soft fork touches every wallet. Watch which path teams actually build on — the cheaper path now is rarely the one that survives contact with the whole network.
  • What you already depend on without knowing it. Exposed public keys, long-lived multisigs and cold storage are where the practical risk sits today, not in cryptography that has not broken yet.

So here is the conclusion, stated plainly. The quantum threat to Bitcoin is less a question of when machines get strong enough than a question of how expensive it is to be ready — and that price is falling faster than most people expected. Every week that number drops is a week the industry’s excuse to postpone gets thinner. That is a better reason to act than any forecast, and unlike a forecast, it can be measured.

Markets, for their part, are not pricing any of this. Bitcoin traded near $83,500 with Ether near $2,650, and total market capitalisation held around $2.86 trillion. Quantum risk is the rare problem where the industry has plenty of time to prepare and almost no incentive to talk about it.


Method note: This piece follows the reading habits of Chinese engineer Chen Hao (左耳朵耗子, 1976–2023): trust measured benchmarks over confident narratives, trace where a number comes from before you repeat it, and say plainly which parts you are not sure about. Cost figures are StarkWare’s, under its own stated hardware assumptions; market data are snapshots taken on Sept. 28, 2026.

Disclaimer: This article is for informational purposes only and is not investment advice. The cost estimate discussed is a moving benchmark, not a market price, and the technical work described does not by itself make Bitcoin resistant to quantum attack. Always do your own research.

Track live prices, market rankings and the latest crypto news on BBVN Markets.

Bitcoin

Bitcoin's $500,000 Target Is Five Years Old and Still Two Years Away

2026-9-28 20:07:11

Bitcoin

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check

2026-9-28 3:04:26

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search