Yukon & StarkWare unlock quantum 80% drop in Bitcoin costs

Yukon Research and StarkWare report a nearly 80 percent reduction in the cost of quantum-safe Bitcoin transactions within a single week. A quantum-safe Bitcoin transaction now requires approximately $67 in GPU compute, a dramatic decrease from the $320 cost of the first such transaction mined just one month ago. The speedup stems from the Quantum-Safe Bitcoin Optimization Challenge, where transaction pinning now runs at over 820 million verified candidates per second on an RTX 4090, up from a baseline of 146.09 million.

AI Competition Achieves 79% Reduction in Quantum-Safe Bitcoin Costs

The challenge’s dashboard calculates the estimate by applying measured speed improvements to the cost of the August transaction, demonstrating a tangible link between optimization and affordability. Subset selection has gone from about 62 million to 623,518,629, a little over ten times faster. The most successful optimization approaches in the challenge have come from the models Opus 5 and Fable 5.1, with GPT-6 Astra, GPT-5.6, Grok 4.6 and Kimi close behind on both leaderboards. The results and submission details are available at qsb.fast, and further information on StarkWare’s quantum work can be found at quantum.starkware.

GPU Performance Gains Drive Down Transaction Pinning and Subset Selection

Subset selection now completes in a fraction of the time previously required, reaching 623,518,629 operations per second as of September 23, a more than tenfold increase from the initial 62 million. This acceleration demonstrates a significant refinement in the process of identifying valid transaction candidates, directly impacting the overall cost of quantum-safe Bitcoin transactions. The Quantum-Safe Bitcoin Optimization Challenge encouraged this speedup by allowing participants to build upon previously verified solutions, rather than restarting from scratch with each attempt.

This iterative approach, where each improvement becomes the new baseline, rapidly drove down computational demands. A month prior, the first such transaction required around $320, highlighting a nearly 79 percent reduction in cost within a short timeframe. This cost reduction is not solely attributable to increased computational throughput; submissions undergo rigorous verification, ensuring that speed gains are achieved through genuine optimization and not by circumventing necessary calculations.

Each kernel is re-derived on a CPU reference implementation and checked against expected results, preventing shortcuts that would compromise security. 6, Grok 4.6 and Kimi. Seven contributors from StarkWare and the Starknet Foundation are co-authors on a September paper detailing these advancements, signaling a commitment to both reducing attack costs and bolstering defensive measures.

StarkWare Pursues Crypto Agility for Bitcoin & Starknet Quantum Defense

This rapid decrease in cost is a direct outcome of focused optimization efforts targeting the underlying processes. The benchmark used to measure this cost replicates the demands placed on a GPU, though it does not itself create Bitcoin transactions, meaning improvements must still be validated within a live network. The company acknowledges that a soft fork remains the preferred long-term solution for widespread quantum protection on Bitcoin, but views this work as an important interim step.

StarkWare frames the problem as extending beyond Bitcoin itself, noting that any blockchain authenticating with elliptic-curve signatures shares the same vulnerability. Crypto agility, the speed with which a network can replace a compromised cryptographic primitive, will ultimately determine its resilience, and StarkWare’s existing hash-based proof system offers a distinct advantage in this regard.

While not achieving full quantum-safety for Bitcoin, the project demonstrably lowers the cost of building a functional response, the company says. The initial week of the optimization challenge operated under a separate prize structure, ensuring that subsequent improvements build upon a continually refined baseline. StarkWare is simultaneously working to reduce both the cost of launching a quantum attack and the cost of defending against it, with the difference representing the available preparation time. Further information on the company’s quantum work is available at quantum.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: