An open competition run by StarkWare, Yukon Research, and Eigen Labs has driven the estimated cost of building a quantum-safe Bitcoin transaction from about $320 down to roughly $67. The three organizers ran the contest openly, and AI models finished at the top of the leaderboards.
The number matters because quantum-safe signatures are bigger and heavier than the elliptic-curve cryptography Bitcoin uses today. Getting a single transaction down to double-digit dollars is the difference between a theoretical upgrade path and one that might actually be deployable.
What the competition actually measured
The target was the estimated cost of a quantum-safe transaction on Bitcoin — not a testnet demo, not a proof-of-concept paper, but a cost figure the organizers put a dollar amount on. Entrants competed to bring that figure down.
They did. The starting estimate sat around $320. By the end, the best entries were landing near $67. That's roughly an 80% reduction, and it happened inside a single contest window rather than over years of incremental protocol research.
The organizers haven't published a full breakdown of which techniques produced the biggest savings, so it's not yet clear how much of the gain came from signature aggregation, how much from witness discounting tricks, and how much from smarter use of existing Bitcoin script. That detail will matter to anyone trying to replicate the result outside a competition setting.
AI models took the top spots
The leaderboards were topped by AI models. That's the part of the result that will get the most attention, and for good reason — it suggests that at least some of the optimization work here is the kind of search problem that machine-driven methods handle well.
It also raises an obvious question the organizers haven't answered: whether the winning approaches generalize, or whether they're tuned to the specific scoring function the contest used. A competition is a closed world. Bitcoin mainnet is not.
Why the cost figure is the whole story
Bitcoin's quantum exposure is well understood in outline. A sufficiently capable quantum computer could, in theory, derive private keys from exposed public keys, and the network's current signature scheme offers no protection against that. The hard part has never been agreeing that the problem exists. It's been making a fix cheap enough that miners and node operators would accept it.
Post-quantum signature schemes are larger. Larger signatures mean more block space, and more block space means higher fees per transaction. If a quantum-safe transaction costs hundreds of dollars, the migration conversation stalls. At $67, it's still expensive by ordinary Bitcoin standards, but it's in a range where the tradeoff can at least be argued.
That's the real output of this contest. Not a deployed upgrade, not a consensus change, not a soft fork on the horizon — a lower bound on what the migration might cost, produced in public, with AI systems doing much of the work.
What's still missing
There's no published timeline for turning any of this into a Bitcoin Improvement Proposal, and no indication that StarkWare, Yukon Research, or Eigen Labs intend to push one. The competition produced numbers, not a roadmap.
The open question is whether the $67 figure survives contact with real network conditions — adversarial mempools, varied node policies, and the messy reality of a chain that can't be reset for a clean benchmark. Until someone runs that experiment, the contest result stands as a strong estimate rather than a proven cost. The organizers have not said whether a follow-up round is planned.




