AI Optimization Cuts Estimated Quantum-Safe Bitcoin Cost to $66
The estimate fell from about $320 after a weeklong open-source challenge, but the improved code has not yet prepared another transaction confirmed by Bitcoin miners.

The estimated computing cost of preparing a Quantum-Safe Bitcoin (QSB) transaction has fallen to $66 from about $320 after a weeklong open-source challenge accelerated the transaction-search process.
The estimate covers computation performed before a transaction reaches the Bitcoin network and excludes network fees. The first QSB transaction was mined and confirmed Aug. 26 after requiring about 3,100 GPU-hours across roughly 100 GPUs.
The challenge focused on two computational steps: pinning and subset selection. A record pinning submission verified 881,273,403 candidates per second on an RTX 4090 graphics card, compared with about 146 million candidates per second in the starting code. That represented a 503% increase. Subset selection improved 906%.
The pinning track recorded 34 accepted entries from 24 participants, with most participants using artificial intelligence programming tools. The optimization results are summarized in TokenPost’s earlier coverage of the estimated QSB cost reduction.
QSB uses a process called signature grinding. The sender searches for a transaction whose hash meets the format required for a valid Bitcoin signature. This shifts the security challenge from protecting a private key to performing a difficult reverse-hash search.
The process operates under Bitcoin’s existing rules and does not require a soft fork. The additional computation takes place before the transaction is broadcast, creating the extra preparation cost.
The $66 figure remains an estimate based on simulated performance from 100 RTX 3090 GPUs and speed improvements measured over 1,200 seconds. Later RTX 4090 results exceeded the measured cutoff, but the improved code has not yet been used to prepare another transaction that Bitcoin miners included in a block.
QSB transactions also use a nonstandard format and must be sent directly to a miner rather than through the ordinary mempool. The method cannot protect addresses whose public keys have already been exposed because a quantum attacker could attempt to derive the private key before a transaction is broadcast.


