Prohibit Merkle Internal Node Preimages That Encode Minimal 64-Byte Transactions

Posted by Antoine Poinsot

Jun 1, 2026/18:49 UTC

The discussion highlights a significant issue concerning Simplified Payment Verification (SPV) verifiers within the Bitcoin network. SPV verifiers can enhance their security protocols by rejecting Merkle proofs where any node deserializes into a Bitcoin transaction, a solution that does not necessitate a consensus change. However, despite these available mitigations, new SPV verifiers continue to be deployed without incorporating these safeguards. This ongoing vulnerability underscores a critical gap in awareness among implementers regarding this specific risk.

In light of this, there is a proposal suggesting the implementation of a consensus rule aimed at addressing this flaw more fundamentally. This approach advocates for rectifying the issue directly at the consensus level, thereby providing a more robust and systemic solution than currently employed methods. The proposed consensus rule could potentially patch the security loophole beneath the usage of Merkle proofs effectively.

Furthermore, the email compares this proposal with another method that involves invalidating 64-byte transactions. It clarifies that invalidating such transactions wouldn't necessarily require all SPV verifiers to update their software, contrary to what might be assumed. Only specific systems like bridges or wallets intending to receive funds into non-spendable scripts would need modifications to reject these transactions. This distinction is crucial as it impacts only a subset of systems, particularly those that do not play a significant role in securing valuable transactions. This perspective was integral in formulating BIP 54, which opted for the approach described in the Rationale section of the proposal. This method is preferred because it does not mandate widespread patches across systems that securely handle transactions, thus making it a practical and focused solution.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback