On (in)ability to embed data into Schnorr

Oct 1 - Oct 1, 2025

  • AdamISZ, also known by the pseudonym waxwing, presents an analysis centered on Schnorr signatures and their potential for data embedding within a specific tuple format (P, R, s) as defined by BIP340.

The core question addressed is whether it's feasible to embed data into these tuples without either grinding (repeated trial and error attempts) or employing side channels to communicate the embedded information, without consequentially revealing the private key associated with the Schnorr public key. The inquiry delves deeper into the implications of such actions, specifically regarding the utilization of unspent transaction outputs (UTXOs) on a blockchain to clandestinely convey data.

The examination leads to a nuanced conclusion that embedding data in this manner inevitably entails the disclosure of the private key, thereby jeopardizing the security integrity of the UTXO set by potentially expediting its removal from the set. This outcome contrasts with previous acknowledgments that while possible to leak information through private key disclosure, alternative methods might exist. AdamISZ aims to establish that no such alternatives are viable, marking a significant assertion in cryptographic discussions surrounding the Schnorr signature framework.

Moreover, the discourse extends beyond the technical feasibility, touching upon the broader ramifications of attaching signatures to every public key on the blockchain—a concept AdamISZ finds fundamentally troubling yet intellectually stimulating. This reflection underscores a broader concern within the cryptographic community regarding the balance between innovation and the practicality of its application, especially concerning privacy and security.

The analysis invites critique and discussion, particularly from individuals skeptical or critical of the methodology or conclusions drawn. The invitation for feedback signals an open-ended exploration into the complexities of cryptographic practices and their implications on blockchain technology. For those interested in delving into the specifics of AdamISZ’s analysis, the research is accessible through the provided GitHub repository: github.com/AdamISZ/schnorr-unembeddability.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback